Threat reportVulnerabilityTL-2026-2358
StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
StyleSmuggler (TL-2026-2358), also tracked as StyleSmuggler, is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-06 and last reviewed 2026-09-14. It has no confirmed attribution, affects Adobe Adobe Commerce, references 1 CVE (CVE-2026-75650), maps to 33 MITRE ATT&CK techniques (T1001.003, T1005, T1008), and is covered by 9 detection rules and 60 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 33MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 60Indicators of compromise
Key facts for TL-2026-2358
- Threat ID
- TL-2026-2358
- Also known as
- StyleSmuggler
- Severity
- CRITICAL
- CVSS
- 10
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- ecommerce, retail, online-store
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 60
- Updates
- 2026-09-14 · 5 updates · revalidated 5× · latest source
Malware and tooling in StyleSmuggler
Malware and tooling: gvfsd-user
How StyleSmuggler works
An unauthenticated remote code execution zero-day vulnerability in Magento Open Source and Adobe Commerce, discovered by Sansec and named StyleSmuggler. The two-stage attack chain abuses Magento's GraphQL endpoint and template rendering system to inject PHP code into log files, then triggers execution through the built-in Payment Transaction Failed Reminder email template — deploying a persistent Rust backdoor disguised as a Linux kernel thread. Actively exploited since September 4, 2026 with confirmed compromises of multiple stores and no official patch or CVE as of publication.
StyleSmuggler is an unauthenticated remote code execution (RCE) zero-day vulnerability affecting Magento Open Source and Adobe Commerce, discovered by Dutch e-commerce security firm Sansec on September 4, 2026. The vulnerability is actively exploited in the wild with confirmed compromises of at least two stores managed by Disrex Group, plus additional victims detected via Sansec's eComscan platform. As of September 6, 2026, no CVE has been assigned by Adobe, no official patch has been released, and all supported versions of Magento Open Source (2.4.6 through 2.4.9) and the corresponding Adobe Commerce versions are confirmed affected — including one victim running 2.4.6-p15 with July and August 2026 security patches applied.
The attack follows a sophisticated two-stage chain. In Stage 1 (injection), the attacker sends a malicious HTTP request through Magento's GraphQL endpoint with crafted styles[] parameters that bypass input sanitization and force Magento's template rendering engine to write PHP code into files the application itself maintains — either var/log/system.log (via an invalid store code logged verbatim) or var/report/ (via uncaught exception failure reports). The trigger header marking the poisoned content is an X-TRACE- followed by ten hex characters (early campaign) or X- followed by twelve hex characters (later same day, after the marker was deliberately changed).
In Stage 2 (execution), the attacker triggers Magento's built-in Payment Transaction Failed Reminder email by submitting an order with a .invalid domain address and a zero total. Magento's getProcessedTemplate() method parses the {{block}} directive embedded in the attacker-controlled text, instantiating objects through parameters like generatorClass and with_resolved. The object-injection chain walks through Magento's internal class hierarchy until it reaches one of three dependency-injection compiler scanner methods — ArrayScanner::collectEntities(), ClassesScanner::includeClass(), or XmlInterceptorScanner::_handleControllerClassName() — in setup/src/Magento/Setup/Module/Di/Code/. These methods accept attacker-controlled file paths and execute them via PHP include or require_once. Because PHP's include executes any PHP content in the file, a log file full of harmless-looking diagnostic messages becomes executable code. A TypeError from array_merge() with an integer argument in system.log immediately after the include is a forensic tell confirming successful exploitation; stealthier variants append return []; to the payload, leaving no error trace.
Upon code execution, a PHP dropper probes six PHP process-execution functions sequentially — shell_exec, exec, system, passthru, proc_open, popen — and uses the first available. On one store where the first four were disabled by open_basedir, proc_open remained enabled and was sufficient for the dropper to spawn the child process, which then operated outside PHP's confinement entirely. The dropper downloads an architecture-matched (~1.9 MB, stripped, statically linked) Rust binary from https://247.cdnflare.xyz/files/kworker-linux-<arch>, compiles for both x86-64 and arm64, makes it executable, and detaches it as a background process.
The binary installs itself at ~/.local/share/.gvfsd/gvfsd-user — outside the web document root, under the site user's home directory — and masquerades as [kworker/u:8:0] to mimic a legitimate Linux kernel thread. Genuine kernel threads are owned by root with zero resident memory; a bracketed process name owned by a site user with real RSS consumption is the definitive detection signal. The implant sets its command-line string to the bracketed value directly, so checks against the comm field (which ps derives from args) match nothing.
Persistence is achieved through a cron entry written directly to /var/spool/cron/crontabs/<user>, bypassing the crontab command so syslog records no REPLACE events. The entry executes the implant every 5 minutes: */5 * * * * exec <home>/.local/share/.gvfsd/gvfsd-user. The implant re-adds the entry within one second of removal; one store exhibited 1,728 identical lines. The binary in memory may differ from the file on disk, as confirmed on one compromised store — defenders are advised to hash the running process from /proc/<pid>/exe as well as the file on disk. The implant persists even after file deletion through the deleted inode accessible via /proc/<pid>/exe.
C2 communication occurs over multiple channels: WebSocket over TLS to 99.84.67.186:443 (and windwsecurity.run:443 for remote shell access), as well as custom NTP-shaped traffic over UDP port 123 to ntp.timesysnc.net, time.microsft.run, and pool.microsft.studio — blending with legitimate NTP traffic on the network. On at least one compromised store, two 200+ MB packet captures contained zero packets to any known C2 address; instead, the implant held 28 simultaneous connections to the local Redis instance on 127.0.0.1:6379, reading Magento session data. This pattern makes egress-based network monitoring unreliable as a compromise indicator.
Attack infrastructure includes 26+ distinct source addresses spanning at least two waves: two hosting-provider IPs (5.181.86.133 from CloudVPS with 96 requests, 91.238.181.19 from AS49434 with 48 requests in a second wave) and 24 residential proxy IPs from consumer ISPs sending 2-6 requests each. Blocking only the most prominent attacker IP (88.216.72.181 with 45 requests) would stop less than a quarter of observed traffic. The malware download host 247.cdnflare.xyz resolves to both IPv4 and IPv6 (2a06:98c1:3120::2, 2a06:98c1:3121::2).
Several early-warning signs help merchants detect compromise: (1) a Payment Transaction Failed Reminder email containing raw unresolved {{var ...}} template tags, a customer address on a .invalid domain, and a total of zero — described by Disrex as exhaust from the exploitation attempt passing through Magento's template filter; (2) Magento's fallback 'an error occurred generating this content' message inside email address blocks; (3) unexpected bursts of Payment Transaction Failed Reminder emails; (4) the presence of X_TRACE_, X_-hex, or <?php markers in var/report/ or var/log/system.log; (5) processes named [kworker] owned by non-root users with non-zero resident memory; (6) cron entries referencing gvfsd or .kw_ in /var/spool/cron/crontabs/; and (7) Response payloads wrapped in MG<20hex>::<base64>::/MG<20hex> patterns.
Multiple unofficial mitigations have been published. Disrex Group shipped a composer-patches source patch adding a PHP_SAPI !== 'cli' guard to all three DI scanner methods, verified working on Magento 2.4.6 through 2.4.9 and live-tested on 2.4.7-p2 and 2.4.8-p4. ProxiBlue (Lucas van Staden) independently published the identical guard on September 5. Graycore published a Composer-installable hardening module (graycore/magento2-style-smuggler-patch) with three entry-point protections: email template block directive filtering, grid row URL generator class validation, and PHP open tag breaking in Web API fatal error reports — explicitly noting this is hardening, not a fix. Server-level protections include disabling all six PHP process-execution functions (especially proc_open), mounting /tmp, /var/tmp, and /dev/shm with noexec, and deploying web server rules blocking styles[], generatorClass, and with_resolved parameters in query strings (bypassable via POST body). Temporarily disabling GraphQL is recommended for classic/Hyvä storefronts that do not require it. Sansec Shield detection rules have been operational since September 5 at 07:15 UTC. Adobe's next scheduled security release is September 8, 2026, although it has not been confirmed to address this vulnerability.
MITRE ATT&CK techniques used in TL-2026-2358
Command and Control
T1001.003 Protocol or Service Impersonation; T1008 Fallback Channels; T1071.001 Web Protocols; T1071.004 Application Layer Protocol: DNS; T1090.002 Proxy: External Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel; T1573.001 Encrypted Channel: Symmetric Cryptography
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerading: Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1564.001 Hide Artifacts: Hidden Files and Directories; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol; T1567 Exfiltration Over Web Service
Persistence
T1053.003 Scheduled Task/Job: Cron; T1505.003 Server Software Component: Web Shell
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 JavaScript
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware
Reconnaissance
Affected products and versions in StyleSmuggler
- Adobe — Adobe Commerce
Vulnerable versions: 2.4.6; 2.4.7; 2.4.8; 2.4.9; prior releases - Magento — Magento Open Source
Vulnerable versions: 2.4.6; 2.4.7; 2.4.8; 2.4.9; prior releases
Remediation for StyleSmuggler
Patches
- Disrex source patch: CLI-only guard on ArrayScanner::collectEntities(), ClassesScanner::includeClass(), XmlInterceptorScanner::_handleControllerClassName() — verified 2.4.6 through 2.4.9
- Graycore magento2-style-smuggler-patch: Composer module hardening email template block directives, grid URL generation, and Web API error report injection
Immediate actions
- Disable GraphQL endpoint if not required by storefront (classic and Hyvä themes; exclude headless/PWA)
- Add all six PHP process-execution functions (shell_exec, exec, system, passthru, proc_open, popen) to disable_functions
- Mount /tmp, /var/tmp, and /dev/shm with noexec to block binary execution from writable directories
- Deploy web server rules blocking styles[], generatorClass, with_resolved, and {{ in query strings (note: POST body bypasses these)
- Deploy Sansec Shield or equivalent WAF rules covering both stages of the exploit chain
- Run eComscan 1.9.7+ with widened scan path (include site user home directory, not just document root)
Workarounds
- Temporarily disable GraphQL for classic and Hyvä storefronts
- Add nginx/Apache query-string filters blocking styles[, generatorClass, with_resolved, {{, <? — POST body bypasses these
- Block 247.cdnflare.xyz and known C2 domains at DNS/network level
- Block known attacker IPs at firewall (88.216.72.181, 5.181.86.133, 91.238.181.19) — residential proxy pool cannot be fully blocked
Longer-term hardening
- Apply Disrex composer-patches source patch or ProxiBlue patch to guard DI scanner methods with PHP_SAPI !== 'cli'
- Deploy Graycore hardening module (graycore/magento2-style-smuggler-patch) for template/grid/error protection
- Implement process monitoring for [kworker] process names owned by non-root users with non-zero RSS
- Monitor for Payment Transaction Failed Reminder email bursts and malformed {{var ...}} template tags
- Set up cron file integrity monitoring on /var/spool/cron/crontabs/
- Schedule regular Redis session store audits for unexpected connection counts
- Apply official Adobe patch when released and verify composership integration
CVEs associated with StyleSmuggler
CVE-2026-75650
Weaknesses (CWE) in StyleSmuggler
Timeline of StyleSmuggler
Showing the 20 most recent tracked events.
- ProxiBlue (Lucas van Staden) publishes three unofficial patches arriving at the identical PHP_SAPI guard; Graycore publishes magento2-style-smuggler-patch Composer module
- Disrex publishes incident report, composer-patches source patch (verified 2.4.6-2.4.9), cleanup guide, IOC list, and web server filter rules
- Disrex confirms the StyleSmuggler compromise during incident response at 13:51 UTC; containment begins at ~14:00 UTC
- Sansec publishes the StyleSmuggler advisory after reproducing the chain on clean Magento 2.4.7, 2.4.8, and 2.4.9 installations
- Sansec Shield detection and blocking rules go live at 07:15 UTC covering both stages of the exploit chain
- Store B (Magento 2.4.7-p2) compromised at 00:55 UTC; both stores breached within the ~8-hour window before any defense existed
- Implant variant v2.1.4 released: binary renamed to fc-cache, stored at ~/.cache/fontconfig/fc-cache; C2 traffic shifted from TLS/WebSocket to NTP-disguised UDP on port 123
- 17:30 UTC — Sansec blocks a GraphQL recon probe (storeConfig { store_code }) against a 2.4.7-p10 storefront; the probe carried php_uname()/get_current_user()/getcwd() and a pub/media-writability check in the Store: header, exfiltrated as 50-char DNS-subdomain labels.
- BleepingComputer, SecurityWeek, heise online, and Aikido publish articles on StyleSmuggler; Adobe Enterprise Support confirms working on a fix
- Adobe publishes emergency hotfix APSB26-146 (VULN-39341, CVE-2026-75650) via repo.magento.com at 20:20 UTC; tested on 2.4.4-2.4.9 August releases and Commerce B2B 1.3.3-1.5.3
- Implant variant v2.1.5 released: binary renamed to chronyd, stored at /tmp/.chrony-<8hex>/chronyd
- A second, unrelated attacker deploys a 485-byte PHP web shell to pub/media/ via StyleSmuggler and exfiltrates data via DNS to an OAST service on oastify.com
- Scandiweb backports a community security patch covering CVE-2026-75650 to 41 legacy/unsupported Magento releases (2.2, 2.3, 2.4.0-2.4.3).
- A public proof-of-concept exploit repository for CVE-2026-75650 appears, per CrowdSec tracking, accelerating opportunistic scanning.
- CISA adds CVE-2026-75650 (StyleSmuggler) to the Known Exploited Vulnerabilities Catalog; per BOD 26-04, federal agencies must remediate by September 11, 2026.
- NVD publishes the CVE-2026-75650 record with CVSS 10.0; CISA KEV had not yet listed the vulnerability as of publication.
- Adobe's next scheduled security release — not confirmed to address StyleSmuggler
- CrowdSec deploys a crowdsourced detection rule for CVE-2026-75650 exploitation traffic; daily exploitation signals average 552/day through September 13.
- Exploitation attempts peak at 1,303 signals in a single day from 193 distinct sources, per CrowdSec telemetry.
- Akamai publishes a detailed public technical write-up of CVE-2026-75650 ("StyleSmuggler"), naming it and detailing the PayPal-endpoint injection vector, WraithC2, and gs-netcat tooling.
Update history for TL-2026-2358
- 2026-09-14 — CVE-2026-75650 "StyleSmuggler": Unauthenticated RCE in Adobe Commerce/Magento via GraphQL Log Poisoning: What changed Motivation reassessed UNKNOWN → FINANCIAL based on convergent reporting (Akamai, CrowdSec, Kudelski, NetSPI) describing opportunistic, residential-proxy-driven mass scanning and commodity RAT/webshell deployment consistent with
- 2026-09-08 — CISA Adds Four Known Exploited Vulnerabilities to Catalog — Adobe Commerce/Magento StyleSmuggler, Microsoft Windows Update Stack & ALPC, N-able N-central: What changed Severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and CVSS (10.0) are unchanged. CISA formally added CVE-2026-75650 to the KEV Catalog on 2026-09-08, converting the earlier 'not yet listed' note into a confirmed KE
- 2026-09-08 — CVE-2026-75650 ("StyleSmuggler"): Actively exploited unauthenticated RCE zero-day in Adobe Commerce (Magento): What changed No severity/exploitability/status escalation — remains CRITICAL/ACTIVE/ACTIVE, CVSS 10.0. Report reconfirms the already-recorded Adobe APSB26-146/VULN-39341 hotfix and CVE-2026-75650 assignment rather than introducing a new sta
- 2026-09-08 — StyleSmuggler — Unauthenticated Magento/Adobe Commerce RCE Zero-Day (CVE-2026-75650): What changed No change to severity, exploitability, or status (still CRITICAL/ACTIVE/ACTIVE) and CVSS score is unchanged at 10.0. The newer report supplies the formal CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and identifies CWE
- 2026-09-08 — Magento StyleSmuggler Zero-Day (CVE-2026-75650) Exploited to Deploy Linux Backdoor: What changed CVE-2026-75650 formally assigned (CVSS 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); Adobe shipped emergency hotfix APSB26-146 on 2026-09-07. Severity/status/exploitability remain CRITICAL/ACTIVE/ACTIVE — a patch existing has not
Sources cited for StyleSmuggler
- StyleSmuggler — Full Technical Analysis (Sansec)
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- StyleSmuggler Magento Zero-Day — Disrex Incident Report
- StyleSmuggler Mitigation Repository (Disrex)
- StyleSmuggler Attack Chain — HOW-IT-WORKS (Disrex)
- Magento 2 StyleSmuggler Patch (Graycore)
- Magento and Adobe Commerce 0-Day RCE — Cybersecurity News
- Create Hosting Advisory — Critical Security Vulnerability StyleSmuggler
- StyleSmuggler IOC List (Disrex)
- StyleSmuggler Cleanup Guide (Disrex)
- ProxiBlue Unofficial Magento StyleSmuggler Patches
Detection coverage for TL-2026-2358
As of 2026-09-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2358 across Splunk SPL, Microsoft KQL and Sigma, covering 60 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.