logo

PolyShell Alert: Critical Magento REST API Vulnerability Faces Massive Global Exploitation in the Wild

ID: 0a894004-92af-5f06-9d0d-4278a4ffdf3b

STIX ID: report--0a894004-92af-5f06-9d0d-4278a4ffdf3b

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

Sansec has identified an actively exploited Magento 2 REST API vulnerability dubbed "PolyShell" that abuses an unrestricted file upload to store polyglot files (image headers prepended to PHP shells), allowing unauthenticated Remote Code Execution and persistent webshells. Exploitation was observed starting March 19, 2026, with rapid automated scanning; attackers are using the access to steal customer data, deploy Magecart skimmers, and pivot into hosting environments. Adobe only published a fix in a pre-release build (2.4.9-alpha3+), so operators must immediately audit uploads, ensure web servers do not execute PHP in upload directories, and monitor REST API traffic for suspicious POST requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.