Magento and Adobe Commerce zero-day 'StyleSmuggler' is being exploited to install a Linux backdoor

Attackers are exploiting a previously unknown flaw in Magento and Adobe Commerce to break into online store servers and install a hidden Linux backdoor. Sansec says the 'StyleSmuggler' zero-day affects all versions, was first seen exploited on September 4 against a fully patched target, and abuses the template system via PHP code injection to trigger remote code execution. The malware persists via cron and disguises itself as 'kworker' or 'fc-cache,' with command traffic masked as network time sync (NTP) over UDP port 123.
Why it matters: This is urgent for online stores because attackers can compromise even fully updated Magento and Adobe Commerce servers before a patch is available. Administrators should apply Adobe fixes as soon as released, disable GraphQL as a temporary mitigation, hunt for the listed indicators, and rotate Magento credentials if compromise is suspected.

Sources

Microsoft breaks Patch Tuesday record with 974-CVE deluge
2026.09.09 87% relevant
This article confirms Adobe issued a hotfix for the actively exploited StyleSmuggler flaw, names it as CVE-2026-75650, notes attacks began on September 4, says all Magento and Adobe Commerce versions from 2.4.4 through 2.4.9 are affected, and adds that CISA placed it in KEV with a September 11 federal deadline.
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Ionut Arghire 2026.09.08 97% relevant
This source confirms Adobe has now patched the actively exploited StyleSmuggler zero-day as CVE-2026-75650, says Adobe is aware of in-the-wild exploitation, and adds vendor remediation details including urgent patching and credential/key rotation guidance.
Adobe fixes critical Magento zero-day exploited to backdoor servers
Bill Toulas 2026.09.08 97% relevant
This article is a direct update on the same StyleSmuggler event, adding Adobe’s emergency patch release, the CVE identifier CVE-2026-75650, affected version ranges, hotfix name VULN-39341, and Adobe’s post-compromise response guidance including secret rotation.
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
info@thehackernews.com (The Hacker News) 2026.09.08 97% relevant
This article appears to report the same underlying event and adds that Adobe has now issued patches for the exploited Magento/Adobe Commerce zero-day, with reporting that the attacks deployed a Rust backdoor alongside a PHP web shell.
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Bill Toulas 2026.09.07 100% relevant
The article establishes a distinct new underlying event: active exploitation of a newly named Magento/Adobe Commerce zero-day, before patch release, to deploy a Linux backdoor.
← Back to all stories