discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.

By Bill Toulas·Sep 7·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Image: bleepingcomputer.com

A zero-day vulnerability in Magento and Adobe Commerce is being exploited to deploy a backdoor. Adobe is working on a fix.

Why it matters

This vulnerability affects a popular e-commerce platform and could allow attackers to gain unauthorized access to systems.

A bad guy found a secret hole in a popular e-commerce website software. They used it to sneak into the system and hide a backdoor, which is like a secret entrance they can use to get back into the system later.

Analysis

{"heading":"Background on the Vulnerability","content":["The vulnerability, dubbed 'StyleSmuggler,' affects all versions of Magento and Adobe Commerce.","It was first observed on September 4 on a target running the latest security updates.","Sansec observed an exploit that abuses Magento's template system through PHP code injection to generate a fake 'failed-payment' email."]}

Key points

  • Magento and Adobe Commerce are affected by a zero-day vulnerability
  • The vulnerability can be exploited to deploy a backdoor
  • Adobe is working on a fix and recommends website administrators disable GraphQL as a mitigation measure
The Upside

Fixes are being worked on by Adobe, and website administrators can temporarily disable a feature to help prevent attacks.

The Downside

If the bad guy gets past the fix, they could use the backdoor to do whatever they want on the website.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritye-commercemagentoadobe-commercebackdoor

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 7, 2026

Source

bleepingcomputer.com

Share

Topics

securitye-commercemagentoadobe-commercebackdoor

Related

More from this desk

Sep 7·thehackernews.com

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.

Sep 7·bleepingcomputer.com

Trezor data breach impact now reaches 81,000 customers

Trezor expands data breach affecting 81,000 customers, including full names, addresses, emails, and phone numbers. ShipMonk failed to delete exposed data as required by contract.

Sep 7·thehackernews.com

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers found three incidents using different methods to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations.

Sep 7·bleepingcomputer.com

ChatGPT can now connect to your personal apps to mimic writing style

OpenAI testing Writing Style feature for ChatGPT that learns writing style from connected apps