Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

2026-09-08T07:23:22Z746a98439f3d431505f7386f29719e3e8644fc2f6caaaea2d15458bc889a0399
CVE-2026-19490Adobe CommerceCitrix NetScalerClickFixConnectWise ScreenConnectLinux backdoorMFA bypassMagentoMikroTik RouterOSN-able N-centralUnicode smugglingactive exploitationauthentication bypasscredential theftdata breachphishing-as-a-serviceremote code executionrouter hijackingzero-day

What happened

A BleepingComputer security-news feed reports active exploitation of multiple vulnerabilities and attack techniques, including a Magento/Adobe Commerce zero-day used to deploy a Linux backdoor, MikroTik RouterOS flaws used to hijack exposed routers, an unpatched ScreenConnect vulnerability, an actively exploited maximum-severity N-able N-central RCE flaw, and the critical Citrix NetScaler authentication bypass CVE-2026-19490. The feed also covers MFA-bypass phishing, ClickFix campaigns, Unicode-based phishing evasion, and several major data breaches.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
746a98439f3d431505f7386f29719e3e8644fc2f6caaaea2d15458bc889a0399
Enrichment time
2026-09-08T07:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Magento StyleSmuggler zero-day exploited to deploy Linux backdoor · Baitaphish