Threat reportVulnerabilityTL-2026-2356
StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation
StyleSmuggler (TL-2026-2356), also tracked as StyleSmuggler, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-06. It has no confirmed attribution, affects Adobe Adobe Commerce, maps to 15 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 19 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2356
- Threat ID
- TL-2026-2356
- Also known as
- StyleSmuggler
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- ecommerce, retail
- Detection rules
- 9
- Indicators of compromise
- 19
How StyleSmuggler works
A critical unauthenticated remote code execution vulnerability dubbed 'StyleSmuggler' affecting all current versions of Magento Open Source and Adobe Commerce (2.4.6-2.4.9) is under active exploitation since September 4, 2026. Discovered by Sansec, the two-stage attack abuses GraphQL 'styles' property injection to poison log files, then triggers execution when Magento renders Payment Transaction Failed Reminder emails. A Rust-based backdoor disguised as a Linux kernel thread ([kworker/u:8:0]) is deployed for persistence and session data theft via local Redis connections. No CVE has been assigned and no official patch is available from Adobe as of September 6, 2026.
StyleSmuggler is an unpatched (0-day) remote code execution vulnerability in Magento Open Source and Adobe Commerce, under active exploitation since September 4, 2026. The vulnerability requires no authentication and affects all current versions of the platform, including the latest 2.4.9 release. Sansec, a Dutch e-commerce security firm, discovered the campaign and independently reproduced the full unauthenticated attack chain on clean installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9.
The attack operates in two stages. Stage 1 — code injection: attackers send crafted GraphQL requests manipulating 'styles' array properties to evade input sanitization and inject malicious PHP code into files Magento writes during normal operations. Observed injection points include the var/report/ directory (payment failure reports) and var/log/system.log. The injected payload contains a crafted directive that forces a chain of Magento's own classes — specifically the dependency-injection (DI) compiler code under setup/src/Magento/Setup/Module/Di/Code/ — to execute code intended only for the CLI compiler, ultimately including the attacker-poisoned log file.
Stage 2 — trigger: the attacker deliberately triggers Magento's 'Payment Transaction Failed Reminder' transactional email. When Magento renders that email template, the injected PHP code executes server-side. No user interaction is required — nobody needs to open or even receive the email for the attack to succeed. The attack works even when email delivery fails.
Once the PHP injection executes, a PHP dropper cycles through six different PHP functions (including proc_open) until it finds one capable of spawning a process, then downloads and launches a persistent implant. The implant is a statically linked Rust binary of approximately 1.9 MB, compiled for both x86-64 and ARM64 architectures. It masquerades as a Linux kernel thread named [kworker/u:8:0] — setting its command line to the literal bracketed string so process-table checks against the comm field match nothing. Genuine kernel worker threads are root-owned with zero resident memory, so any bracketed kworker running under a website user account with measurable resident memory is the implant.
The backdoor is persisted via a cron entry written directly into the crontab spool file (/var/spool/cron/crontabs/) to bypass standard system logging, executing every 5 minutes. In one compromised store, the implant had the same cron line repeated 1,728 times and re-added it within one second of removal. The implant's network behavior is notably stealthy: on one confirmed store, it made no outbound internet connections at all, instead opening 28 simultaneous connections to the site's own local Redis instance (port 6379) to read live Magento session data. This design allows the malware to operate almost invisibly to network-based monitoring. On other stores, the backdoor connected to C2 infrastructure via WebSocket over TLS (port 443) and custom NTP-shaped UDP traffic on port 123.
Disrex Group, a Magento hosting firm handling two breached stores, independently analyzed the attack chain. Their packet captures (each >200 MB taken with the implant live) contained zero packets to the C2 addresses Sansec listed, confirming the Redis-only operational mode. They also noted that the binary running in memory differed from the file on disk on one store — indicating defenders must hash both the running process from /proc/<pid>/exe and the on-disk file. Disrex found 26 distinct source IPs across their two compromised stores, primarily a residential proxy pool, indicating broad exploitation infrastructure rather than a single attacker.
No official CVE has been assigned. Adobe's next scheduled security bulletin is September 8, 2026, but it remains unknown whether that release will address this vulnerability. Unofficial mitigations have been published by Disrex Group, ProxiBlue, and Graycore, all of which are characterized as hardening measures rather than definitive fixes. Server-level mitigations including disabling PHP's proc_open function and mounting temporary directories with noexec have been shown effective at preventing the dropper from launching its payload. Disabling the GraphQL endpoint entirely is recommended for stores not relying on headless or PWA storefronts.
MITRE ATT&CK techniques used in TL-2026-2356
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1480 Execution Guardrails; T1564 Hide Artifacts
Persistence
Privilege Escalation
Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1095 Non-Application Layer Protocol; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
Affected products and versions in StyleSmuggler
- Adobe — Adobe Commerce
Vulnerable versions: 2.4.6-p15; 2.4.7; 2.4.7-p2; 2.4.8; 2.4.9 - Magento (Open Source) — Magento Open Source
Vulnerable versions: 2.4.7; 2.4.8; 2.4.9
Remediation for StyleSmuggler
Patches
- No official patch available as of September 6, 2026
- Unofficial hardening patches available from Disrex Group, ProxiBlue, and Graycore (composer-patches, GitHub)
- Adobe's next scheduled security bulletin: September 8, 2026 — unconfirmed if StyleSmuggler is covered
Immediate actions
- Disable GraphQL endpoint for stores not using headless or PWA storefronts
- Add proc_open to PHP's disable_functions list
- Mount /tmp, /var/tmp, and /dev/shm with noexec flag
- Deploy nginx/Apache rules blocking POST to /graphql with styles[] array parameters
- Scan for backdoor files in ~/.local/share/.gvfsd/ and /tmp/.kw_* paths
- Check for [kworker/u:8:0] processes owned by non-root users with non-zero resident memory
- Search var/report/ for X_TRACE_ markers and var/log/system.log for PHP code or base64 payloads
- Inspect crontab spool files for suspicious gvfsd entries
- Monitor for bursts of Payment Transaction Failed Reminder emails
- Check for unexpected simultaneous Redis connections from non-Redis processes
Workarounds
- Disable GraphQL endpoint entirely for non-headless storefronts
- Sansec Shield provides real-time blocking of exploitation attempts (rules deployed Sept 5, 07:15 UTC)
- eComscan 1.9.7 can detect known implant variants (note: scans document root; implant may reside in home directory above it)
- Apply Disrex Group's web-server rule blocks for current attack traffic patterns
- Apply Graycore's module hardening email template block directives, grid URL generation, and Web API error reports
Longer-term hardening
- Apply Adobe's official patch when released (pending September 8, 2026 security bulletin)
- Implement GraphQL request validation and schema hardening
- Deploy WAF rules with behavioral detection for log poisoning patterns
- Transition to file integrity monitoring on var/report/ and var/log/ paths
- Implement runtime process monitoring for masqueraded kernel thread names
- Establish baseline of expected Redis connection counts for e-commerce infrastructure
Weaknesses (CWE) in StyleSmuggler
Timeline of StyleSmuggler
- Adobe's most recent Commerce security bulletin published, pre-dating the StyleSmuggler campaign
- Store A (Sansec Shield customer running Magento 2.4.8) compromised — hit approximately 23:10 UTC, hours before Shield blocking rules were deployed
- Sansec identified the ongoing attack campaign at approximately 22:40 UTC
- First confirmed StyleSmuggler exploitation observed by Sansec at approximately 22:20 UTC
- Sansec published public disclosure of StyleSmuggler, publishing early 'because stores are being compromised right now'
- ProxiBlue and Graycore published unofficial hardening patches on GitHub and Packagist
- Disrex Group published incident response repository with nginx/Apache blocking rules, code-level DI scanner guards, and cleanup guidance; contained both compromised stores approximately 11-14 hours after first contact
- Sansec independently reproduced the full unauthenticated attack chain on clean installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9
- Sansec Shield blocking rules went live at 07:15 UTC, blocking StyleSmuggler exploitation in real time
- Store B (running Magento 2.4.7-p2) first compromised at approximately 00:55 UTC
- Widespread industry awareness; Adobe has not issued an advisory, CVE identifier, or patch; no official response from Adobe as of this date
- Adobe's next scheduled security bulletin — unconfirmed whether this vulnerability will be addressed
Sources cited for StyleSmuggler
- StyleSmuggler — Full Technical Breakdown (Sansec Threat Research)
- Magento and Adobe Commerce 0-Day RCE Under Active Exploitation (Cyber Security News)
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (CyberNoz)
- Disrex Group — Incident Response Repository
- Graycore — StyleSmuggler Mitigation Module (GitHub/Packagist)
- CISA Known Exploited Vulnerabilities Catalog (KEV)
Detection coverage for TL-2026-2356
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2356 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.