$ techbeacon▋
CVE & Exploits

Zero-Day 'StyleSmuggler' Exploited to Install Linux Backdoor Across Magento and Adobe Commerce Sites

Zero-Day 'StyleSmuggler' Exploited to Install Linux Backdoor Across Magento and Adobe Commerce Sites

A previously unknown vulnerability identified as "StyleSmuggler" is being weaponized in the wild to implant a Linux‑based backdoor on websites running Magento or Adobe Commerce, according to security researchers who first reported the issue to BleepingComputer.

The flaw, classified as a zero‑day because it was unknown to the software vendor at the time of exploitation, affects every released version of the popular e‑commerce platform and its enterprise counterpart. It stems from insecure handling of style‑related inputs, allowing an attacker to inject malicious code that executes with the same privileges as the web server.

Threat actors are leveraging the vulnerability to drop a stealthy backdoor that provides persistent command‑and‑control access on compromised servers. Once installed, the malicious component can be used to exfiltrate data, modify product listings, or launch further attacks against visitors and downstream services. Because the payload runs on Linux, it aligns with the operating systems most commonly used to host Magento installations.

Online retailers that rely on Magento for their storefronts are particularly exposed, as the platform powers a significant share of global e‑commerce traffic. A compromised store can lead to theft of customer credentials, payment information, and intellectual property, undermining consumer trust and potentially triggering regulatory scrutiny under data‑protection laws.

Adobe has acknowledged the issue and issued an advisory urging all merchants to apply available mitigations while a comprehensive patch is being developed. Recommendations include disabling the vulnerable style processing endpoint, tightening file‑upload controls, and deploying web‑application firewalls to block known exploit patterns.

The emergence of StyleSmuggler highlights the ongoing challenge of securing complex, widely deployed software ecosystems. Security experts stress the importance of rapid patch management, regular code reviews, and layered defenses to reduce the attack surface for similar zero‑day threats in the future.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related