Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US Open: Zheng in 5-0 comeback; Gauff, Rybakina, Zverev also in quarters | Tennis

    September 8, 2026

    Eiffel Tower shut by staff strike over female workers being moved for religious visit

    September 8, 2026

    Police seek to identify protesters behind Portsmouth anti-migrant disorder

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US Open: Zheng in 5-0 comeback; Gauff, Rybakina, Zverev also in quarters | Tennis
    • Eiffel Tower shut by staff strike over female workers being moved for religious visit
    • Police seek to identify protesters behind Portsmouth anti-migrant disorder
    • Eric Wu’s newest company, out of stealth since May, is going after construction’s labor crunch
    • Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    • Liquid Recovers 85% of Bitcoin Withdrawn in Exploit
    • North Korea and Russia open first road bridge linking the two countries
    • Die Koalition der Ratlosigkeit – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports.

    Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties.

    According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email.

    The remote code execution (RCE) flaw works on Magento versions 2.4.7, 2.4.8 and 2.4.9, and has been exploited against deployments running the July and August 2026 patches, Sansec says.

    Successful attacks have been deploying a backdoor against Commerce and Magento stores. Written in Rust, the backdoor was seen connecting to a command-and-control (C&C) server and waiting for commands.

    Sansec says the exploitation started on September 4, with the backdoor disguised as ‘[kworker/u:8:0]’. On September 6, a second version of the backdoor emerged, disguising itself as ‘fc-cache’.

    Advertisement. Scroll to continue reading.

    The malware hides its C&C communication as NTP server replies. Its messages carry host information, including agent ID, hostname and username, memory and disk usage, OS version, uptime, root access, and implant version. It also identifies the store’s public IP before beaconing to the C&C.

    “StyleSmuggler deliberately triggers Magento’s standard ‘Payment Transaction Failed Reminder’ email. Unexpected bursts of these messages are a reason to investigate, although legitimate declined payments can generate the same notification,” Sansec notes.

    The cybersecurity firm explains that the malicious code is executed when Magento resends the email, as well as when email delivery fails, and that no user interaction is required for successful exploitation.

    “Sansec found the campaign on September 4th, 22:40 UTC and reproduced the chain on clean installations within hours,” Sansec notes.

    Adobe is expected to roll out scheduled fixes on September 8, as part of its monthly Patch Tuesday updates, but it is unclear when StyleSmuggler will be addressed. SecurityWeek has emailed Adobe for a statement and will update this article if the company responds.

    Related: HPE Patches Critical RCE Vulnerabilities in AOS-CX

    Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

    Related: Sangoma Switchvox Vulnerabilities Exploited in the Wild

    Related: 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

    Adobe Backdoor commerce Exploited online stores ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    OpenAI Agents Hijack Another Victim Website

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US Open: Zheng in 5-0 comeback; Gauff, Rybakina, Zverev also in quarters | Tennis

    September 8, 2026

    Eiffel Tower shut by staff strike over female workers being moved for religious visit

    September 8, 2026

    Police seek to identify protesters behind Portsmouth anti-migrant disorder

    September 8, 2026

    Eric Wu’s newest company, out of stealth since May, is going after construction’s labor crunch

    September 8, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US Open: Zheng in 5-0 comeback; Gauff, Rybakina, Zverev also in quarters | Tennis

    September 8, 2026

    Eiffel Tower shut by staff strike over female workers being moved for religious visit

    September 8, 2026

    Police seek to identify protesters behind Portsmouth anti-migrant disorder

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.