New Magento Vulnerability Exposed: Unofficial Fixes Released Amid Active Exploitation
September 5, 2026
Two active incident-response groups, Sansec and Disrex, have documented indicators (files, cron entries, network IOCs, and sample hashes) and provided mitigation steps; Disrex has published multiple patches and mitigations that attempt to neutralize the chain, though none are official fixes from Adobe.
The infection chain involves planting PHP code via Magento’s own processes and triggering execution through Magento’s Payment Transaction Failed Reminder email, enabling a backdoor to run a Rust-based implant under a non-root process; indicators include a specific kernel-thread-like process name and files in user home directories and /tmp directories.
All current versions of Magento/Open Source and Adobe Commerce are affected, including 2.4.9, with confirmed exploits on installations of 2.4.6-p15 through 2.4.9; no Adobe advisory or CVE yet as of early September, and Adobe’s next security release was scheduled for September 8.
Some stores reported only partial or no exploitation at times, and eComscan, Sansec’s scanner, can detect and terminate the implant in Shield-enabled environments; the broader fix depends on Adobe releasing an official patch or workaround.
Mitigations include temporarily disabling GraphQL for Shield customers, applying unofficial patches from Disrex, ProxiBlue, and Graycore, and server hardening measures such as disabling proc_open, mounting /tmp, /var/tmp, and /dev/shm with noexec, and enforcing additional PHP function disablement; these mitigations are not a full fix and must be reevaluated as the exploit chain evolves.
Observations from Disrex and Sansec indicate the backdoor can operate without outbound connections in some variants, and in at least one case the implant leveraged Redis session storage and manipulated log files; several indicators and IOCs (process names, file paths, domain, and IPs) have been published for detection.
Industry responses include incident notices from hosting providers Nexcess and Liquid Web acknowledging review and precautionary measures; Adobe, Sansec, and others have been contact for comment, with ongoing updates anticipated as more details and fixes emerge.
Sansec reports a new unpatched vulnerability in Magento Open Source and Adobe Commerce, dubbed StyleSmuggler, that allows unauthenticated code execution and backdoor installation on online stores; attacks began on September 4 and were actively exploiting as of September 5-6.
Summary based on 1 source
Get a daily email with more Tech stories
Source

The Hacker News • Sep 5, 2026
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores