Adobe Commerce Zero-Day Exploit: How to Protect Your Online Store from Cyberattacks
Adobe Commerce and Magento e-commerce platforms face a critical zero-day exploit, allowing cybercriminals to inject malicious code and deploy backdoors.
Report Overview
Cybersecurity firm Sansec has identified a previously unknown security flaw in Adobe Commerce and Magento e-commerce platforms, dubbed StyleSmuggler. Attackers exploit this vulnerability to inject malicious PHP code into Magento’s template system, bypassing detection mechanisms through ‘styles’ properties.
Vulnerability Details
The exploit operates in two phases. The first involves injecting PHP code by triggering a failure report, which is then executed via a failed payment process. This remote code execution (RCE) flaw impacts Magento versions 2.4.7, 2.4.8, and 2.4.9, with exploitation targeting deployments that applied the July and August 2026 security patches.
Attack Phases
The malicious backdoor, developed in Rust, communicates with a command-and-control (C&C) server and awaits instructions. Sansec identified the initial variant on September 4, disguised as ‘[kworker/u:8:0]’, with a second iteration emerging on September 6 as ‘fc-cache’.
Malware Behavior
The malware conceals C&C interactions by mimicking NTP server responses, transmitting data such as agent identifiers, hostname, username, system metrics, operating system details, uptime, root access status, and the implant’s version. It also gathers the store’s public IP address before establishing contact with the C&C server.
Exploit Methodology
Sansec highlights that the exploit leverages Magento’s default “Payment Transaction Failed Reminder” feature. Unusual spikes in these notifications may indicate malicious activity, though legitimate payment declines can generate similar alerts. The malicious code executes automatically when Magento resends the notification or during delivery failures, requiring no user interaction.
Response and Mitigation
Sansec confirmed detecting the campaign on September 4 at 22:40 UTC and replicated the attack chain on clean installations within hours. Adobe is scheduled to address the vulnerability in its September 8 Patch Tuesday updates, but the timeline for resolving StyleSmuggler remains unspecified. Organizations using affected Magento versions are advised to apply updates promptly and monitor for anomalous activity.
“The exploitation of this flaw underscores the risks associated with unpatched systems and the sophistication of modern attack techniques,” said Sansec.
Conclusion
The StyleSmuggler vulnerability highlights the critical need for timely patching and vigilance in e-commerce security. Cybercriminals are increasingly targeting known platforms, emphasizing the importance of proactive defense measures.
