Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover

Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover

First seen 20 Mar 2026, 22:27 UTC BleepingcomputerScworldSecurityaffairs.CoGbhackersCybersecuritynews+3 83% similarity 70.5

Article Content

Browse articles
ThreatCluster

A newly disclosed vulnerability named 'PolyShell' affects all stable versions of Magento Open Source and Adobe Commerce, allowing unauthenticated remote code execution (RCE) and account takeover. The flaw arises from the handling of file uploads in Magento's REST API, specifically when a product option is set to type 'file'. Attackers can upload a polyglot file that functions as both an image and a script, potentially leading to severe security breaches. Although Adobe has released a fix in an alpha version of 2.4.9, production versions remain vulnerable. eCommerce security firm Sansec warns that exploit methods are already circulating, and automated attacks are anticipated soon. Store administrators are advised to restrict access to the upload directory and verify web server configurations until a patch for production versions is available.

Key Points: • The 'PolyShell' vulnerability allows unauthenticated RCE and account takeover on Magento systems. • Adobe has released a fix in an alpha version, but production versions are still vulnerable. • Sansec warns of circulating exploit methods and expects automated attacks to commence soon.

ThreatCluster AI

Timeline

2026-03-19
Bleeping Computer reports on the PolyShell vulnerability
2026-03-20
Scworld publishes brief on the PolyShell exploit

Community

Browse all →