Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
BLUF
Active exploitation of a critical zero-day in all Magento/Adobe Commerce versions requires immediate patching or mitigation.
NEWS
Security researchers have identified a new zero-day vulnerability named StyleSmuggler impacting all Magento and Adobe Commerce installations. Threat actors are currently weaponizing this flaw to deploy Linux backdoors, granting persistent remote access to compromised e-commerce servers.
Why I Care
This matters because e-commerce platforms handle sensitive customer data and payment information; a successful breach leads to data theft, financial loss, and reputation damage. All merchants using Magento or Adobe Commerce are at risk regardless of version.
Next Steps
Merchants should immediately apply vendor patches once released or implement WAF rules to block exploitation attempts. Security teams must scan for indicators of compromise related to the backdoor and isolate affected systems until remediation is complete.
Source: BleepingComputer ·