Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Magento Flaw Risks RCE and Account Security

Magento Flaw Risks RCE and Account Security

Posted on March 20, 2026 By CWS

Sansec has identified a significant security vulnerability in Magento’s REST API, enabling potential unauthenticated attackers to execute arbitrary code and compromise accounts. This flaw has been dubbed ‘PolyShell’ due to its method of disguising harmful code as an image file.

The vulnerability affects all Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2, although there have been no confirmed exploitations in real-world scenarios.

Understanding the PolyShell Vulnerability

According to the Dutch security firm Sansec, the vulnerability arises from Magento’s REST API accepting file uploads through custom cart item options. When a product option is of type ‘file,’ it processes an embedded file_info object, which includes base64-encoded file data, a MIME type, and a filename.

The file is then saved in the directory pub/media/custom_options/quote/ on the server. Depending on the server setup, this flaw could lead to remote code execution through PHP uploads or account takeovers via stored XSS attacks.

Adobe’s Response and Remaining Risks

Adobe has addressed this issue in the pre-release version 2.4.9 as part of APSB25-94, although current production versions remain without a dedicated patch. While Adobe offers a sample web server configuration to mitigate the issue, most stores rely on custom configurations provided by their hosting services, which may not include these safeguards.

Mitigation Strategies for E-commerce Stores

To reduce potential risks, online retailers should restrict access to the upload directory pub/media/custom_options/ and ensure that their web servers, such as nginx or Apache, have rules to prevent directory access. Additionally, routine scans for web shells, backdoors, and other malicious software are recommended.

Sansec emphasizes that merely blocking directory access does not prevent malicious uploads. Therefore, employing a specialized Web Application Firewall (WAF) is crucial to enhance security measures.

In conclusion, while Adobe has taken initial steps to address the vulnerability, e-commerce sites must actively implement additional security measures to protect against potential exploits and ensure the safety of their platforms.

The Hacker News Tags:account takeover, Adobe Commerce, Cybersecurity, e-commerce, file upload, Magento, RCE, REST API, Sansec, security flaw, Vulnerability, web security

Post navigation

Previous Post: Microsoft Enhances Teams for iOS and Android
Next Post: US Links Handala Hackers to Iranian Government

Related Posts

Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released The Hacker News
New Sni5Gect Attack Crashes Phones and Downgrades 5G to 4G without Rogue Base Station New Sni5Gect Attack Crashes Phones and Downgrades 5G to 4G without Rogue Base Station The Hacker News
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale The Hacker News
54 EDR Killers Exploit Vulnerable Drivers to Evade Security 54 EDR Killers Exploit Vulnerable Drivers to Evade Security The Hacker News
Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign The Hacker News
OFAC Sanctions North Korean IT Network Exploiting Remote Jobs OFAC Sanctions North Korean IT Network Exploiting Remote Jobs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CyberSentinel AI Revolutionizes Security with 33 Tools
  • Macron Advocates Global AI Regulation at G7 Summit
  • Gravity SMTP Plugin Vulnerability Exposes API Keys
  • AutoJack Exploit Risks AI Agents with Code Execution
  • CISA Urges Fortinet Device Security Amid FortiBleed Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark