132,158 Observable Magento Stores: Sizing the Population Exposed in the StyleSmuggler Window
Opening
CVE-2026-75650 (StyleSmuggler) was exploited from 4 September 2026, and Adobe's hotfix VULN-39341 arrived on 7 September. Between those dates, every internet-reachable Adobe Commerce or Magento Open Source deployment was in the exposure window, and the post-compromise Rust backdoor survives patching. Sizing that population with a real measurement beats estimating it. On 19 September 2026, the ZoomEye query app="Magento" returned 132,158 observable services.
Context and method
The query used the official app fingerprint field with sub_type=all and requested country and port facets. A fingerprint match means the platform's scanning vantage observed Magento characteristics on the service. It does not mean the deployment ran a vulnerable version during the exposure window - version data is not included in this query - and it does not count stores behind CDNs, which the Magento population intersects heavily.
What the facets show
Country facet:
- United States: 61,553
- Germany: 12,101
- United Kingdom: 7,612
- China: 4,982
- Belgium: 4,916
- The Netherlands: 4,456
- France: 4,448
- Ireland: 3,932
- Singapore: 3,770
- India: 3,012 Port facet:
- Port 443: 60,327
- Port 80: 50,995
- Port 8080: 5,367
- Port 8443: 2,783
- Port 2086: 1,445 (a cPanel-associated port)
- Port 2082: 1,422
- Port 2052: 1,409 Two distributions carry information for incident-response planning. The country concentration (46.6% US in the top-10 subset) reflects where the e-commerce hosting market concentrates, and matches where Sansec observed exploitation. The cPanel-associated ports (2082/2086/2095 together over 4,200 services) indicate shared-hosting Magento deployments, a segment that typically patches slowest and has the least in-house incident-response capability - the exact population the StyleSmuggler backdoor persistence model targets.
From population to prioritization
The measurement converts to a work queue in three steps:
- Version triage. Fingerprint match is not version data. Stores that applied VULN-39341 before 7 September were in the window; stores that applied it after were in it longer. Order internal stores by hotfix application date, not by alarm level.
-
Persistence sweep. The Rust backdoor impersonates kernel threads (
[kworker/u:8:0],fc-cache,chronyd) and communicates over UDP 123 as fake NTP. Sweeppub/mediafor PHP, check process tables for those names, and review egress for UDP 123 regardless of patch date. - Shared-hosting follow-up. The cPanel-port population deserves separate follow-up: those operators often cannot sweep their own hosts and depend on the hosting provider.
Limits
This count bounds the observable population, not the victim count. Sansec and Disrex observed exploitation within minutes of disclosure in at least one incident, which suggests the actual exploited subset was small but fast-moving. The fingerprint also cannot see stores behind CDN fronts or on private networks. The number is a denominator for risk conversations, not a victim list.
References
- ZoomEye v2 API responses recorded 2026-09-19:
app="Magento"with country and port facets - Adobe APSB26-146 and hotfix VULN-39341 (exploitation from 4 September 2026, hotfix 7 September 2026)
- Sansec StyleSmuggler research and Disrex incident timeline
- CISA KEV entry for CVE-2026-75650, added 8 September 2026
Top comments (0)