Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

2026-09-06T01:24:01Z0e5de6a8e2dac8048b6a6c95f3fcd07c9b47a0640ee59d93cb694a45813f8d6b
CVE-2026-14894CVE-2026-20212CVE-2026-59346CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-83548CVE-2026-85046Adobe CommerceCISA KEVChromeCisco NexusMagentoPaperCutPostgreSQLVMwareWordPressactive exploitationbackdoorcloud securitycredential theftdata breachdefense evasioninfostealermalwarephishingprivilege escalationrcespywaresupply-chain compromiseunauthenticated accessweb applicationszero-day

What happened

The feed reports widespread active exploitation and disclosure of critical vulnerabilities across e-commerce platforms, network infrastructure, virtualization software, databases, browsers, WordPress plugins, and enterprise applications. It also highlights phishing campaigns, malware and backdoors, credential theft, supply-chain compromise, ransomware/criminal access activity, spyware targeting, and major data breaches. Several issues are zero-days or actively exploited, including Magento/Adobe Commerce StyleSmuggler, Chrome V8, Cisco Nexus 9000, PaperCut, WordPress plugins, and CISA KEV-added

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0e5de6a8e2dac8048b6a6c95f3fcd07c9b47a0640ee59d93cb694a45813f8d6b
Enrichment time
2026-09-06T01:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.