{"id":10064,"date":"2026-09-11T17:48:38","date_gmt":"2026-09-11T17:48:38","guid":{"rendered":"https:\/\/fortgale.com\/blog\/?p=10064"},"modified":"2026-09-13T14:04:39","modified_gmt":"2026-09-13T14:04:39","slug":"stylesmuggler-magento-0day","status":"publish","type":"post","link":"https:\/\/fortgale.com\/blog\/emerging-threats\/stylesmuggler-magento-0day\/","title":{"rendered":"Stylesmuggler magento 0day"},"content":{"rendered":"\n<!-- ============================================================\n  StyleSmuggler: the Magento 0-day that lets the shop run the attacker's code  (ADVISORY, WP Gutenberg)\n  Incollare in Gutenberg: editor a codice (Ctrl+Shift+Alt+M) \u2192 incolla \u2192 torna a visuale.\n  TITOLO (campo WP, non nel body): StyleSmuggler: the Magento 0-day that lets the shop run the attacker's code\n  Categoria: Defence \u00b7 Tag: stylesmuggler, cve-2026-75650, magento, adobe commerce, 0day, rce, rust backdoor, cron persistence\n  INTESTAZIONI DI CAPITOLO\/SEZIONE: blocchi wp:html con CSS inline (brand token, no clip-path per safecss).\n  Titoli reali <h2>\/<h3> nel DOM (SEO\/TOC ok). Nessun H1 (WP lo genera dal titolo).\n============================================================ -->\n\n\n<p class=\"wp-block-paragraph\">On 4 September 2026 at 22:20 UTC, an unauthenticated request began landing on Magento and Adobe Commerce storefronts and walking straight to remote code execution. No login. No admin session. No plugin. The flaw, tracked as CVE-2026-75650 and named StyleSmuggler, carries a CVSS of 10.0, and it was exploited in the wild for roughly three days before Adobe shipped an emergency hotfix. This is a short advisory: what the vulnerability is, how the intrusion behaves once it lands, what to look for, and what to do first.<\/p>\n\n\n\n<div style=\"background:#0A2952;border-left:5px solid #2B7BFF;padding:16px 22px;margin:40px 0 14px;border-radius:4px;overflow:hidden;\">\n<span style=\"float:left;width:48px;height:48px;line-height:48px;text-align:center;background:#2B7BFF;color:#001B3B;font-family:'JetBrains Mono',monospace;font-weight:700;font-size:21px;border-radius:6px;margin-right:18px;\">01<\/span>\n<span style=\"display:block;font-family:'JetBrains Mono',monospace;font-size:12px;letter-spacing:3px;color:#4D90FF;text-transform:uppercase;\">Chapter 01<\/span>\n<h2 style=\"margin:3px 0 0;padding:0;border:0;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:28px;font-weight:600;color:#E6F0FF;line-height:1.2;\">The vulnerability in one page<\/h2>\n<\/div>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 1.1&nbsp;&nbsp;<\/span>What is affected<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">StyleSmuggler is an unauthenticated remote code execution flaw in the Magento and Adobe Commerce template pipeline, classified as improper neutralisation of special elements in a template engine (CWE-1336). It reaches every supported branch: Magento Open Source 2.4.4 through 2.4.9, Adobe Commerce and Adobe Commerce on Cloud through 2.4.9-2026-aug, and Adobe Commerce B2B through 1.5.3-2026-aug. Adobe released the fix out of band as APSB26-146, delivered as the VULN-39341 Composer hotfix rather than a minor version bump. It was added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026.<\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 1.2&nbsp;&nbsp;<\/span>How the name earns itself<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The attack is two moves, and neither one looks like an exploit on its own. In the first move the threat actor abuses the template system&#8217;s handling of <code>styles<\/code> properties, reported to be reachable through an unauthenticated GraphQL request, to smuggle PHP source past the platform&#8217;s template safeguards and into a file Magento writes itself during normal operation: a payment failure report under <code>var\/report\/<\/code>, or an entry in <code>var\/log\/system.log<\/code>. Nothing executes yet. The code is just sitting in a log.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second move triggers Magento&#8217;s built-in Payment Transaction Failed Reminder email. Rendering that template pulls the poisoned file through code paths that exist to serve the command-line dependency-injection compiler, and the smuggled PHP runs on the server. Execution happens during template rendering, so the email never has to be delivered for the code to fire. The elegance, from the attacker&#8217;s side, is that the dangerous step is the shop performing its own routine housekeeping on a file the shop itself created.<\/p>\n\n\n\n<div style=\"background:#F2F6FF;border:1px solid #C7D9F5;border-left:4px solid #1257C7;padding:14px 20px;margin:26px 0;border-radius:4px;\">\n<p style=\"margin:0;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:15px;color:#0F1117;line-height:1.55;\"><strong>Confidence.<\/strong> The version range, CVSS and hotfix identifiers are confirmed by Adobe&#8217;s advisory. The exact injection parameter (the <code>styles<\/code> property over GraphQL) is asserted consistently by independent analysts but is not spelled out in Adobe&#8217;s bulletin, so we mark that link of the chain as high, not certain.<\/p>\n<\/div>\n\n\n\n<div style=\"background:#0A2952;border-left:5px solid #2B7BFF;padding:16px 22px;margin:48px 0 14px;border-radius:4px;overflow:hidden;\">\n<span style=\"float:left;width:48px;height:48px;line-height:48px;text-align:center;background:#2B7BFF;color:#001B3B;font-family:'JetBrains Mono',monospace;font-weight:700;font-size:21px;border-radius:6px;margin-right:18px;\">02<\/span>\n<span style=\"display:block;font-family:'JetBrains Mono',monospace;font-size:12px;letter-spacing:3px;color:#4D90FF;text-transform:uppercase;\">Chapter 02<\/span>\n<h2 style=\"margin:3px 0 0;padding:0;border:0;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:28px;font-weight:600;color:#E6F0FF;line-height:1.2;\">What lands: the backdoor<\/h2>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Code execution is the door. The payload behind it is a compiled implant: a stripped, statically linked binary of roughly 1.9 to 2.2 MB, built for both x86-64 and ARM64, so it runs on the full spread of hosting hardware without a dependency to satisfy. The sample listed in the indicators below is the <code>chronyd<\/code> variant our Threat Intelligence team pulled from internal investigations.<\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 2.1&nbsp;&nbsp;<\/span>Persistence through the cron spool<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Persistence is a cron job, but not an ordinary one. The implant writes directly to the cron spool file rather than going through the normal <code>crontab<\/code> replacement path, which sidesteps the logging that a crontab edit would otherwise leave behind. The entry re-launches the binary on a short interval, observed between five and thirty minutes across variants, so a killed process is back within the hour. An operator who checks only for recent <code>crontab<\/code> modifications, and not the spool contents, will not see it.<\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 2.2&nbsp;&nbsp;<\/span>Hiding in plain sight<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The implant does not hide from process listings, it blends into them. Early samples presented as <code>[kworker\/u:8:0]<\/code>, borrowing the bracketed naming of a Linux kernel worker thread that an administrator scrolls past by reflex. Later ones copy themselves to <code>~\/.cache\/fontconfig\/fc-cache<\/code>, a path that reads exactly like the font cache, or run as <code>gvfsd-user<\/code> and <code>chronyd<\/code>, the names of real desktop and time-synchronisation daemons. The evasion is entirely at the level of naming and location: on a busy server, a familiar name in a familiar place is the cheapest camouflage there is.<\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 2.3&nbsp;&nbsp;<\/span>Command and control shaped like normal traffic<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The command-and-control channel followed the same instinct and then went quieter. Early variants spoke TLS over WebSocket to port 443, indistinguishable at a glance from ordinary HTTPS. Newer ones drop the connection into UDP on port 123 shaped to look like NTP, reaching out to hostnames built to pass a tired eye: <code>ntp.timesync.net<\/code>, <code>time.microsft.run<\/code>, <code>pool.microsft.studio<\/code>. Before calling home the implant learns its own public address through legitimate lookup services (<code>ipify<\/code>, <code>icanhazip<\/code>, <code>ident.me<\/code>, <code>ipinfo.io<\/code>), a step that itself generates only benign-looking requests. In at least one analysed case no outbound C2 was seen at all while the implant was resident, a reminder that absence of C2 traffic is not absence of compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What the operator gets from all of this is the store, from the inside: administrative access, the Magento encryption key, REST, SOAP, GraphQL and OAuth tokens, payment-gateway API credentials, and the integrity of the checkout page itself. On an e-commerce host, that last item is the one that turns a server compromise into a skimming operation against every customer who pays.<\/p>\n\n\n\n<div style=\"background:#0A2952;border-left:5px solid #2B7BFF;padding:16px 22px;margin:48px 0 14px;border-radius:4px;overflow:hidden;\">\n<span style=\"float:left;width:48px;height:48px;line-height:48px;text-align:center;background:#2B7BFF;color:#001B3B;font-family:'JetBrains Mono',monospace;font-weight:700;font-size:21px;border-radius:6px;margin-right:18px;\">03<\/span>\n<span style=\"display:block;font-family:'JetBrains Mono',monospace;font-size:12px;letter-spacing:3px;color:#4D90FF;text-transform:uppercase;\">Chapter 03<\/span>\n<h2 style=\"margin:3px 0 0;padding:0;border:0;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:28px;font-weight:600;color:#E6F0FF;line-height:1.2;\">The threat actor, not the CVE<\/h2>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A vulnerability is a door. What decides the outcome is the threat actor walking through it, and how they work once inside. Our Threat Intelligence team tracks StyleSmuggler within a scope of 287 adversary groups and offensive tools, and has integrated the indicators below into the Fortgale Intelligence Feed for preventive blocking across our client base.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 3.1&nbsp;&nbsp;<\/span>MITRE ATT&amp;CK mapping<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Tactic<\/th><th>Technique<\/th><th>ID<\/th><\/tr><\/thead><tbody><tr><td>Initial Access<\/td><td>Exploit Public-Facing Application<\/td><td><code>T1190<\/code><\/td><\/tr><tr><td>Execution<\/td><td>Server-side template injection via <code>styles<\/code> property<\/td><td><code>T1190<\/code><\/td><\/tr><tr><td>Persistence<\/td><td>Server Software Component: Web Shell (poisoned PHP in <code>var\/report<\/code> \/ <code>var\/log<\/code>)<\/td><td><code>T1505.003<\/code><\/td><\/tr><tr><td>Execution<\/td><td>Command and Scripting Interpreter: Unix Shell<\/td><td><code>T1059.004<\/code><\/td><\/tr><tr><td>Persistence<\/td><td>Scheduled Task\/Job: Cron (direct spool write)<\/td><td><code>T1053.003<\/code><\/td><\/tr><tr><td>Defense Evasion<\/td><td>Masquerading: Match Legitimate Name or Location (kworker, fc-cache, gvfsd-user, chronyd)<\/td><td><code>T1036.005<\/code><\/td><\/tr><tr><td>Defense Evasion<\/td><td>Obfuscated Files or Information (stripped, statically linked binary)<\/td><td><code>T1027<\/code><\/td><\/tr><tr><td>Defense Evasion<\/td><td>Impair Defenses: Indicator Blocking (bypass of crontab logging)<\/td><td><code>T1562.006<\/code><\/td><\/tr><tr><td>Discovery<\/td><td>System Network Configuration Discovery: Internet Connection Discovery<\/td><td><code>T1016.001<\/code><\/td><\/tr><tr><td>Command and Control<\/td><td>Encrypted Channel (TLS\/WebSocket over 443)<\/td><td><code>T1573<\/code><\/td><\/tr><tr><td>Command and Control<\/td><td>Non-Application Layer Protocol (UDP shaped as NTP on 123)<\/td><td><code>T1095<\/code><\/td><\/tr><tr><td>Command and Control<\/td><td>Data Obfuscation: Protocol Impersonation<\/td><td><code>T1001.003<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The mapping is our analytical reconstruction from public reporting and sample analysis, at medium-high confidence; the two Execution rows share <code>T1190<\/code> because the injection and its rendered execution are one exploitation flow rather than two separate techniques.<\/p>\n\n\n\n<h3 style=\"margin:34px 0 8px;padding:6px 0 6px 14px;border-left:3px solid #2B7BFF;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:21px;font-weight:600;color:#0F1117;line-height:1.3;\"><span style=\"font-family:'JetBrains Mono',monospace;color:#1257C7;font-size:13px;letter-spacing:2px;\">&#9656; 3.2&nbsp;&nbsp;<\/span>Indicators of Compromise<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Indicator (defanged)<\/th><th>Type<\/th><th>Role<\/th><\/tr><\/thead><tbody><tr><td><code>1a3374ffac5b0a62467612f264c49792d206304d4514409c982325c91231375d<\/code><\/td><td>SHA-256<\/td><td>Implant, <code>chronyd<\/code> variant (ELF x86-64, static-pie, 2.18 MB)<\/td><\/tr><tr><td><code>15d35ff26fe5640be1ad12f3065472b95d79f4b2<\/code><\/td><td>SHA-1<\/td><td>Same sample<\/td><\/tr><tr><td><code>63290e1c707a7ff9e1c7c56428d3f656<\/code><\/td><td>MD5<\/td><td>Same sample<\/td><\/tr><tr><td><code>4352cabaa451e5a894535fbcc4d46628701303322a13745cb5479d7d0534ae8e<\/code><\/td><td>SHA-256<\/td><td>Implant, <code>kworker<\/code> variant (x64)<\/td><\/tr><tr><td><code>d2fbf9eb75c495bfea48790d3b228fab0c15a282419c3d3f5e49294c4e1a3e82<\/code><\/td><td>SHA-256<\/td><td>Implant, <code>kworker<\/code> variant (ARM)<\/td><\/tr><tr><td><code>247.cdnflare[.]xyz<\/code> \u00b7 <code>209.141.43[.]95<\/code><\/td><td>Host \/ IP<\/td><td>Payload delivery<\/td><\/tr><tr><td><code>www.incofar[.]it\/js\/jquery\/plugins\/ajaxfileupload\/mag.txt<\/code><\/td><td>URL<\/td><td>Second-stage download (compromised third party)<\/td><\/tr><tr><td><code>99.84.67[.]186:443<\/code> \u00b7 <code>windwsecurity[.]run:443<\/code><\/td><td>C2<\/td><td>TLS\/WebSocket channel<\/td><\/tr><tr><td><code>ntp.timesync[.]net<\/code> \u00b7 <code>time.microsft[.]run<\/code> \u00b7 <code>pool.microsft[.]studio<\/code> \u00b7 <code>ntp.synctime[.]to<\/code> \u00b7 <code>ntpsync[.]io<\/code> \u00b7 <code>185.157.160[.]251<\/code><\/td><td>C2<\/td><td>NTP-shaped UDP\/123 channel<\/td><\/tr><tr><td><code>~\/.cache\/fontconfig\/fc-cache<\/code><\/td><td>Path<\/td><td>Implant copy location (<code>fc-cache<\/code> variant)<\/td><\/tr><tr><td><code>var\/report\/<\/code> \u00b7 <code>var\/log\/system.log<\/code><\/td><td>Path<\/td><td>Files poisoned with PHP in stage one<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Indicators are integrated into the Fortgale Intelligence Feed and will be updated as the StyleSmuggler infrastructure evolves. For the full indicator set, or to confirm exposure of a specific store, contact us at <a href=\"mailto:info@fortgale.com\"><code>info@fortgale.com<\/code><\/a>.<\/p>\n\n\n\n<div style=\"background:#0A2952;border-left:5px solid #2B7BFF;padding:16px 22px;margin:48px 0 14px;border-radius:4px;overflow:hidden;\">\n<span style=\"float:left;width:48px;height:48px;line-height:48px;text-align:center;background:#2B7BFF;color:#001B3B;font-family:'JetBrains Mono',monospace;font-weight:700;font-size:21px;border-radius:6px;margin-right:18px;\">04<\/span>\n<span style=\"display:block;font-family:'JetBrains Mono',monospace;font-size:12px;letter-spacing:3px;color:#4D90FF;text-transform:uppercase;\">Chapter 04<\/span>\n<h2 style=\"margin:3px 0 0;padding:0;border:0;font-family:'IBM Plex Sans','Inter',sans-serif;font-size:28px;font-weight:600;color:#E6F0FF;line-height:1.2;\">What to do first<\/h2>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Immediate.<\/strong> Apply the VULN-39341 hotfix (APSB26-146) on every Magento and Adobe Commerce instance in the affected range. Understand that the patch closes the door but does not clean a store that was already entered: exploitation ran for days before the fix existed, so treat any unpatched store that was internet-facing between 4 and 8 September 2026 as potentially compromised until proven otherwise. As interim hardening, disable GraphQL until the hotfix is fully deployed, add <code>proc_open<\/code> to PHP&#8217;s <code>disable_functions<\/code>, and mount <code>\/tmp<\/code>, <code>\/var\/tmp<\/code> and <code>\/dev\/shm<\/code> with <code>noexec<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Short term.<\/strong> Hunt, do not just scan. Inspect the cron spool directly, not the <code>crontab<\/code> edit history, for entries launching binaries from user cache or temporary paths. Look for processes whose name matches a legitimate daemon (<code>kworker<\/code>, <code>fc-cache<\/code>, <code>gvfsd-user<\/code>, <code>chronyd<\/code>) but whose binary sits in an unexpected location. Grep <code>var\/report\/<\/code> and <code>var\/log\/system.log<\/code> for PHP tags. Review outbound UDP\/123 to hosts that are not your configured NTP servers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Structural.<\/strong> If compromise is confirmed, patching is the beginning, not the end. Rotate the Magento encryption key, flush session storage and Redis, and reset every secret the store held: admin passwords, REST, SOAP, GraphQL and OAuth tokens, payment-gateway API credentials, database credentials, and SSH and deploy keys. Then verify checkout-page integrity, because on an e-commerce host the credential the attacker most wants is the customer&#8217;s card, and the place they take it is the payment form.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A cyber attack is not something. It is someone. StyleSmuggler is a clean illustration: the vulnerability is a door, but what walks through is an operator who reuses tooling, dresses their process up as a system daemon, and shapes their traffic to look like the clock ticking. You do not defend against a CVE. You defend against the person using it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Knowing the adversary is the first act of defence. Stopping them in time is the second.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/fortgale.com\/en\/contact\/\">Talk to our analysts<\/a><\/strong> about StyleSmuggler exposure across your Magento estate, or <strong><a href=\"https:\/\/fortgale.com\/en\/contact\/\">request a threat briefing<\/a><\/strong> on StyleSmuggler and its indicators.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>On 4 September 2026 at 22:20 UTC, an unauthenticated request began landing on Magento and Adobe Commerce storefronts and walking straight to remote code execution. No login. No admin session. No plugin. The flaw, tracked as CVE-2026-75650 and named StyleSmuggler, carries a CVSS of 10.0, and it was exploited in the wild for roughly three &#8230; <a title=\"Stylesmuggler magento 0day\" class=\"read-more\" href=\"https:\/\/fortgale.com\/blog\/emerging-threats\/stylesmuggler-magento-0day\/\" aria-label=\"Read more about Stylesmuggler magento 0day\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":10070,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1497,3],"tags":[3372,3370,3371],"class_list":["post-10064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defence","category-emerging-threats","tag-chronyd","tag-magento","tag-stylesmuggler"],"_links":{"self":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/10064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/comments?post=10064"}],"version-history":[{"count":4,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/10064\/revisions"}],"predecessor-version":[{"id":10069,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/posts\/10064\/revisions\/10069"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media\/10070"}],"wp:attachment":[{"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/media?parent=10064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/categories?post=10064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fortgale.com\/blog\/wp-json\/wp\/v2\/tags?post=10064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}