← BACK TO FEED
TAG

adobe commerce1 article

StyleSmuggler: Rust-Powered Backdoor Hits Adobe Commerce Stores via Unpatched Zero-Day

A zero-day vulnerability dubbed **StyleSmuggler** is being actively exploited in Adobe Commerce and Magento e-commerce platforms, allowing attackers to inject PHP code into Magento's template system and achieve remote code execution. The two-stage attack triggers a failed payment report to inject the code, then executes it via a payment failure email — requiring no user interaction. Successful attacks deploy a Rust-written backdoor that disguises itself as a legitimate system process and communicates with a command-and-control server, with exploitation observed since September 4; Adobe patches were expected on September 8, though it was unclear whether StyleSmuggler would be addressed.

8 Sept 2026