Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.
Intelligence analysis by Qwen 2.5 (3B)

A zero-day vulnerability in Magento and Adobe Commerce is being exploited to deploy a backdoor. Adobe is working on a fix.
A bad guy found a secret hole in a popular e-commerce website software. They used it to sneak into the system and hide a backdoor, which is like a secret entrance they can use to get back into the system later.
Analysis
{"heading":"Background on the Vulnerability","content":["The vulnerability, dubbed 'StyleSmuggler,' affects all versions of Magento and Adobe Commerce.","It was first observed on September 4 on a target running the latest security updates.","Sansec observed an exploit that abuses Magento's template system through PHP code injection to generate a fake 'failed-payment' email."]}
Key points
- Magento and Adobe Commerce are affected by a zero-day vulnerability
- The vulnerability can be exploited to deploy a backdoor
- Adobe is working on a fix and recommends website administrators disable GraphQL as a mitigation measure
Fixes are being worked on by Adobe, and website administrators can temporarily disable a feature to help prevent attacks.
If the bad guy gets past the fix, they could use the backdoor to do whatever they want on the website.



