Hackers Exploiting Magento Flaw to Execute Remote Code and Seize Full Account Access
ID: 7299734f-2ae6-51bb-ad07-d639bae2043d
STIX ID: report--7299734f-2ae6-51bb-ad07-d639bae2043d
Feed Name: GBHackers
PolyShell is a critical, actively exploited vulnerability in Magento/Adobe Commerce REST API anonymous guest cart routes that allows unauthenticated attackers to upload polyglot files (e.g., GIF89a with embedded PHP) to the server, enabling stored web shells and potential remote code execution across affected versions up to 2.4.9-alpha2. Sansec observed mass scanning and exploitation beginning March 19, 2026; the report includes IOCs (filenames, hardcoded MD5 auth hashes, and attacker IPs) and urgent mitigations such as deploying a WAF and locking down pub/media/custom_options/ until official patches are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
