Skip to content
feed: live
>_0dayNews
adobe
● Breaking

Magento Zero-Day Exploited to Backdoor Online Stores

Attackers exploit an unpatched unauthenticated RCE in Magento Open Source and Adobe Commerce to install backdoors in online stores. No patch available.

Magento Zero-Day Exploited to Backdoor Online Stores
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Exploitation confirmed. An unpatched vulnerability in Magento Open Source and Adobe Commerce enables unauthenticated code execution on the store server. Observed payload: backdoor installation. No CVE assigned. No patch from Adobe.

Source: The Hacker News, September 5.

Confirmed

Unauthenticated access: no credentials required to trigger the flaw. Active exploitation in the wild. Observed attacker objective is backdoor installation, not opportunistic scanning.

Pending

No CVE identifier. Affected version ranges not specified in available reporting. No vendor attribution. No Adobe advisory as of September 6.

No fix available

No patch exists. Unpatched with confirmed active exploitation means no fix to apply: mitigations only, not remediation.

Unauthenticated code execution on a commerce server gives an attacker access to database credentials, server configuration, and the ability to install persistent implants.

Prior campaigns

Adobe Commerce saw a separate exploitation campaign in August against CVE-2026-71362, patched after confirmed exploitation. A CVSS 10.0 RCE in Adobe Campaign Classic shipped in the same patch cycle. The Adobe commerce stack has been under sustained attacker attention this quarter. This zero-day adds an unpatched front.

Adobe’s security advisory page is the source for patch timing. No advisory posted as of this writing.

Found this useful? Share it.