Wire Observer.
Technology

Zero‑Day Flaw in Magento and Adobe Commerce Sparks Active Exploits, No Patch Yet

Zero‑Day Flaw in Magento and Adobe Commerce Sparks Active Exploits, No Patch Yet

Security researchers have confirmed that a newly uncovered zero‑day vulnerability affecting Magento Open Source and Adobe Commerce platforms is being leveraged by threat actors to gain complete control of online storefronts. The flaw, first disclosed by Dutch e‑commerce security firm Sansec, allows remote code execution without authentication, enabling attackers to install backdoors, steal data, and manipulate transactions.

Magento and Adobe Commerce power a significant share of global e‑commerce sites, ranging from small boutique shops to large multinational retailers. Because the software is widely deployed and often customized, a vulnerability that bypasses standard defenses can have a rapid, cascading impact across the sector. Analysts estimate that thousands of sites could be vulnerable, especially those that have not applied recent security hardening measures.

Sansec’s advisory, released earlier this week, details how the vulnerability can be triggered through crafted HTTP requests that exploit a flaw in the platform’s core routing logic. The firm observed malicious activity in the wild within hours of the discovery, noting that exploit kits are already circulating on underground forums. While the exact exploit code has not been publicly released, its presence signals a high level of attacker interest and a race against time for merchants.

At present, Adobe has not issued an official patch or mitigation guidance, leaving administrators to rely on temporary workarounds such as restricting network access, disabling vulnerable modules, and monitoring for anomalous activity. Security experts advise businesses to audit logs for unexpected admin logins, enforce multi‑factor authentication, and consider third‑party web‑application firewalls to block suspicious payloads until a fix arrives.

The situation underscores broader challenges in the software supply chain, where open‑source components can become attack vectors before vendors can respond. Industry observers expect Adobe to prioritize a security update in the coming weeks, but the timeline remains uncertain. In the meantime, merchants are urged to stay vigilant, apply any interim recommendations from security firms, and prepare incident‑response plans to mitigate potential breaches.

Diya Sharma — AI & research desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related