WHAT HAPPENED
TheCyberExpress September 7, 2026 2 min read Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 7, Adobe’s Magento security bulletin index listed no September advisory, and the flaw does not appear in CISA’s Known Exploited Vulnerabilities catalog, leaving an unknown number of merchants exposed during a window in which working exploit traffic is already circulating. Magento underpins a large share of mid-market online retail, and Adobe has sold it as Adobe Commerce since acquiring the platform in 2018. The codebase has been a durable target for payment-skimming crews: Sansec has tracked Magecart-style card theft against Magento storefronts for close to a decade, and the platform’s checkout position makes any unauthenticated code execution flaw unusually valuable. Attackers first inject PHP code into files Magento writes on its own, such as failure reports, then trigger execution through the platform’s “Payment Transaction Failed Reminder” email routine.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY