{"id":9324,"date":"2026-09-08T11:36:48","date_gmt":"2026-09-08T11:36:48","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9324"},"modified":"2026-09-08T11:36:48","modified_gmt":"2026-09-08T11:36:48","slug":"adobe-commerce-max-severity-bug-comes-under-active-attack","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9324","title":{"rendered":"Adobe Commerce max-severity bug comes under active attack"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers.<\/p>\n<p class=\"wp-block-paragraph\">Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento\u2019s Style properties to inject malicious code past existing safeguards.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen the attack succeeds, a backdoor background process is launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and waits for commands,\u201d Sansec researchers said in a blog <a href=\"https:\/\/sansec.io\/research\/stylesmuggler-0day\" target=\"_blank\" rel=\"noopener\">post<\/a>, adding that the backdoor had not been weaponized at the time of writing.<\/p>\n<p class=\"wp-block-paragraph\">The flaw, tracked as <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2026-75650\" target=\"_blank\" rel=\"noopener\">CVE-2026-75650<\/a>, carries a CVSS score of 10.0 and affects Magento and Adobe Commerce versions 2.4.4 through 2.4.9. Magento is the open-source edition of an e-commerce platform used to build and operate online stores. Adobe Commerce is the commercial\/enterprise version of Magento. Adobe acquired Magento in 2018.<\/p>\n<p class=\"wp-block-paragraph\">According to Sansec, exploitation began on September 4, with the first confirmed attack recorded at 22:20 UTC. The company reproduced the complete unauthenticated attack chain against clean Magento Open Source installations running versions 2.4.7, 2.4.8, and 2.4.9.<\/p>\n<p class=\"wp-block-paragraph\">One victim was running 2.4.6-p15 with both July and August security updates installed, the researchers noted.<\/p>\n<p class=\"wp-block-paragraph\">Adobe has released an emergency hotfix, <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-146.html\" target=\"_blank\" rel=\"noopener\">VULN-393411<\/a>, for the vulnerability. But because attackers had three days to exploit the flaw before a fix arrived, Sansec warns that patching alone isn\u2019t enough for stores that may already have been compromised.<\/p>\n<h2 class=\"wp-block-heading\">Attack triggered through failed payment email<\/h2>\n<p class=\"wp-block-paragraph\">StyleSmuggler\u2019s first trick is to get malicious PHP code into data that Magento itself will write out, such as a payment failure report. \u201cStyleSmuggler deliberately triggers Magento\u2019s standard \u2018Payment Transaction Failed Reminder\u2019email,\u201d the researchers explained. \u201cUnexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The attackers abuse Magento\u2019s template processing by passing specially crafted \u201cstyles properties,\u201d allowing the poisoned data, the injected PHP code, to execute on the server.<\/p>\n<p class=\"wp-block-paragraph\">The customer doesn\u2019t have to open the email, the researchers pointed out. The code executes while Magento renders the message, meaning the attack can succeed even if delivery of the email subsequently fails.<\/p>\n<p class=\"wp-block-paragraph\">Once execution is achieved, the attacker moves on to a small Rust-based backdoor being launched as a background process. The implant was seen adopting names such as \u201c[kworker\/u:8:0]\u201d and \u201cfc-cache,\u201d non-suspicious to a human eye.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>The backdoor is not weaponized, yet<\/h2>\n<p class=\"wp-block-paragraph\">The Rust implant establishes command-and-control communication and uses persistence mechanisms, including <a href=\"https:\/\/www.csoonline.com\/article\/4055678\/docker-malware-breaks-in-through-exposed-apis-then-changes-the-locks.html?utm=hybrid_search#:~:text=port%202375.%20A-,cron%20job,-is%20a%20scheduled\">cron jobs<\/a>. The fc-cache variant copied itself into the fontconfig cache directory and scheduled itself to restart twice an hour. Its C2 traffic was disguised as NTP traffic over UDP port 123, an attempt to make malicious communications blend into routine system activity, the researchers noted.<\/p>\n<p class=\"wp-block-paragraph\">Sansec says it has not yet seen evidence that this backdoor was actually weaponized after installation. But the investigation revealed that another attacker was already exploiting the same StyleSmuggler access.<\/p>\n<p class=\"wp-block-paragraph\">On September 7, Samsec found a separate 485-byte PHP dropper that used the vulnerability to deploy a web shell inside Magento\u2019s product-image cache. The shell could execute PHP commands when supplied with the correct header, giving the second operator a foothold independent of the Rust implant. <\/p>\n<p class=\"wp-block-paragraph\">The researchers recommended checking for unexpected PHP files under \u201cpub\/media,\u201d while also looking for the known malicious processes, cron entries, and other indicators of compromise. Adobe\u2019s emergency hotfix closes the vulnerability, but stores feared to be exposed should scan for implants and secondary backdoors and rotate potentially compromised credentials and secrets.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento\u2019s Style properties to inject malicious code past existing safeguards. \u201cWhen the attack succeeds, a [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9325,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9324","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9324"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9324"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9324\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9325"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}