Attackers are exploiting a previously unpatched flaw in Adobe Commerce and Magento to break into online stores and plant persistent backdoors. The reported zero-day affects Adobe Commerce and Magento deployments and is being used to compromise e-commerce sites before a fix is available, letting intruders maintain access and potentially steal customer data, payment information, or alter store content. The attack appears to target internet-facing store servers.
Why it matters: This is urgent for businesses running Adobe Commerce or Magento because attackers can quietly seize control of store systems before a patch exists. Affected organizations should apply any vendor mitigations immediately, hunt for signs of compromise and webshells or backdoors, and prepare for emergency patching as soon as fixes are released.
Ionut Arghire
2026.09.07
99% relevant
This appears to be the same underlying event and adds technical detail from Sansec on the exploit chain, affected versions (2.4.7, 2.4.8, 2.4.9), observed start date of exploitation, and the Rust backdoor variants masquerading as '[kworker/u:8:0]' and 'fc-cache' with NTP-like command-and-control traffic.
info@thehackernews.com (The Hacker News)
2026.09.05
100% relevant
This article establishes a distinct new event: active exploitation of an unpatched Adobe Commerce and Magento zero-day to backdoor stores, which is different from previously tracked Adobe Commerce and Magento stories tied to other CVEs.
← Back to all stories