Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Security firm Sansec discovers unpatched Magento and Adobe Commerce vulnerability exploited to run malicious code and install backdoor.
Intelligence analysis by Qwen 2.5 (3B)

Security firm Sansec warns of Magento and Adobe Commerce vulnerability exploited, allowing attackers to run code and install backdoor without logging in.
Bad guys found a bug in some online store software that lets them secretly take control of the store without logging in. They can do bad things like steal money or change prices.
Analysis
{"heading_1":"The Vulnerability","paragraph_1":"Sansec advises merchants to temporarily disable GraphQL until Adobe releases a fix, as headless and progressive web app storefronts require GraphQL.","paragraph_2":"Disrex found that the implant is a background process disguised under [kworker/u:8:0], with a binary installed at ~/.local/share/.gvfsd/gvfsd-user and a cron entry that restarts it every five minutes.","paragraph_3":"Both stores were contained the same day, with no evidence of data exfiltration, rogue admin accounts, or database backdoors found.","heading_2":"Impact and Detection","heading_3":"Defenses and Mitigation"}
Key points
- Sansec discovered a new unpatched vulnerability in Magento and Adobe Commerce
- The vulnerability allows attackers to run malicious code without logging in
- Disrex found evidence of exploitation on two compromised stores
- Both stores were contained quickly, with no evidence of data exfiltration or other damage
- Sansec advises merchants to temporarily disable GraphQL until a fix is released
With quick detection and containment, the damage from this bug can be limited, and merchants can recover their stores.
If the bug is not caught quickly, attackers could cause significant damage, including stealing money and changing prices on many stores.



