A zero-day vulnerability in Adobe Commerce and Magento is being actively exploited to install backdoors in online stores, cybersecurity firm Sansec reports.
The vulnerability (CVE-2026-75650), dubbed StyleSmuggler, allows attackers to inject PHP code into Magento’s template system and execute it without user interaction. The attack begins by triggering a failure report, after which Magento runs the malicious code through a failed-payment email.
Sansec says attacks began on September 4, targeting Magento versions 2.4.7, 2.4.8 and 2.4.9, including systems with recent July and August 2026 security patches. Attackers installed a Rust-based backdoor that connects to a command-and-control server and waits for instructions.
The malware initially disguised itself as “kworker/u:8:0” and later appeared as “fc-cache.” It hides its communications as NTP traffic and collects information about the infected server, including the hostname, username, operating system and public IP address.
Adobe released an emergency hotfix on September 7 for CVE-2026-75650. The flaw affects Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9.
Adobe recommends merchants install the hotfix and rotate their encryption key and all credentials protected by it, including administrator passwords, API keys, payment credentials, database passwords and SSH keys. Simply changing the encryption key is not enough to invalidate information that attackers may have already stolen.