StyleSmuggler: Unpatched Magento RCE Zero-Day Backdoor Deployment
Score: 9/10

StyleSmuggler: Unpatched Magento RCE Zero-Day Backdoor Deployment

StyleSmuggler targets Magento and Adobe Commerce using an unauthenticated RCE (CVE-2025-54236) to deploy a persistent Rust-based backdoor masquerading as a kernel thread.

Executive Summary

StyleSmuggler is a high-impact zero-day campaign targeting Magento and Adobe Commerce platforms (versions 2.4.7 through 2.4.9) that was first detected in the wild on September 4, 2026. The vulnerability (CVE-2025-54236) allows unauthenticated remote code execution (RCE) by poisoning Magento's template system and triggering execution via system-generated emails, such as payment failure notifications.

Technically, the attack chain involves two stages: injecting malicious PHP code into logs or report files, followed by an object injection primitive that forces Magento to execute the poisoned file. The resulting payload is a stripped, statically linked Rust binary that masquerades as a legitimate Linux kernel worker process named `[kworker/u:8:0]`. This implant maintains persistence through crontabs and has been observed communicating over WebSocket-over-TLS or reading tasks directly from local Redis instances to evade network detection.

This threat is critical for e-commerce organizations as it bypasses all current authentication controls and standard patch levels. At the time of discovery, no official Adobe patch was available, leading to the deployment of third-party mitigations and emergency real-time blocking rules.

Key Details

Threat Name

StyleSmuggler

Affects

Magento, Adobe Commerce, Magento Open Source, Magento 2.4.9

Adversary

—

Malware/Tools

StyleSmuggler, PolyShell, SessionReaper, CosmicSting, gvfsd-user

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure9
Technical Depth9

Sources