Attackers are actively exploiting a newly discovered vulnerability in Magento Open Source and Adobe Commerce platforms, allowing them to execute malicious code on store servers without authentication. Dutch cybersecurity firm Sansec identified the flaw and issued an advisory on September 5, 2026, warning that the zero-day is being used to install backdoors in live e-commerce environments. The vulnerability affects unpatched installations and requires no user interaction or login credentials to trigger. The exploit enables remote code execution through a flaw in how the platforms handle certain input parameters, which attackers can manipulate to inject and run arbitrary scripts. Sansec reported that compromised stores are being used to steal payment data, redirect customers to phishing sites, or maintain persistent access for future attacks. The company noted that the attack leaves minimal traces, making detection difficult without specialized monitoring tools.
Merchants using outdated versions are urged to apply emergency mitigations while awaiting an official patch from Adobe. How Attackers Are Gaining Silent Access to Store Servers The vulnerability stems from improper validation of user-supplied data in a core processing module, which Sansec did not fully disclose to prevent further abuse. Attackers send crafted requests that bypass security checks, triggering the execution of malicious payloads with server-level privileges. Once inside, they can modify files, create hidden administrator accounts, or deploy skimming scripts that capture credit card details at checkout. Sansec’s telemetry showed a spike in exploitation attempts within hours of the advisory release, indicating active targeting by threat actors familiar with e-commerce infrastructure. What Steps Should Merchants Take Immediately? Sansec recommends implementing a web application firewall rule to block suspicious request patterns associated with the exploit, particularly those containing unusual parameter combinations.
Store operators should also review server logs for unexpected file changes or unknown processes, especially in publicly accessible directories. While Adobe has not yet released a patch, the company confirmed it is working on a fix and advised customers to monitor official channels. In the meantime, disabling non-essential extensions and restricting admin access to trusted IPs may reduce exposure. Frequently Asked Questions Is this vulnerability present in all versions of Magento and Adobe Commerce? Sansec confirmed that the flaw affects recent versions of both platforms but did not specify exact release numbers, urging all users to treat the advisory as critical until further details are published. Can traditional antivirus software detect the malware installed via this exploit? No, the malware often operates as legitimate server processes or hides within normal file structures, making it invisible to standard endpoint protection without behavioral analysis or memory scanning.
How long has this zero-day been actively exploited before discovery? Sansec did not disclose the exact timeline but noted that the exploitation pattern suggested recent activity, with no evidence of widespread use prior to September 2026.