A critical vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to execute malicious code on e-commerce servers without authentication. The security flaw, identified by Dutch e-commerce security firm Sansec and named 'StyleSmuggler', was disclosed on September 5. It allows attackers to backdoor online stores, posing significant risks to businesses using these platforms. The attacks began on September 4, and as of September 6, Adobe has not issued a security advisory or patch to address this issue.
Sansec's findings indicate that all current versions of the affected platforms, including 2.4.9, are vulnerable. The company demonstrated the exploit on clean installations of Magento Open Source versions 2.4.7 to 2.4.9. The vulnerability allows attackers to install a persistent backdoor, disguising malicious processes under legitimate Linux kernel task names. Disrex Group, a Magento hosting and development company, confirmed the exploitation of two compromised stores and noted that headless and progressive web app storefronts relying on GraphQL are particularly at risk.
In the absence of an official patch from Adobe, Sansec recommends disabling GraphQL as a temporary mitigation measure. Disrex's independent findings have corroborated the occurrence of these attacks and highlighted the need for immediate action from merchants to protect their online stores. The company's investigation revealed that the implant did not establish any outbound connections, instead exploiting local resources to evade detection, and found no evidence of data exfiltration or unauthorized access to customer information.
Both Sansec and Disrex emphasize the urgency for online merchants to take proactive steps to secure their platforms. Adobe's next scheduled security update is on September 8, but it remains unclear if this will address the StyleSmuggler vulnerability. In the meantime, affected businesses should closely monitor their systems for indicators of compromise and consider rotating credentials to minimize the risk of further exploitation.

