PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks
2026-03-21T14:51:51Z•9184d55e6bb2ace6e819131a83ac772e30f482035c30fe2f8e8cc879a6cb1442
account-takeoveradobe-commerceaisurubotnetciscocorunacve-2025-66376cve-2026-20131darksworddata-breachdefacementfile-uploadios-exploit-kitiotjackskidkimwolflaw-enforcementmagentonaviapolyshellstrava-opsecubiquitiunifixsszimbra
What happened
Multiple high-impact security events: Sansec disclosed “PolyShell,” a critical unauthenticated file-upload (and possible XSS) flaw in the Magento/Adobe Commerce REST API affecting versions up to 2.4.9-alpha2; a large defacement campaign has altered 7,500+ Magento sites across ~15,000 hostnames. Navia Benefit Solutions reported a breach exposing ~2.7M people. Apple warned of active exploit kits (Coruna, DarkSword) targeting outdated iPhones; DarkSword is being used broadly. U.S. law enforcement disrupted C2 infrastructure for several IoT botnets (AISURU, Kimwolf, JackSkid). A Strava OPSEC leak暴
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9184d55e6bb2ace6e819131a83ac772e30f482035c30fe2f8e8cc879a6cb1442
- Enrichment time
- 2026-03-21T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.