socradar.io 7 Sept 2026, 11:31 UTC

Active Magento RCE Lets Attackers Install Persistent Backdoors

STYLESMUGGLER is a currently active, unauthenticated remote code execution (RCE) vulnerability affecting Magento Open Source and Adobe Commerce, with attackers installing a persistent backdoor. The flaw, dubbed StyleSmuggler by Dutch security firm Sansec, was disclosed in an advisory on 5 September 2026; as of 7 September 2026, Adobe had not issued a CVE, security bulletin, patch, or workaround.

The exploit chain enables full server-side code execution and backdoor deployment without requiring any authentication, and public technical details remain limited.

Sansec asserts that all supported Magento Open Source releases are affected, including 2.4.7, 2.4.8, and 2.4.9, with no patch available. Adobe Commerce and Adobe Commerce on Cloud have not been confirmed by Adobe or Sansec. The attack proceeds in two stages: the attacker plants PHP code in a file Magento itself writes (such as a failure report or system log), then triggers Magento’s Payment Transaction Failed Reminder email template. The PHP code executes during email rendering, even if email delivery fails.

The implanted backdoor is a stripped Rust binary (~1.9 MB, built for x86-64 and arm64) that masquerades as a Linux kernel thread, installs a cron entry to restart itself every five minutes, and can read Magento session storage via Redis. Defenders have observed active exploitation beginning on 4 September 2026.

Interim mitigations include disabling GraphQL, hardening servers (disabling proc_open in PHP and mounting /tmp, /var/tmp, and /dev/shm with noexec), checking for indicators of compromise, and rotating credentials. No CVE has been assigned, and CISA KEV has not yet listed StyleSmuggler.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline