# StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation

> A critical unauthenticated remote code execution vulnerability dubbed 'StyleSmuggler' affecting all current versions of Magento Open Source and Adobe Commerce (2.4.6-2.4.9) is under active exploitation since September 4, 2026. Discovered by Sansec, the two-stage attack abuses GraphQL 'styles' property injection to poison log files, then triggers execution when Magento renders Payment Transaction Failed Reminder emails. A Rust-based backdoor disguised as a Linux kernel thread ([kworker/u:8:0]) is deployed for persistence and session data theft via local Redis connections. No CVE has been assigned and no official patch is available from Adobe as of September 6, 2026.

- **Published:** 2026-09-06T00:00:00Z
- **Last reviewed:** 2026-09-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2356
- **ID:** TL-2026-2356
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

StyleSmuggler is an unpatched (0-day) remote code execution vulnerability in Magento Open Source and Adobe Commerce, under active exploitation since September 4, 2026. The vulnerability requires no authentication and affects all current versions of the platform, including the latest 2.4.9 release. Sansec, a Dutch e-commerce security firm, discovered the campaign and independently reproduced the full unauthenticated attack chain on clean installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9.

The attack operates in two stages. Stage 1 — code injection: attackers send crafted GraphQL requests manipulating 'styles' array properties to evade input sanitization and inject malicious PHP code into files Magento writes during normal operations. Observed injection points include the var/report/ directory (payment failure reports) and var/log/system.log. The injected payload contains a crafted directive that forces a chain of Magento's own classes — specifically the dependency-injection (DI) compiler code under setup/src/Magento/Setup/Module/Di/Code/ — to execute code intended only for the CLI compiler, ultimately including the attacker-poisoned log file.

Stage 2 — trigger: the attacker deliberately triggers Magento's 'Payment Transaction Failed Reminder' transactional email. When Magento renders that email template, the injected PHP code executes server-side. No user interaction is required — nobody needs to open or even receive the email for the attack to succeed. The attack works even when email delivery fails.

Once the PHP injection executes, a PHP dropper cycles through six different PHP functions (including proc_open) until it finds one capable of spawning a process, then downloads and launches a persistent implant. The implant is a statically linked Rust binary of approximately 1.9 MB, compiled for both x86-64 and ARM64 architectures. It masquerades as a Linux kernel thread named [kworker/u:8:0] — setting its command line to the literal bracketed string so process-table checks against the comm field match nothing. Genuine kernel worker threads are root-owned with zero resident memory, so any bracketed kworker running under a website user account with measurable resident memory is the implant.

The backdoor is persisted via a cron entry written directly into the crontab spool file (/var/spool/cron/crontabs/) to bypass standard system logging, executing every 5 minutes. In one compromised store, the implant had the same cron line repeated 1,728 times and re-added it within one second of removal. The implant's network behavior is notably stealthy: on one confirmed store, it made no outbound internet connections at all, instead opening 28 simultaneous connections to the site's own local Redis instance (port 6379) to read live Magento session data. This design allows the malware to operate almost invisibly to network-based monitoring. On other stores, the backdoor connected to C2 infrastructure via WebSocket over TLS (port 443) and custom NTP-shaped UDP traffic on port 123.

Disrex Group, a Magento hosting firm handling two breached stores, independently analyzed the attack chain. Their packet captures (each >200 MB taken with the implant live) contained zero packets to the C2 addresses Sansec listed, confirming the Redis-only operational mode. They also noted that the binary running in memory differed from the file on disk on one store — indicating defenders must hash both the running process from /proc/<pid>/exe and the on-disk file. Disrex found 26 distinct source IPs across their two compromised stores, primarily a residential proxy pool, indicating broad exploitation infrastructure rather than a single attacker.

No official CVE has been assigned. Adobe's next scheduled security bulletin is September 8, 2026, but it remains unknown whether that release will address this vulnerability. Unofficial mitigations have been published by Disrex Group, ProxiBlue, and Graycore, all of which are characterized as hardening measures rather than definitive fixes. Server-level mitigations including disabling PHP's proc_open function and mounting temporary directories with noexec have been shown effective at preventing the dropper from launching its payload. Disabling the GraphQL endpoint entirely is recommended for stores not relying on headless or PWA storefronts.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1053 Scheduled Task/Job
- T1036 Masquerading
- T1564 Hide Artifacts
- T1027 Obfuscated Files or Information
- T1480 Execution Guardrails
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1057 Process Discovery
- T1005 Data from Local System
- T1573 Encrypted Channel
- T1095 Non-Application Layer Protocol
- T1571 Non-Standard Port
- T1219 Remote Access Tools

## Sources

- [StyleSmuggler — Full Technical Breakdown (Sansec Threat Research)](https://sansec.io/research/stylesmuggler)
- [Magento and Adobe Commerce 0-Day RCE Under Active Exploitation (Cyber Security News)](https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/)
- [Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (CyberNoz)](https://cybernoz.com/unpatched-magento-and-adobe-commerce-zero-day-exploited-to-backdoor-online-stores/)
- [Disrex Group — Incident Response Repository](https://github.com/disrex-group)
- [Graycore — StyleSmuggler Mitigation Module (GitHub/Packagist)](https://github.com/graycore)
- [CISA Known Exploited Vulnerabilities Catalog (KEV)](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2356
