Wire Observer.
Technology

Zero-Day in Magento and Adobe Commerce Enables Silent Server Hijack, Security Firm Warns

Zero-Day in Magento and Adobe Commerce Enables Silent Server Hijack, Security Firm Warns

A newly discovered zero‑day flaw affecting Magento Open Source and Adobe Commerce is being weaponised by threat actors to execute arbitrary code on e‑commerce servers without needing valid credentials, a security advisory released on September 5 revealed.

The vulnerability, which remains unpatched, permits remote code execution by injecting malicious payloads directly into the application stack. Attackers can therefore install backdoors, modify site content, or exfiltrate data while evading typical authentication checks.

Sansec, a Dutch e‑commerce security consultancy, disclosed the active exploitation in its advisory, noting that the exploit chain appears to bypass standard logging mechanisms, making detection challenging for site operators. The firm urged merchants to treat the issue as an immediate emergency.

Magento powers a substantial portion of the world’s online storefronts, from small boutiques to large enterprises, while Adobe Commerce represents its premium, enterprise‑grade offering. Their widespread adoption creates a lucrative target for cyber‑criminals seeking to compromise high‑traffic retail sites.

Potential consequences of a successful breach include theft of customer payment information, installation of ransomware, or the insertion of malicious advertisements that can damage brand reputation and lead to regulatory penalties. The silent nature of the attack amplifies the risk, as operators may remain unaware until significant damage has occurred.

At the time of the advisory, Adobe had not issued a public patch. The company advised administrators to apply any available security hardening measures, such as restricting file permissions, employing web‑application firewalls, and monitoring for anomalous traffic. Security researchers recommend that affected merchants prioritize updating to the latest versions once they become available and consider third‑party scanning tools to identify signs of compromise.

Source: feedburner
Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related