https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/
StyleSmuggler zero-day hits Magento and Adobe Commerce A zero-day dubbed StyleSmuggler is being exploited against all Magento and Adobe Commerce versions, including fully updated systems. Observed activity uses PHP code injection in the template system to trigger code execution via #fake failed-payment emails