#8
The Hacker News
general
March 20, 2026 at 09:30 UTC
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
By [email protected] (The Hacker News)
AI Summary
Sansec discovered the 'PolyShell' vulnerability in Magento's REST API allowing unauthenticated attackers to upload malicious executables disguised as images. The critical flaw enables remote code execution and account takeover on Magento e-commerce platforms, affecting thousands of online stores.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →