Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    September 8, 2026

    Man Arrested After Allegedly Shooting Flaming Projectile at Flock Cameras, Melting Them Into Slag

    September 8, 2026

    Here’s when the vivo X500 series is launching in China

    September 8, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    Cybersecurity

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    The Tech GuyBy The Tech GuySeptember 8, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports.

    Advertisement

    Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties.

    According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email.

    The remote code execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9, and has been exploited against deployments running the July and August 2026 patches, Sansec says.

    Successful attacks have been deploying a backdoor against Commerce and Magento stores. Written in Rust, the backdoor was seen connecting to a command-and-control (C&C) server and waiting for commands.

    Sansec says the exploitation started on September 4, with the backdoor disguised as ‘[kworker/u:8:0]’. On September 6, a second version of the backdoor emerged, disguising itself as ‘fc-cache’.

    Advertisement. Scroll to continue reading.

    The malware hides its C&C communication as NTP server replies. Its messages carry host information, including agent ID, hostname and username, memory and disk usage, OS version, uptime, root access, and implant version. It also identifies the store’s public IP before beaconing to the C&C.

    “StyleSmuggler deliberately triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email. Unexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification,” Sansec notes.

    The cybersecurity firm explains that the malicious code is executed when Magento resends the email, as well as when email delivery fails, and that no user interaction is required for successful exploitation.

    “Sansec found the campaign on September 4th, 22:40 UTC and reproduced the chain on clean installations within hours,” Sansec notes.

    Adobe is expected to roll out scheduled fixes on September 8, as part of its monthly Patch Tuesday updates, but it is unclear when StyleSmuggler will be addressed. SecurityWeek has emailed Adobe for a statement and will update this article if the company responds.

    Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX

    Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

    Related: Sangoma Switchvox Vulnerabilities Exploited in the Wild

    Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    OpenAI Agents Hijack Another Victim Website

    September 8, 2026

    North Korean Hackers Deploy New Linux Espionage Toolkit

    September 7, 2026

    Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

    September 7, 2026

    Nvidia Is Buying AI Platform Hugging Face for $13 Billion

    September 6, 2026

    Google Patches 6th Chrome Zero-Day of 2026

    September 6, 2026

    VMware Workstation and Fusion Updates Patch Critical Vulnerability

    September 6, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    September 8, 2026

    Man Arrested After Allegedly Shooting Flaming Projectile at Flock Cameras, Melting Them Into Slag

    September 8, 2026

    Here’s when the vivo X500 series is launching in China

    September 8, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.