Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Cybersecurity researchers have discovered a critical zero-day vulnerability in Magento and Adobe Commerce, two popular e-commerce platforms used by thousands of online stores. This flaw allows attackers to remotely backdoor websites, giving them full control over sensitive data and operations.

The vulnerability, which has been actively exploited since August 2026, affects versions 2.4.x and earlier of both platforms. It is a privilege escalation bug that enables an attacker to gain elevated access to the website’s administration panel, allowing them to inject malicious code, steal customer data, or take control of the entire site.

Magento and Adobe Commerce are used by over 250,000 online stores worldwide, including well-known brands such as Walmart and Home Depot. The platforms’ popularity makes them an attractive target for hackers seeking to exploit vulnerabilities in high-traffic sites. An attacker can use social engineering tactics to trick a website owner into installing a malicious plugin or file, which then exploits the zero-day flaw.

The vulnerability works by exploiting a cross-domain privilege escalation issue, allowing an attacker to bypass security measures and gain access to sensitive areas of the website’s administration panel. This could enable an attacker to inject malware, steal customer data, or even take control of the entire site. The attack path is often mapped through cross-domain privilege escalation, which can be used to sever breach routes at key choke points.

The discovery of this vulnerability highlights the importance of keeping software up-to-date and patching known security flaws in a timely manner. With thousands of online stores potentially vulnerable to exploitation, website owners are advised to take immediate action to secure their sites. This includes verifying the integrity of all installed plugins and files, applying any available patches, and ensuring that all software components are updated.

Magento and Adobe Commerce have released emergency patches for affected versions of their platforms, which should be applied as soon as possible. Website owners who rely on these e-commerce solutions must take a proactive approach to security by regularly monitoring their sites for signs of compromise and staying informed about emerging threats.


Source: The Hacker News — 2026-09-05