Magento Open Source and Adobe Commerce (Magento 2.x) contain a file-upload flaw dubbed "PolyShell" that allows unauthenticated remote code execution and account takeover.
Part of the PlainSec briefing for 2026-03-26