Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

StyleSmuggler Zero-Day Puts Magento Stores on Emergency Footing

StyleSmuggler Zero-Day Puts Magento Stores on Emergency Footing
Photo by Ann H on Pexels

Attackers are exploiting an unpatched vulnerability in Magento Open Source that can provide unauthenticated code execution and persistent access to online stores. Researchers observed compromises beginning on September 4, while Adobe had not yet released an advisory, official workaround or patch when the story was published.

News Date: 2026-09-05

Operators of Magento online stores are facing an active zero-day campaign with no official vendor patch available at the time of publication. The vulnerability, named StyleSmuggler by security company Sansec, reportedly allows attackers to execute code without authenticating and install a persistent Linux backdoor.

Sansec said attacks began on September 4 and that it reproduced the unauthenticated chain against clean installations of Magento Open Source 2.4.7, 2.4.8 and 2.4.9. One confirmed victim was reportedly running the newest available security updates for its release branch, demonstrating that normal patch compliance alone could not stop this campaign.

A Two-Stage Route to Server Access

The reported attack chain first places malicious PHP content in a file written by Magento, such as a log or failure-report file. The attacker then causes the application to process that file while rendering a standard payment failure reminder. No employee or customer needs to open the resulting message, and exploitation may succeed even when email delivery fails.

Investigators found an implant installed outside the normal web root and disguised with a name resembling a Linux kernel worker. A cron entry restarted the process every five minutes, complicating manual removal. On at least one affected server, the malware also opened numerous connections to the store's Redis service, where Magento sessions were stored.

This creates risks beyond website defacement. An attacker controlling an e-commerce application may gain access to customer sessions, administrator credentials, payment integrations, API keys and commercially sensitive order information. Persistent access could also be used later to introduce a payment skimmer or manipulate the software supply chain.

Immediate Defensive Priorities

  • Temporarily disable GraphQL where business and storefront architecture permit it.
  • Inspect both Magento report and system log directories for unexpected PHP content.
  • Search for suspicious non-root processes using kernel-like names and consuming real memory.
  • Review user cron files, including entries that repeatedly restart hidden binaries.
  • Preserve volatile evidence before rebooting, reinstalling packages or killing processes.
  • Invalidate sessions and rotate Magento keys, administrator passwords and integration credentials after suspected compromise.

I believe merchants should treat this as a potential breach rather than a routine patching ticket. Temporary filtering rules may block the requests currently being observed, but they are not equivalent to a complete fix. Until Adobe delivers validated remediation, defenders need layered controls, expanded file monitoring and active threat hunting across the operating system as well as the Magento application directories.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path