StyleSmuggler Zero-Day Attacks on Adobe Commerce and Magento
Score: 9/10

StyleSmuggler Zero-Day Attacks on Adobe Commerce and Magento

Unauthenticated attackers are exploiting the StyleSmuggler zero-day vulnerability in Adobe Commerce and Magento to achieve remote code execution and install persistent Rust-based backdoors.

Executive Summary

Beginning on September 4, 2026, a critical zero-day campaign dubbed 'StyleSmuggler' has targeted Magento Open Source and Adobe Commerce platforms. The vulnerability allows unauthenticated attackers to achieve Remote Code Execution (RCE) by poisoning template properties and triggering malicious code execution through standard system processes, such as the rendering of failed payment emails. All current versions, including 2.4.9, are reported to be affected, even those with recent security patches applied.

Technical analysis indicates a two-stage attack chain: first, malicious PHP code is injected into system log or report files (e.g., `var/report/` or `var/log/system.log`); second, this code is executed when the platform renders a 'Payment Transaction Failed Reminder' email. Successful exploitation typically results in the deployment of a persistent, statically-linked Rust implant disguised as a Linux kernel thread. This implant has been observed reading session storage from Redis and maintaining persistence through frequently-respawning cron jobs.

This threat poses a severe risk to the e-commerce sector, as it requires no user interaction or authentication to compromise a store. With an official Adobe patch still pending as of the initial reports, merchants are advised to immediately monitor for suspicious background processes, deploy temporary GraphQL restrictions if applicable, and implement server-level hardening to prevent unauthorized binary execution.

Key Details

Threat Name

StyleSmuggler

Affects

Magento, Adobe Commerce

Adversary

—

Malware/Tools

StyleSmuggler, PolyShell, SessionReaper, CosmicSting

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources