logo

Hackers Exploiting Magento Flaw to Execute Remote Code and Seize Full Account Access

ID: 7299734f-2ae6-51bb-ad07-d639bae2043d

STIX ID: report--7299734f-2ae6-51bb-ad07-d639bae2043d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Divya

...
...

PolyShell is a critical, actively exploited vulnerability in Magento/Adobe Commerce REST API anonymous guest cart routes that allows unauthenticated attackers to upload polyglot files (e.g., GIF89a with embedded PHP) to the server, enabling stored web shells and potential remote code execution across affected versions up to 2.4.9-alpha2. Sansec observed mass scanning and exploitation beginning March 19, 2026; the report includes IOCs (filenames, hardcoded MD5 auth hashes, and attacker IPs) and urgent mitigations such as deploying a WAF and locking down pub/media/custom_options/ until official patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.