Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe’s Magento e-commerce platform has been hit with a zero-day vulnerability that allowed attackers to deploy a backdoor and web shell, compromising user security. This critical issue affects anyone using Magento 2.x up to version 2.3.7-p1, which is used by over 250,000 online stores worldwide.

The exploit takes advantage of a previously unknown privilege escalation bug in the way Magento handles cross-domain requests between subdomains and parent domains. Essentially, this flaw allowed attackers to bypass authentication checks and elevate their privileges on vulnerable sites. With these elevated permissions, hackers could then inject malicious code – including the Rust backdoor and PHP web shell – into affected systems.

The backdoor, which was deployed using the Rust programming language, allows attackers to maintain persistent access to a compromised site even after it has been patched or updated. Meanwhile, the PHP web shell provides a convenient entry point for hackers to execute arbitrary commands on the server, effectively giving them free rein over the system. The presence of these malicious tools indicates that attackers are using this vulnerability as an active attack path to gain control and potentially spread malware.

The severity of this issue is compounded by the fact that Magento’s popularity among e-commerce platforms makes it a prime target for attackers seeking to exploit vulnerabilities in widely used software. Moreover, since the vulnerability has been described as a zero-day flaw, its existence was not previously known or accounted for by security experts, making detection and mitigation more difficult.

Given the widespread adoption of Magento and the critical nature of this vulnerability, users are advised to update their platforms immediately to the latest version (2.3.7-p1) or higher. Furthermore, administrators should thoroughly review their systems’ configuration and monitoring to detect any signs of potential attacks or malware activity.

It is crucial for online store owners and IT professionals to stay vigilant in responding to this threat and take proactive measures to protect their websites from similar vulnerabilities in the future. As we continue to see new exploits targeting widely used software, it’s essential that users remain informed about these risks and prioritize timely updates and robust security configurations to safeguard their digital assets.


Source: The Hacker News — 2026-09-08