PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks

2026-03-21T14:51:51Z9184d55e6bb2ace6e819131a83ac772e30f482035c30fe2f8e8cc879a6cb1442
account-takeoveradobe-commerceaisurubotnetciscocorunacve-2025-66376cve-2026-20131darksworddata-breachdefacementfile-uploadios-exploit-kitiotjackskidkimwolflaw-enforcementmagentonaviapolyshellstrava-opsecubiquitiunifixsszimbra

What happened

Multiple high-impact security events: Sansec disclosed “PolyShell,” a critical unauthenticated file-upload (and possible XSS) flaw in the Magento/Adobe Commerce REST API affecting versions up to 2.4.9-alpha2; a large defacement campaign has altered 7,500+ Magento sites across ~15,000 hostnames. Navia Benefit Solutions reported a breach exposing ~2.7M people. Apple warned of active exploit kits (Coruna, DarkSword) targeting outdated iPhones; DarkSword is being used broadly. U.S. law enforcement disrupted C2 infrastructure for several IoT botnets (AISURU, Kimwolf, JackSkid). A Strava OPSEC leak暴

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9184d55e6bb2ace6e819131a83ac772e30f482035c30fe2f8e8cc879a6cb1442
Enrichment time
2026-03-21T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks · Baitaphish