#stylesmuggler
Hackers are using a new zero-day to take over Adobe Commerce and Magento online stores.

A successful attack allows attackers to start a backdoored background process on hacked stores

sansec.io/research/sty...
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current ver...
sansec.io
September 6, 2026 at 11:18 PM
Onlineshops auf Basis von Magento und Adobe Commerce sind offenbar aufgrund einer ungepatchten Sicherheitslücke namens StyleSmuggler angreifbar. #Security
Zero-Day-Lücke StyleSmuggler in Magento und Adobe Commerce wird aktiv ausgenutzt
Onlineshops auf Basis von Magento und Adobe Commerce sind offenbar aufgrund einer ungepatchten Sicherheitslücke namens StyleSmuggler angreifbar.
www.heise.de
September 7, 2026 at 3:26 PM
After the StyleSmuggler patch, Adobe recommends rotating all Admin passwords. This n98-magerun2 add-on forces resets for active admins; run a dry run first. Thanks Christian Walter & the valantic Magento team!

https://github.com/netz98/magerun2-addon-admin-password-reset

#n98-magerun2
September 24, 2026 at 8:00 AM
Attackers are exploiting the StyleSmuggler zero‑day in Magento 1.9.2.3 and later to backdoor e‑commerce sites that have not yet applied the security patch. #Magento #StyleSmuggler #ZeroDay #CyberSecurity https://thecyberexpress.com/attackers-exploit-unpatched-magento-zero-day/
Attackers Exploit Unpatched Magento Zero-Day To Backdoor Online Stores - The Cyber Express
Attackers are exploiting StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day, to backdoor online stores. No Adobe patch as of Sept. 6.
thecyberexpress.com
September 8, 2026 at 11:22 AM
-Patch Tuesday is out
-Microsoft patches two zero-days
-New N-able N-central zero-day
-Adobe patches StyleSmuggler zero-day
-New WeChat worm
-New SAP OVERPASS and S4GET vulnerabilities
-PostGREShell vulnerability
-Cross-account data leakage in ChatGPT
-fwd:cloudsec Europe 2026 streams
September 9, 2026 at 7:56 AM
132,158 Observable Magento Stores: Sizing the Population Exposed in the StyleSmuggler Window
# 132,158 Observable Magento Stores: Sizing the Population Exposed in the StyleSmuggler Window ## Opening CVE-2026-75650 (StyleSmuggler) was exploited from 4 September 2026, and Adobe's hotfix VULN-39341 arrived on 7 September. Between those dates, every internet-reachable Adobe Commerce or Magento Open Source deployment was in the exposure window, and the post-compromise Rust backdoor survives patching. Sizing that population with a real measurement beats estimating it. On 19 September 2026, the ZoomEye query `app="Magento"` returned 132,158 observable services. ## Context and method The query used the official `app` fingerprint field with `sub_type=all` and requested country and port facets. A fingerprint match means the platform's scanning vantage observed Magento characteristics on the service. It does not mean the deployment ran a vulnerable version during the exposure window - version data is not included in this query - and it does not count stores behind CDNs, which the Magento population intersects heavily. ## What the facets show Country facet: * United States: 61,553 * Germany: 12,101 * United Kingdom: 7,612 * China: 4,982 * Belgium: 4,916 * The Netherlands: 4,456 * France: 4,448 * Ireland: 3,932 * Singapore: 3,770 * India: 3,012 Port facet: * Port 443: 60,327 * Port 80: 50,995 * Port 8080: 5,367 * Port 8443: 2,783 * Port 2086: 1,445 (a cPanel-associated port) * Port 2082: 1,422 * Port 2052: 1,409 Two distributions carry information for incident-response planning. The country concentration (46.6% US in the top-10 subset) reflects where the e-commerce hosting market concentrates, and matches where Sansec observed exploitation. The cPanel-associated ports (2082/2086/2095 together over 4,200 services) indicate shared-hosting Magento deployments, a segment that typically patches slowest and has the least in-house incident-response capability - the exact population the StyleSmuggler backdoor persistence model targets. ## From population to prioritization The measurement converts to a work queue in three steps: 1. **Version triage.** Fingerprint match is not version data. Stores that applied VULN-39341 before 7 September were in the window; stores that applied it after were in it longer. Order internal stores by hotfix application date, not by alarm level. 2. **Persistence sweep.** The Rust backdoor impersonates kernel threads (`[kworker/u:8:0]`, `fc-cache`, `chronyd`) and communicates over UDP 123 as fake NTP. Sweep `pub/media` for PHP, check process tables for those names, and review egress for UDP 123 regardless of patch date. 3. **Shared-hosting follow-up.** The cPanel-port population deserves separate follow-up: those operators often cannot sweep their own hosts and depend on the hosting provider. ## Limits This count bounds the observable population, not the victim count. Sansec and Disrex observed exploitation within minutes of disclosure in at least one incident, which suggests the actual exploited subset was small but fast-moving. The fingerprint also cannot see stores behind CDN fronts or on private networks. The number is a denominator for risk conversations, not a victim list. ## References * ZoomEye v2 API responses recorded 2026-09-19: `app="Magento"` with country and port facets * Adobe APSB26-146 and hotfix VULN-39341 (exploitation from 4 September 2026, hotfix 7 September 2026) * Sansec StyleSmuggler research and Disrex incident timeline * CISA KEV entry for CVE-2026-75650, added 8 September 2026
dev.to
September 25, 2026 at 1:47 PM
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
www.bleepingcomputer.com
September 8, 2026 at 1:35 PM
🔴 StyleSmuggler — Magento zero-day under active attack

A new unauthenticated RCE zero-day is hitting Magento Open Source and Adobe Commerce stores. Sansec confirmed succes

stemshop.top/blog/magento...

#Magento #AdobeCommerce #StyleSmuggler #ZeroDay #RCE #EcommerceSecurity #CyberSecurity #InfoSec
StyleSmuggler — Magento & Adobe Commerce Zero-Day RCE Under Active Attack
StyleSmuggler is an unpatched unauthenticated RCE zero-day affecting Magento Open Source and Adobe Commerce. Active attacks are installing persistent backdoors on online stores.
stemshop.top
September 6, 2026 at 11:50 PM
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
sansec.io/research/sty...
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current ver...
sansec.io
September 7, 2026 at 11:40 AM
Magento & Adobe CommerceのStyleSmuggler脆弱性は、Linuxバックドア展開に悪用されています。
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
www.bleepingcomputer.com
September 7, 2026 at 7:07 PM
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
www.bleepingcomputer.com
September 7, 2026 at 4:50 PM
Magento's StyleSmuggler zero-day is being exploited, allowing hackers to install a Linux backdoor. This highlights the importance of timely software updates and cybersecurity vigilance. #CyberSecurityNews
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor.
www.bleepingcomputer.com
September 8, 2026 at 10:05 AM
StyleSmuggler Vulnerability in Magento and Adobe Commerce Exploited, Risking Code Execution and Backdoor Deployment

huntaegis.com
September 7, 2026 at 1:19 PM
Hackers are actively exploiting the critical #StyleSmuggler zero-day to compromise Adobe Commerce and Magento stores, with researchers finding Linux backdoors and PHP web shells on affected systems.

Listen/Read: hackread.com/stylesmuggle...

#Cybersecurity #Magento #Adobe #0Day #Vulnerability
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores
A critical Adobe Commerce and Magento zero-day dubbed StyleSmuggler is under active attack, allowing hackers to execute PHP code without authentication.
hackread.com
September 15, 2026 at 11:26 AM
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Two unauthenticated requests: poison a Magento failure report, then drive the email template system into the DI compiler that includes it. Full chain analysis, lab PoC, and mitigations.
fortbridge.co.uk
September 12, 2026 at 3:58 PM
StyleSmuggler Zero-Day Exploited In Adobe Commerce And Magento Open Source | CVE-2026-75650

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
September 23, 2026 at 5:29 PM
StyleSmuggler Zero-Day Exploited In Adobe Commerce And Magento Open Source | CVE-2026-75650

youtu.be/C3dPj9Ea1jE

Follow for more weekly cybersecurity news

#cybersecurity #cybersecuritynews
September 23, 2026 at 5:27 PM
🚨 SECURITY ALERT: Magento and Adobe Commerce 🚨
An urgent hotfix is available to patch a critical zero-day vulnerability known as StyleSmuggler in Magento and Adobe Commerce. Risks include card skimming and access to your store. Update your software as soon as you can.

sitehost.nz/blog/securit...
Magento and Adobe Commerce StyleSmuggler vulnerability
An urgent hotfix is available to patch a critical vulnerability in Magento and Adobe Commerce. Update your store's software as soon as you can.
sitehost.nz
September 15, 2026 at 12:18 AM
Auf Grund von User:innen-Anfragen zur Gefährdung von Linux-Desktop-Systemen im Zusammenhang mit StyleSmuggler: Es gibt keinen Hinweis auf Komponenten, die Desktop-Systeme – egal ob Windows, macOS oder Linux-Desktops – direkt angreifen.
digitalalltag.de
#digitalalltag #infosec
September 7, 2026 at 8:16 PM
🚨 SECURITY ALERT: Magento and Adobe Commerce 🚨

An urgent hotfix is available to patch a critical zero-day vulnerability known as StyleSmuggler in Magento and Adobe Commerce. Risks include card skimming and access to your store.

Update your software as soon as you can.

myhost.nz/blog/securit...
Magento and Adobe Commerce vulnerability: Apply hotfix ASAP
An urgent hotfix is available to patch a critical vulnerability in Magento and Adobe Commerce. Update your store's software as soon as you can.
myhost.nz
September 15, 2026 at 2:52 AM