Bản viết lại dựa trên nguồn: https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores – SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events Podcast ICS: ICS Cybersecurity Conference Malware & Threats Cyberwarfare Cybercrime Data Breaches Fraud & Identity Theft Nation-State Ransomware Vulnerabilities Security Operations Threat Intelligence Incident Response Tracking & Law Enforcement Security Architecture Application Security Cloud Security Endpoint Security Identity & Access IoT Security Mobile & Wireless Network Security Risk Management Cyber Insurance Data Protection Privacy & Compliance Supply Chain Security CISO Strategy Cyber Insurance CISO Conversations CISO Forum ICS/OT Industrial Cybersecurity ICS Cybersecurity Conference Funding/M&A Cybersecurity Funding M&A Tracker Cyber AI Cybersecurity News Webcasts Virtual Events Podcast ICS Cybersecurity Conference Connect with us Hi, what are you looking for? SecurityWeek Malware & Threats Cyberwarfare Cybercrime Data Breaches Fraud & Identity Theft Nation-State Ransomware Vulnerabilities Security Operations Threat Intelligence Incident Response Tracking & Law Enforcement Security Architecture Application Security Cloud Security Endpoint Security Identity & Access IoT Security Mobile & Wireless Network Security Risk Management Cyber Insurance Data Protection Privacy & Compliance Supply Chain Security CISO Strategy Cyber Insurance CISO Conversations CISO Forum ICS/OT Industrial Cybersecurity ICS Cybersecurity Conference Funding/M&A Cybersecurity Funding M&A Tracker Cyber AI Vulnerabilities Adobe Commerce Zero-Day Exploited to Backdoor Online Stores The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. By Ionut Arghire | September 7, 2026 (7:58 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties. According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email. The remote code execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9, and has been exploited against deployments running the July and August 2026 patches, Sansec says. Successful attacks have been deploying a backdoor against Commerce and Magento stores. Written in Rust, the backdoor was seen connecting to a command-and-control (C&C) server and waiting for commands. Sansec says the exploitation started on September 4, with the backdoor disguised as ‘[kworker/u:8:0]’. On September 6, a second version of the backdoor emerged, disguising itself as ‘fc-cache’.Advertisement. Scroll to continue reading. The malware hides its C&C communication as NTP server replies. Its messages carry host information, including agent ID, hostname and username, memory and disk usage, OS version, uptime, root access, and implant version. It also identifies the store’s public IP before beaconing to the C&C. “StyleSmuggler deliberately triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email. Unexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification,” Sansec notes. The cybersecurity firm explains that the malicious code is executed when Magento resends the email, as well as when email delivery fails, and that no user interaction is required for successful exploitation. “Sansec found the campaign on September 4th, 22:40 UTC and reproduced the chain on clean installations within hours,” Sansec notes. Adobe is expected to roll out scheduled fixes on September 8, as part of its monthly Patch Tuesday updates, but it is unclear when StyleSmuggler will be addressed. SecurityWeek has emailed Adobe for a statement and will update this article if the company responds. Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Related: Sangoma Switchvox Vulnerabilities Exploited in the Wild Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Sangoma Switchvox Vulnerabilities Exploited in the Wild12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverVMware Workstation and Fusion Updates Patch Critical VulnerabilityGoogle Patches 6th Chrome Zero-Day of 2026Manchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalHiddenLayer Raises $100 Million for AI Runtime Security153 Million Driver License Images Offered on Dark WebOver 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Latest News Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsNorth Korean Hackers Deploy New Linux Espionage ToolkitOpenAI Agents Hijack Another Victim WebsiteModified ScreenConnect Clients Used in Worm-Like CampaignElementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B ValuationHPE Patches Critical RCE Vulnerabilities in AOS-CXOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email Popular Topics Cybersecurity News Industrial Cybersecurity Security Community Virtual Cybersecurity Events Webcast Library CISO Forum AI Risk Summit ICS Cybersecurity Conference Cybersecurity Newsletters Stay Intouch Cyber Weapon Discussion Group RSS Feed Security Intelligence Group Follow SecurityWeek on LinkedIn About SecurityWeek Advertising Event Sponsorships Writing Opportunities Feedback/Contact Us Privacy Policy News Tips Got a confidential news tip? We want to hear from you. Submit Tip Advertising Reach a large audience of enterprise cybersecurity professionals Contact Us Daily Briefing Newsletter Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox. Privacy Policy Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time. Close
