Vulnerabilities · 191 days ago
Magento Open Source and Adobe Commerce (Magento 2.x) contain a file-upload flaw dubbed "PolyShell" that allows unauthenticated remote code execution and account takeover.
2 sources covering this story
PolyShell attacks target 56% of all vulnerable Magento stores
Attacks leveraging the 'PolyShell' vulnerability in version 2 of Magento Open Source and Adobe Commerce installations are underway, targeting more than half of all vulnerable stores.
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Magento flaw allows unauthenticated file uploads up to 2.4.9-alpha2, enabling RCE or takeover, exposing stores to attack risk.
New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores
A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover.
Part of the PlainSec briefing for 2026-03-26