If your Magento store was reachable between September 4 and the moment you applied Adobe’s hotfix, you have two jobs this week, not one. Patch, then find out whether someone already walked in. Sansec disclosed Magento StyleSmuggler on September 5. Attacks had already been running since September 4, three days before a fix existed. Here Read More
Category: TechHub
PolyShell: A New Vulnerability in Magento & Adobe Commerce
A new security vulnerability in Magento and Adobe Commerce was publicly disclosed on March 17, 2026. Named PolyShell, it allows attackers to upload executable files to any store through the REST API — without needing an account or login. No production patch exists yet, and the exploit method is already circulating.