Executive Summary
Since September 4, 2026, threat actors have been actively exploiting an unpatched zero-day vulnerability dubbed 'StyleSmuggler' affecting Magento and Adobe Commerce versions 2.4.7 through 2.4.9. The exploit leverages a two-stage process: first, attackers inject malicious PHP code into template or report files (log poisoning); second, they trigger a 'Payment Transaction Failed Reminder' email which causes the platform to execute the poisoned code during server-side rendering.
Successful exploitation leads to the installation of a persistent, statically linked Rust implant disguised as a Linux kernel thread ([kworker/u:8:0]). This implant is designed to maintain persistence via cron and has been observed interacting with local Redis instances to harvest session data. Because the vulnerability allows unauthenticated remote code execution (RCE), all merchants using affected versions are at high risk until a formal patch is released by Adobe. As of reporting, mitigation requires disabling GraphQL or implementing third-party web application firewall (WAF) rules.
