Vulnerabilità · 190 giorni fa
La falla PolyShell nelle API di Magento 2 consente upload di file che possono portare a remote code execution o account takeover in alcune configurazioni. Sansec segnala exploit di massa: circa 56% dei negozi vulnerabili è stato colpito. Adobe ha inserito la correzione nella branch 2.4.9-beta1, non ancora distribuita sul canale stabile.
2 fonti che coprono questa storia
PolyShell attacks target 56% of all vulnerable Magento stores
Attacks leveraging the 'PolyShell' vulnerability in version 2 of Magento Open Source and Adobe Commerce installations are underway, targeting more than half of all vulnerable stores.
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Magento flaw allows unauthenticated file uploads up to 2.4.9-alpha2, enabling RCE or takeover, exposing stores to attack risk.
New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores
A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover.
Part of the PlainSec briefing for 2026-03-26