#magento


Adobe fixes critical Magento zero-day exploited to backdoor servers

Sep 8, 2026 // 16:36

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. […]

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Sep 8, 2026 // 01:17

A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. The first exploitation […]

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Sep 5, 2026 // 23:58

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server […]

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

Jun 4, 2026 // 14:26

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to […]

Magento stores heavily targeted: PolyShell exploits hit over half of vulnerable shops.

Mar 26, 2026 // 09:37

Attacks taking advantage of the ‘PolyShell’ security flaw in Magento Open Source and Adobe Commerce version 2 are active, impacting over half of susceptible online […]

Magento PolyShell: Unauth. Uploads & RCE Lead to Account Takeover (Security Flaw)

Mar 20, 2026 // 14:43

Sansec is alerting users to a serious security vulnerability in Magento’s REST API. This flaw could allow unauthorized individuals to upload harmful files, potentially leading […]

Magento stores vulnerable to remote code execution via ‘PolyShell’ bug, no login needed.

Mar 20, 2026 // 11:17

A newly discovered security flaw, called ‘PolyShell,’ impacts all stable versions of Magento Open Source and Adobe Commerce version 2. It allows unauthorized users to […]