DEV Community

Cover image for StyleSmuggler Zero-Day Exploits Adobe Commerce and Magento Template Systems
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

StyleSmuggler Zero-Day Exploits Adobe Commerce and Magento Template Systems

Summary

Attackers are exploiting a zero-day vulnerability called StyleSmuggler in Adobe Commerce and Magento to execute remote code and install Rust-based backdoors. The flaw bypasses recent security patches by injecting malicious PHP into the template system via failed payment email rendering.

Take Action:

If you run Magento or Adobe Commerce, disable GraphQL immediately until you can apply the upcoming September 8 patch. Check your server for unusual background processes named fc-cache or chronyd and unexpected PHP files in pub/media. If you find signs of compromise, rotate all Magento credentials and treat the store as breached.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)