logo

New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores

ID: 21321f36-6977-5728-98fc-401cb91276ae

STIX ID: report--21321f36-6977-5728-98fc-401cb91276ae

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical vulnerability named "PolyShell" affects Magento Open Source and Adobe Commerce v2 installations by allowing unauthenticated file uploads via the REST API custom options feature; crafted polyglot files can act as images and scripts enabling RCE or stored XSS/account takeover depending on webserver configuration. Adobe provided a fix only in an alpha release (2.4.9 alpha), exploit methods are reported to be circulating though no active exploitation has been observed yet, and immediate mitigations include restricting access to pub/media/custom_options/* and scanning for uploaded shells.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.