PolyShell - Vulnerability

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
March 19, 2026
Last Seen
March 21, 2026

PolyShell is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

PolyShell is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed March 19, 2026; most recent activity March 21, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks — Securityaffairs.Co · March 21, 2026
  • Magento stores vulnerable to 'PolyShell' exploit | brief — Scworld · March 20, 2026
  • New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e — Bleepingcomputer · March 19, 2026

Frequently asked questions

What is PolyShell?

PolyShell is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Is PolyShell still active?

The most recent intelligence report mentioning PolyShell on ThreatCluster is dated March 21, 2026. Activity was first observed March 19, 2026, giving a tracked span from then to March 21, 2026.

What is PolyShell associated with?

Across ThreatCluster reporting, PolyShell most frequently co-occurs with Cross-site Scripting, Zero-day Exploit, T1190 - Exploit Public-Facing Application, T1203 - Exploitation for Client Execution, Adobe Commerce, among 8 tracked related entities.

What are the latest developments involving PolyShell?

The most significant recent cluster is “Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover” (10 articles · Updated March 20, 2026). PolyShell appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on PolyShell?

PolyShell appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown