← Back to Tech & Science

Unpatched Magento Flaw Enables Unauthenticated Attacks on Global E-commerce Stores

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — Cyberattackers exploited a critical, unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce on Friday, gaining the ability to execute malicious code on online stores without authentication. The breach, detected late Friday evening, allows attackers to install persistent backdoors, granting them long-term access to compromised systems.

The vulnerability affects widely used e-commerce platforms powering thousands of retail websites globally. Security researchers identified that the flaw permits remote code execution, a severe capability that lets intruders run arbitrary commands on server infrastructure without needing valid login credentials. Once inside, attackers can deploy backdoors designed to maintain access even if the initial entry point is discovered and closed.

Adobe Commerce and Magento Open Source are enterprise-grade solutions utilized by businesses ranging from small retailers to major multinational corporations. The unauthenticated nature of this specific exploit means that any store running affected versions of the software is immediately at risk, regardless of the strength of its user password policies or firewall configurations. The attack vector bypasses standard authentication mechanisms entirely.

The exact scope of the compromise remains unclear as organizations scramble to assess their exposure. While the vulnerability was publicly disclosed on Friday, it is unknown how many stores have already been targeted or if data theft has occurred. The attackers' motives remain unidentified, with no claims of responsibility made by known threat groups. It is also uncertain whether the malicious code installed was intended for ransomware deployment, data exfiltration, or to serve as a staging ground for further attacks.

Adobe and the Magento community have been notified of the issue, but an official patch has not yet been released. In the interim, security experts recommend that administrators take immediate defensive measures, including isolating affected servers from public networks and monitoring for unauthorized file changes. The lack of an immediate fix leaves merchants in a precarious position, forced to rely on temporary workarounds that may not fully mitigate the risk.

The incident highlights the ongoing challenges facing e-commerce security, where supply chain vulnerabilities can impact vast numbers of independent businesses simultaneously. As the investigation continues, questions remain regarding the origin of the exploit and whether it was discovered by a specific threat actor or through automated scanning tools. The duration for which attackers may have held access prior to Friday's detection is also unknown, raising concerns about potential data breaches that may not be fully understood until forensic analysis is complete.

Discussion

0 / 2000