UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Magento StyleSmuggler Zero-Day RCE 2026: Patch Now

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

A newly disclosed zero-day dubbed StyleSmuggler is being actively exploited against Magento stores and affects all current versions of Magento and Adobe Commerce. Adobe later assigned the issue CVE-2026-75650. Given the unauthenticated exploitation and backdoor risk described by Sansec, UK retailers and SaaS platforms running Magento should implement robust vulnerability management and treat this as an emergency patching event.

Mitigation options before and after patching
ActionEffortRisk CutDisable GraphQLImmediateLowHighMonitor for IOCsOngoingMediumMediumRotate credentialsIf compromisedLowHighApply VULN-39341 patchPriorityLowCritical
View the data behind this chart
Mitigation options before and after patching
ActionEffortRisk Cut
Disable GraphQLImmediateLowHigh
Monitor for IOCsOngoingMediumMedium
Rotate credentialsIf compromisedLowHigh
Apply VULN-39341 patchPriorityLowCritical

What StyleSmuggler is and why it's serious

Sansec reports that it first recorded exploitation on 4 September 2026 on a Magento store running the latest security updates, and dubbed the vulnerability StyleSmuggler — highlighting that at the time, no existing patches protected against the attack. According to Adobe's APSB26-146 advisory, the vulnerability is tracked as CVE-2026-75650 and rated CVSS 10.0.

Sansec says the bug affects all current versions of Magento and Adobe Commerce. In its own advisory, Sansec reports reproducing the exploit chain on clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 installs. Given Magento's footprint — more than 160,000 live websites, including roughly 14,000 of the top one million sites globally — the potential impact on UK retail and SaaS operators is substantial.

How the attack chain actually works

Sansec reports that the exploit abuses Magento's template system through PHP code injection to generate a fake 'failed-payment' email, which triggers code execution on the server. Combined with Sansec's description of unauthenticated access, this amounts to remote code execution without requiring login credentials.

Once inside, the attackers drop a small Rust-based backdoor that runs as a background process. Early samples disguised themselves as kworker/u:8:0, while newer variants rename the process to fc-cache and copy it to the fontconfig cache directory to blend in with legitimate Linux system activity. Other researchers have reported a separate cluster of attacks abusing the same flaw to drop a PHP web shell into the product image cache, so defenders should not assume a single payload type.

  • Persistence via a cron job that re-executes the backdoor every 30 minutes
  • Command-and-control traffic disguised as NTP time-sync packets over UDP port 123
  • Public IP lookups via services such as ipify, icanhazip, ident.me and ipinfo.io
  • Checks the Linux TracerPid value to detect analysis tools; if detected, it still installs but stays silent

Patch status: what's fixed and what buyers must still do

Adobe's advised remediation is to apply the VULN-39341 patch for the affected Magento or Adobe Commerce version, and to rotate encryption keys after remediation is complete. Anyone who has already applied the fix should still treat credential and key rotation as mandatory, not optional, given the unauthenticated nature of the original exploit.

Because the backdoor can sit dormant and communicate with attacker infrastructure at any time after installation, teams should develop an incident response plan that assumes compromise may have occurred before the patch was applied, not just after.

Illustration: Magento StyleSmuggler Zero-Day RCE 2026: Patch Now

Why UK e-commerce and SaaS buyers should treat this as urgent

UK retailers running Magento or Adobe Commerce as their storefront, or SaaS providers embedding it into multi-tenant platforms, sit squarely in the affected population. An unauthenticated RCE chain that installs a covert Linux backdoor capable of receiving remote commands is precisely the scenario that PCI DSS assessors, cyber insurers and boards will want evidence of containment for — before, not after, a breach notification is required.

Sansec's observation that the malware disguises its C2 traffic as NTP packets and checks for tracing tools before beaconing shows a level of operational tradecraft that basic antivirus or default logging is unlikely to catch. This is a strong argument for buyers to managed detection & response coverage on production e-commerce infrastructure rather than relying on periodic scans alone.

Immediate actions for infrastructure teams

Until the VULN-39341 patch is fully rolled out across every affected environment, Sansec recommends disabling GraphQL as a stopgap mitigation. Teams should also audit for the specific indicators associated with this campaign and assume any hit is a live compromise requiring credential rotation.

  • Apply Adobe's VULN-39341 patch to the relevant Magento/Adobe Commerce version immediately
  • Disable GraphQL on any store not yet patched
  • Rotate all Magento admin credentials and encryption keys
  • Hunt for 'kworker' or 'fc-cache' processes, unusual cron entries every 30 minutes, and unexpected temp files
  • Watch for a surge in 'Payment Transaction Failed Reminder' emails, a known exploitation signature
  • Inspect outbound UDP traffic on port 123 for connections to unfamiliar or NTP-mimicking hostnames

The bigger lesson for retail IT infrastructure risk

StyleSmuggler follows a pattern seen repeatedly with Adobe Commerce this year: attackers finding unauthenticated code-execution paths in a platform that underpins a huge share of UK online retail revenue. Buyers who treat Magento patching as routine maintenance rather than a critical dependency are exposed disproportionately compared with the perceived risk. Building resilience means pairing rapid patch cycles with ransomware protection and backup and disaster recovery plans that assume a backdoor could already be present, alongside a longer-term move toward zero trust segmentation between storefront, payment and admin systems.

Share
Key takeaways
  • StyleSmuggler (CVE-2026-75650, CVSS 10.0) is an unauthenticated zero-day affecting all current Magento and Adobe Commerce versions, exploited since 4 September 2026.
  • Successful exploitation installs a persistent Rust-based Linux backdoor disguised as 'kworker' or 'fc-cache', with cron persistence every 30 minutes.
  • Adobe's fix is delivered via patch VULN-39341; encryption keys and Magento credentials must be rotated after remediation.
  • With over 160,000 Magento sites live, including 14,000 in the global top one million, UK retailers should treat patching, GraphQL disabling and IOC monitoring as immediate priorities.
Frequently asked

FAQs — Magento StyleSmuggler Zero-Day RCE 2026

What is the Magento StyleSmuggler zero-day?

StyleSmuggler is the name Sansec gave to CVE-2026-75650, an unauthenticated remote code execution flaw in Magento and Adobe Commerce that abuses the template system via PHP code injection triggered by a fake failed-payment email.

Is my Magento store still at risk even if fully patched previously?

Yes. Sansec observed the first exploitation against a store running the latest security updates available at the time, meaning prior patches did not cover this flaw. Only applying Adobe's VULN-39341 patch closes the specific hole.

How can I tell if my store has already been compromised?

Look for an unexpected surge of 'Payment Transaction Failed Reminder' emails, background processes named 'kworker' or 'fc-cache', suspicious cron jobs running every 30 minutes, and outbound UDP traffic to port 123 mimicking NTP servers.

What should UK e-commerce teams do right now?

Apply Adobe's VULN-39341 patch immediately, disable GraphQL as an interim mitigation if not yet patched, rotate Magento credentials and encryption keys, and audit logs for the indicators above — pairing this with develop an incident response plan in case compromise already occurred.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111