Critical StyleSmuggler zero-day flaw hits Magento and Adobe Commerce
Hackers actively exploit vulnerability to install backdoors on Linux servers
BleepingComputer1 hour ago
7 September, 17:101 min read
Users of e-commerce platforms Magento and Adobe Commerce face a severe security challenge. As reported by technology news outlet BleepingComputer, experts have identified a critical new zero-day vulnerability dubbed "StyleSmuggler". The flaw allows attackers to implant malware, specifically a backdoor, onto Linux servers.
Threat to all versions
According to information shared by BleepingComputer, the StyleSmuggler vulnerability affects all existing versions of Magento and Adobe Commerce. Attackers are already actively exploiting the flaw in real-world attacks, posing an immediate threat to the owners of online stores and web platforms.
Once inside the system, hackers can deploy a hidden access mechanism on the Linux server. This enables them to maintain persistent control over the machine and perform various unauthorized actions in the future.
Why this matters
Magento and Adobe Commerce are among the world's most popular online shopping platforms, utilised by numerous Georgian and international e-commerce stores. Because zero-day flaws often lack an official security patch at the time of active exploitation, webmasters and server administrators need to exercise extreme caution.
Security researchers are urging administrators to closely monitor security advisories from Adobe, strengthen server monitoring, and implement prompt preventive measures to safeguard their Linux infrastructure.