Swapupdate · Technology
Attackers are exploiting a new unpatched vulnerability in Magento Open Source
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce. A successful attack gives the attacker code execution on the store’s server and installs a persistent backdoor. As of September 6, Adobe has not published an advisory, a CVE identifier, a patch, or a workaround, and its Adobe Commerce security bulletin index lists nothing after the August 11 update.
Why it matters. Active exploitation of an unpatched zero-day vulnerability in popular e-commerce platforms poses severe risks of server compromise and data theft for online businesses.
- Attackers are exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce.
- Successful exploitation leads to remote code execution and the installation of persistent backdoors.
- Adobe had not released an advisory, patch, or CVE identifier for the flaw as of September 6.
Licensed summary · LicensedSummary