Unpatched Magento zero-day is being exploited to backdoor online stores
Attackers are actively exploiting an unpatched zero-day in Magento Open Source and Adobe Commerce to run code on stores' servers without logging in, according to e-commerce security firm Sansec, which named it StyleSmuggler. Exploitation began September 4, and every current version is affected, including the latest 2.4.9; Sansec even found a fully patched store already compromised. The attack manipulates a styles field in a GraphQL request to inject PHP into a file the platform generates normally, then installs a persistent backdoor. As of disclosure, Adobe had not issued an advisory, a CVE, or a fix, so exposed stores should be treated as at risk and watched for compromise.
- Check
- Since there is no patch, review logs for suspicious unauthenticated requests to Magento since September 4, especially style or template processing, and hunt for web shells and new admin accounts.
- Affected
- Any store on Magento Open Source or Adobe Commerce, including fully patched and latest 2.4.9 installs; an unauthenticated attacker can execute code and install a persistent backdoor, and exploitation is happening now.
- Fix
- Apply web application firewall rules against anomalous style and template requests, restrict and monitor admin and API endpoints, watch for skimmer injections and backdoors, and apply the vendor fix when it ships.