Attackers are actively backdooring online stores through an Adobe Commerce flaw

Online stores face potential server takeover and payment-system exposure through an actively exploited weakness in Adobe Commerce and Magento.

This is a Daily Cyber dot News update, brought to you by Bare Metal Cyber dot com, for Wednesday, September 9th, 2026.

Online stores face potential server takeover and payment-system exposure through an actively exploited weakness in Adobe Commerce and Magento. Adobe released an emergency fix for this maximum-severity issue after attacks were observed from at least September 4th. One campaign used it to plant a backdoor. A second attacker was seen deploying a small PHP web shell with different tooling. CISA added the issue to its Known Exploited Vulnerabilities catalog on September 8th.

Applying the patch closes the entry point, but it doesn’t remove access an attacker may already have established. Leaders should treat affected commerce servers as potential incidents because those systems support revenue, customer activity, and sensitive integrations. Defenders should install the hotfix, hunt for unexpected files and processes, and review the reported failed-payment reminder emails. Adobe also advises rotating administrator passwords, payment credentials, database credentials, tokens, keys, and other secrets after the fix is installed. The recommended response is immediate patching followed by compromise assessment and full rotation of every secret the server could access.

For the sources and the full Daily Cyber newsletter, visit Daily Cyber dot news.

Attackers are actively backdooring online stores through an Adobe Commerce flaw
Broadcast by