Executive Summary
StyleSmuggler is a high-impact zero-day campaign targeting Magento and Adobe Commerce platforms (versions 2.4.7 through 2.4.9) that was first detected in the wild on September 4, 2026. The vulnerability (CVE-2025-54236) allows unauthenticated remote code execution (RCE) by poisoning Magento's template system and triggering execution via system-generated emails, such as payment failure notifications.
Technically, the attack chain involves two stages: injecting malicious PHP code into logs or report files, followed by an object injection primitive that forces Magento to execute the poisoned file. The resulting payload is a stripped, statically linked Rust binary that masquerades as a legitimate Linux kernel worker process named `[kworker/u:8:0]`. This implant maintains persistence through crontabs and has been observed communicating over WebSocket-over-TLS or reading tasks directly from local Redis instances to evade network detection.
This threat is critical for e-commerce organizations as it bypasses all current authentication controls and standard patch levels. At the time of discovery, no official Adobe patch was available, leading to the deployment of third-party mitigations and emergency real-time blocking rules.
