PolyShell Alert: Critical Magento REST API Vulnerability Faces Massive Global Exploitation in the Wild
ID: 0a894004-92af-5f06-9d0d-4278a4ffdf3b
STIX ID: report--0a894004-92af-5f06-9d0d-4278a4ffdf3b
Feed Name: securityonline.info
Sansec has identified an actively exploited Magento 2 REST API vulnerability dubbed "PolyShell" that abuses an unrestricted file upload to store polyglot files (image headers prepended to PHP shells), allowing unauthenticated Remote Code Execution and persistent webshells. Exploitation was observed starting March 19, 2026, with rapid automated scanning; attackers are using the access to steal customer data, deploy Magecart skimmers, and pivot into hosting environments. Adobe only published a fix in a pre-release build (2.4.9-alpha3+), so operators must immediately audit uploads, ensure web servers do not execute PHP in upload directories, and monitor REST API traffic for suspicious POST requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
