$ techbeacon▋
Ransomware

Zero-Day in Magento and Adobe Commerce Enables Unauthenticated Server Takeover, Security Firm Warns

Zero-Day in Magento and Adobe Commerce Enables Unauthenticated Server Takeover, Security Firm Warns

A newly discovered zero‑day flaw affecting both Magento Open Source and Adobe Commerce is already being leveraged by cybercriminals to run arbitrary code on vulnerable storefronts. The vulnerability, which does not require a valid login, gives attackers direct access to the underlying server, according to a security advisory released by Dutch firm Sansec on September 5. Researchers say exploitation appears to be active in the wild.

The flaw bypasses typical authentication checks by injecting malicious payloads through a publicly reachable endpoint. Once the code is executed, the intruder can install a persistent backdoor, modify site content, or exfiltrate customer data without triggering conventional alerts. Because the vulnerability resides in the core framework rather than a third‑party extension, it potentially affects any installation that has not been updated since the issue was first identified.

Magento powers a substantial share of online retail platforms worldwide, and Adobe Commerce, its commercial counterpart, is favored by large enterprises for its extensibility. The popularity of the platform has historically made it a frequent target for ransomware gangs and data‑theft operations. Prior incidents, such as the 2019 “Magento Shoplift” breach, demonstrated how attackers can exploit unpatched components to compromise thousands of merchants in a short period.

Sansec’s advisory urges merchants to apply any available security updates immediately and to monitor server logs for suspicious activity, including unexpected PHP processes or outbound connections to unknown hosts. The firm also recommends deploying a web‑application firewall configured to block known malicious request patterns and conducting regular integrity checks of core files. At the time of publication, Adobe had not issued an official patch, prompting security teams to rely on temporary mitigations and heightened surveillance.

The emergence of this zero‑day underscores the ongoing risk that e‑commerce operators face when running complex, third‑party software. For retailers, a successful compromise could lead to loss of customer trust, regulatory penalties, and direct financial damage. Industry observers expect Adobe to prioritize a fix, while analysts warn that attackers may continue to sell exploit kits until an official remedy is widely deployed. In the meantime, merchants are advised to review their incident‑response plans and consider additional layers of protection such as runtime application self‑protection (RASP) tools.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related