Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
2026-09-06T01:24:01Z•0e5de6a8e2dac8048b6a6c95f3fcd07c9b47a0640ee59d93cb694a45813f8d6b
CVE-2026-14894CVE-2026-20212CVE-2026-59346CVE-2026-6471CVE-2026-81578CVE-2026-82078CVE-2026-83548CVE-2026-85046Adobe CommerceCISA KEVChromeCisco NexusMagentoPaperCutPostgreSQLVMwareWordPressactive exploitationbackdoorcloud securitycredential theftdata breachdefense evasioninfostealermalwarephishingprivilege escalationrcespywaresupply-chain compromiseunauthenticated accessweb applicationszero-day
What happened
The feed reports widespread active exploitation and disclosure of critical vulnerabilities across e-commerce platforms, network infrastructure, virtualization software, databases, browsers, WordPress plugins, and enterprise applications. It also highlights phishing campaigns, malware and backdoors, credential theft, supply-chain compromise, ransomware/criminal access activity, spyware targeting, and major data breaches. Several issues are zero-days or actively exploited, including Magento/Adobe Commerce StyleSmuggler, Chrome V8, Cisco Nexus 9000, PaperCut, WordPress plugins, and CISA KEV-added
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0e5de6a8e2dac8048b6a6c95f3fcd07c9b47a0640ee59d93cb694a45813f8d6b
- Enrichment time
- 2026-09-06T01:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.