A critical Magento vulnerability dubbed PolyShell allows unauthenticated attackers to upload arbitrary files through the platform's REST API by disguising malicious payloads as image uploads in cart item custom options. The issue affects all stable versions of Magento Open Source and Adobe Commerce, and stems from Magento writing base64-encoded file data to a server-accessible upload directory, creating a path to compromise without prior authentication.
Depending on web server configuration, successful exploitation can lead to remote code execution or account takeover through stored cross-site scripting. Adobe addressed the flaw in the 2.4.9 pre-release branch under APSB25-94, but no standalone production patch is available, leaving current deployments exposed. Researchers at Sansec said exploit methods are already circulating and warned that automated attacks are likely, urging administrators to restrict access to the affected upload directory, verify web server protections, and scan stores for web shells or other malware.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
By 2026-03-25, Sansec reported that PolyShell exploitation had escalated to impact 56.7% of vulnerable Magento and Adobe Commerce stores. The researchers also observed some attacks deploying a new payment card skimmer that used WebRTC and DTLS-encrypted UDP to evade common web security controls, with one detected victim described as a major car maker's e-commerce site.
Security reporting said exploit techniques for PolyShell were already circulating, raising the likelihood of imminent automated attacks against exposed Magento stores. At the time of reporting, there was no evidence of active exploitation.
Sansec publicly disclosed a critical Magento REST API vulnerability dubbed PolyShell that affects all stable Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2. The flaw allows unauthenticated arbitrary file uploads disguised as images and can lead to remote code execution or account takeover depending on server configuration.
Adobe addressed the PolyShell file-upload vulnerability in the 2.4.9 pre-release branch via APSB25-94. The fix was not available as a standalone patch for current production Magento Open Source and Adobe Commerce versions.
Sansec reported that PolyShell was being actively exploited against Magento and Adobe Commerce stores, with mass automated scanning starting on 2026-03-19. The activity involved more than 50 IP addresses targeting 23% of protected stores, marking a shift from circulating exploit methods to observed real-world attacks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.