Attackers exploit a recently disclosed zero-day vulnerability known as “StyleSmuggler” to gain remote code execution and deploy stealthy backdoors on online stores running Magento and Adobe Commerce.
SecurityWeek and Bleeping Computer both report that the vulnerability enables malicious actors to run code on affected systems and install a backdoor intended to persist undetected. Both sources describe the activity as an active exploitation campaign rather than a purely theoretical risk.
The outlets differ mainly in emphasis and detail. SecurityWeek focuses on the capability to execute code and establish a “stealthy backdoor” through the zero-day. Bleeping Computer emphasizes that the exploitation leads to the deployment of a Linux backdoor and notes that the issue affects all versions of Magento and Adobe Commerce. Across both reports, the common thread is that StyleSmuggler is being used in real-world attacks against these e-commerce platforms.