TechRadar News.
Technology

Zero‑Day Bug in Magento and Adobe Commerce Prompt Active Exploits, Patch Still Unavailable

Zero‑Day Bug in Magento and Adobe Commerce Prompt Active Exploits, Patch Still Unavailable

Security analysts have verified that a freshly identified zero‑day vulnerability in Magento Open Source and Adobe Commerce is already being abused by attackers to seize total control of e‑commerce sites. The issue, initially reported by the Dutch e‑commerce security company Sansec, permits unauthenticated remote code execution, giving malicious actors the ability to plant backdoors, exfiltrate information, and alter transactions.

Magento and Adobe Commerce run a large portion of the world’s online stores, from modest boutique outlets to sprawling multinational chains. Their broad adoption and frequent customizations mean that a flaw capable of evading normal safeguards can spread quickly and cause a chain reaction throughout the industry. Experts reckon that thousands of installations may be at risk, particularly those that have not implemented the latest hardening steps.

In an advisory issued earlier this week, Sansec explained that the bug can be activated by specially crafted HTTP requests targeting a defect in the platform’s core routing logic. The company detected hostile activity in the wild mere hours after the flaw’s identification and reported that exploit kits are already being shared on underground forums. Although the full exploit code has not been made public, its existence indicates strong attacker interest and puts merchants on a tight timeline.

So far, Adobe has not released an official fix or mitigation advice, forcing administrators to depend on interim measures like limiting network exposure, turning off the affected modules, and watching for irregular behavior. Security specialists recommend that companies scrutinize logs for atypical admin sign‑ins, enable multi‑factor authentication, and possibly deploy third‑party web‑application firewalls to filter malicious payloads until a proper patch is delivered.

The episode highlights the wider issue of software‑supply‑chain risk, where open‑source pieces can turn into attack surfaces before vendors can react. Observers anticipate that Adobe will place a security update at the top of its agenda in the next few weeks, though no exact schedule has been set. Meanwhile, merchants are advised to remain alert, follow any provisional guidance from security firms, and ready incident‑response strategies to curb possible breaches.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related