Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
adobe
1 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Attackers are actively exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce, allowing them to execute arbitrary code on affected servers without requiring authentication. Dutch e-commerce security firm Sansec, which discovered the flaw and dubbed it StyleSmuggler, issued an advisory on September 5 after observing the first attacks on September 4.

    The zero-day enables remote code execution (RCE) by smuggling malicious payloads through what Sansec describes as a previously unknown attack vector. This allows threat actors to backdoor online stores and potentially steal payment data or compromise the entire infrastructure underlying the e-commerce platform.

    • Both Adobe Commerce and Magento Open Source installations are at risk.
    • No official patch was available at the time of Sansec's disclosure, leaving stores vulnerable to active exploitation.
    • Sansec has stated it is publishing early indicators of compromise and mitigation guidance for merchants.

    Given the lack of a vendor-supplied fix, administrators are urged to audit their systems for signs of intrusion immediately and apply any available workarounds provided by security researchers. The exact technical mechanics of the vulnerability have not been fully disclosed to prevent further abuse while the zero-day remains open.

    Source: The Hacker News

    Is your team already taking steps to trace unauthorized file changes or review server logs for the specific attack patterns Sansec mentioned, or are you waiting for an official patch before intervening?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World