Zero‑Day in Magento and Adobe Commerce Lets Attackers Backdoor Online Stores Without a Login
Attackers are actively exploiting an unpatched zero‑day flaw in Magento and Adobe Commerce to install backdoors on online stores without needing to log in, security researchers warn. With no CVE assigned and no vendor patch yet, e‑commerce operators face a race to detect compromises and protect customer data.
A critical, previously unknown vulnerability in two of the web’s most widely used commerce platforms is being exploited in the wild, allowing attackers to silently backdoor online stores without even logging in.
Security researchers have disclosed that an unpatched zero‑day flaw in Magento and Adobe Commerce is under active attack. The exploit does not require authentication, meaning hackers can target vulnerable sites directly from the internet and gain a foothold without valid user accounts. No official CVE identifier has been published yet, and Adobe has not released a patch, leaving thousands of merchants exposed while details of the attack circulate among cybercriminals.
Magento and Adobe Commerce power a significant share of small and mid‑sized online shops, as well as some larger retail operations. By compromising the underlying platform, attackers can modify store code, inject malicious scripts, skim payment information, create hidden administrator accounts or redirect shoppers to fraudulent checkout pages. Because the attack abuses a flaw in the application logic itself, traditional defenses such as login monitoring or password hygiene offer little protection once a site is targeted.
For store owners and their customers, the immediate risk is theft of payment card data, personal information and authentication credentials. Past compromises of commerce platforms have led to months of undetected skimming, during which every transaction processed by an affected site was copied to an attacker’s server. Even after a vulnerability is fixed, victims may face chargebacks, regulatory scrutiny, class‑action lawsuits and reputational damage that outlast the technical incident.
Operationally, the zero‑day forces e‑commerce operators into a difficult position. Without a vendor patch, the emphasis shifts to temporary mitigations: tightening web application firewalls, monitoring for unusual file changes or outbound traffic, and applying community‑developed rules that try to block known exploit patterns. Many smaller businesses lack dedicated security teams and may not realize they are vulnerable—or already compromised—until banks or payment processors raise alarms.
At a systemic level, the incident underscores how much of the digital economy depends on a relatively small number of software platforms and how a single undisclosed flaw can ripple through thousands of businesses at once. Attackers understand this leverage and increasingly seek out zero‑days in popular frameworks, plugins and content management systems where a working exploit can be reused against many targets with minimal adaptation.
The episode also highlights a trust gap between vendors and merchants. With no CVE assigned and no public patch timeline, store operators must decide whether to keep processing payments on software they know is being attacked, or to take disruptive steps such as disabling certain features, switching providers or even temporarily suspending online sales.
The uncomfortable truth for consumers is that their card number is only as safe as the least‑protected store they use.
Key developments to watch include Adobe’s official acknowledgment and advisory, the release of security updates or emergency patches, and any guidance from major payment processors on handling suspected compromises. Evidence of mass card‑skimming campaigns or large‑scale credential theft linked to the flaw would indicate that attackers are successfully weaponizing the zero‑day at scale, raising the urgency for merchants to act even before a formal fix arrives.
Sources
- OSINT