Vulnerability

StyleSmuggler Zero‑Day Exploits Magento, Adobe Commerce – Active Attacks, No Patch Yet

⏱️ 4 min read📅 9/6/2026👁️ 28 views

StyleSmuggler is already in the wild

An unauthenticated code‑execution vulnerability dubbed StyleSmuggler hit Magento Open Source and Adobe Commerce on September 4 , 2026, and attackers have been leveraging it for at least a day.

Why it matters now

Adobe has not published an advisory, CVE identifier, patch, or workaround as of September 6 2026. The next scheduled security release is slated for September 8, but there is no confirmation it will address the bug. In the meantime, two Magento stores were breached within an eight‑hour window after the first exploitation.

Technical walk‑through

Sansec reproduced a full unauthenticated exploit chain on clean installations of Magento Open Source 2.4.7, 2.4.8 and 2.4.9. The first known victim ran 2.4.6‑p15 with July and August 2026 security updates applied, showing that patch level did not stop the attack.

The payload drops a background process that masquerades as [kworker/u:8:0], runs under a non‑root user, and lives at ~/.local/share/.gvfsd/gvfsd‑user. A cron job executes it every five minutes:

*/5 * * * * exec $HOME/.local/share/.gvfsd/gvfsd‑user

Network indicators point to a command‑and‑control server at 247.cdnflare.xyz (IP 99.84.67.186) with additional source IPs 88.216.72.181 and 5.181.86.133. SHA‑256 hashes of the implant files have been published by both Sansec and Disrex.

Who is seeing the impact

Both Magento Open Source and Adobe Commerce are in scope. Confirmed compromises involve:

  • Store A – Magento 2.4.8, a Sansec Shield customer
  • Store B – Magento 2.4.7‑p2, not a Shield customer

Sansec has not released a reproduction on Adobe Commerce or Adobe Commerce on Cloud, and Adobe has not confirmed which versions are vulnerable.

Immediate defensive steps

With no official fix, the community is relying on mitigations:

  • Temporarily disable the GraphQL endpoint – the attack surface Sansec identified.
  • Deploy unofficial patches from Disrex, ProxiBlue, or Graycore.
  • Apply web‑server rules (nginx/Apache) that block the malicious query‑string parameters; note that POST/JSON bodies can still bypass them.
  • Use the composer‑patch from Disrex to guard three Magento dependency‑injection scanner methods – it may break the mageplaza/module‑admin‑permissions module.
  • Sansec Shield customers can run the eComscan scanner (v1.9.7) to detect and terminate the rogue process.

Organizations should also monitor the IOCs above, audit cron jobs for unexpected entries, and ensure any custom modules are not inadvertently loading the vulnerable scanner methods.

#Magento#Adobe Commerce#Zero-Day#StyleSmuggler#GraphQL#Backdoor