• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    StyleSmuggler Magento GraphQL styles[] Template Poisoning RCE

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated Sep 6, 2026•0•0•1

    This rule detects attempted exploitation of Adobe Commerce (Magento) via GraphQL, specifically targeting Template Property Poisoning through malicious 'styles' array injection as observed in the StyleSmuggler campaign (CVE-2025-54236).

    Suricata

    Tags

    TA0001 - Initial AccessT1190 - Exploit Public-Facing ApplicationT1505.003 - Web ShellTA0003 - PersistenceIDS IPS AlertExploit AttemptHTTP RequestLinuxNetwork GenericSuricata IDSSnort IDSCVE-2025-54236HTTPWeb Application Attack

    Found in

    • StyleSmuggler Zero-Day Remote Code Execution in MagentoLast updated 29 days ago
    • StyleSmuggler Zero-Day Exploited in Adobe Commerce AttacksLast updated Sep 8, 2026
    • StyleSmuggler: Unpatched Magento RCE Zero-Day Backdoor DeploymentLast updated Sep 7, 2026
    • StyleSmuggler Zero-Day Attacks on Adobe Commerce and MagentoLast updated Sep 6, 2026
    • StyleSmuggler Zero-Day Attacks on Adobe Commerce and MagentoLast updated Sep 6, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?