Published Saturday, September 05, 2026 at 05:04 PM PT

BLUF: Attackers are actively exploiting unpatched zero-day vulnerabilities in Magento and Adobe Commerce to deploy persistent backdoors and hijack customer accounts on affected e-commerce stores. Exploitation is live; patch status and scope confirmation in progress.
DETAILS:
- Multiple sources report zero-day exploitation targeting Magento and Adobe Commerce platforms; attackers achieving backdoor deployment and customer account compromise
- Adobe Commerce vulnerability (CVE-2026-71362 referenced in secondary reporting) targeted immediately post-disclosure; exploitation attempts observed within hours
- Attack vector described in related disclosures as SQL injection enabling unauthorized data access and system compromise
- Unpatched systems confirmed as primary target; patched versions reported available but deployment status across customer base unknown
- Backdoor persistence capability confirmed โ not opportunistic access, but sustained foothold establishment
IMPACT:
- Affected: Online stores running unpatched Magento and Adobe Commerce versions (scope: all versions unless patched; confirmed across NG and MF variants per related Joomla/CMS patterns)
- Risk Surface: Customer PII (accounts, payment data potentially), store operational control, supply-chain spillover (e-commerce as attack staging point)
- Timeline: Active exploitation window unknown โ report timestamp and patch release timeline not yet confirmed in provided material
RECOMMENDED ACTIONS โ IMMEDIATE:
- Audit: If running Magento or Adobe Commerce, verify patch status immediately; check for unauthorized admin accounts, API keys, or backdoor artifacts in logs (last 72 hours minimum)
- Containment: Isolate affected instances from production if unpatched; apply security patches as available from Adobe/Magento security advisories
- Monitoring: Enable real-time alerting on SQL queries, file modifications, and unauthorized account creation; review web server access logs for exploitation signatures
- Customer notification: If compromise suspected, notify customers per PCI-DSS/regional breach requirements
SOURCES:
- The Hacker News, BleepingComputer, SecurityWeek (all reporting active exploitation)
- CVE-2026-71362 referenced in secondary Adobe Commerce disclosures
- Related zero-day patterns (PaperCut, GeoServer, AnySign4PC) confirm attackers are aggressively weaponizing unpatched flaws within hours of disclosure
STATUS: Developing โ official Adobe/Magento advisory details, exact CVE-to-version mapping, and total-affected-store count pending publication. This alert will update as patch and remediation guidance becomes available.
Recent high-severity events at publish time:

