Saturday, 5 September 2026
Sansec reports an unpatched, actively exploited zero-day backdooring Magento and Adobe Commerce stores
A no-login remote code execution flaw in Magento Open Source and Adobe Commerce is under active exploitation with no fix available, the day's most urgent item among a run of exploited flaws and breaches.
The Hacker News reports that attackers are exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on a store's server without logging in. The report attributes the discovery to Dutch e-commerce security firm Sansec, which published its advisory on September 5 and said the flaw is being used to backdoor online stores. There is no patch. If you run Magento Open Source or Adobe Commerce, follow Sansec's advisory, watch server-side file writes and unexpected admin or process activity, and treat any exposed storefront as a live target until a vendor fix ships.
Several other products are named as under attack. SecurityWeek reports that a vulnerability in the Elementor Pro WordPress plugin, described as an arbitrary file upload issue in the function that handles form submissions, is being exploited to hack sites. The Hacker News reports, citing the Arctic Wolf Adversary Research Team, that attackers are exploiting newly disclosed PaperCut flaws — an authentication bypass and a remote code execution bug — to steal credentials in attacks on the education sector in the U.S. and Europe. BleepingComputer reports that a cybercriminal operation is using thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain.
On patched flaws: The Hacker News reports that Broadcom released security updates for VMware Workstation and Fusion, including a critical integer-overflow bug that a local attacker could use to execute code on the host; apply Broadcom's updates. SecurityWeek reports that HPE patched critical remote code execution flaws in AOS-CX that an unauthenticated attacker could exploit by sending crafted packets to achieve RCE with elevated privileges; apply HPE's updates.
Two disclosures round out the day. The Hacker News reports that JetBrains is urging Cadence users to immediately revoke or rotate all credentials after threat actors exploited a recently disclosed critical TeamCity vulnerability to breach its environment and extract AWS credentials. The Hacker News also reports that Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' names, email addresses, phone numbers, shipping addresses, and order numbers.
Sources
- The Hacker News — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- BleepingComputer — Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
- SecurityWeek — Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
- Schneier on Security — Friday Squid Blogging: Squid on a Stick at the New York State Fair
- The Register — ASCII smuggling isn't just an AI security risk
- The Hacker News — Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- The Hacker News — Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- The Hacker News — Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
- SecurityWeek — HPE Patches Critical RCE Vulnerabilities in AOS-CX
- BleepingComputer — OpenAI admits it didn't disclose rogue AI wiki hijacking incident
- The Hacker News — Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
- The Hacker News — Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.