discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security firm Sansec discovers unpatched Magento and Adobe Commerce vulnerability exploited to run malicious code and install backdoor.

By Swati Khandelwal·Sep 5·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Image: thehackernews.com

Security firm Sansec warns of Magento and Adobe Commerce vulnerability exploited, allowing attackers to run code and install backdoor without logging in.

Why it matters

This vulnerability could allow attackers to compromise online stores, impacting millions of merchants and consumers.

Bad guys found a bug in some online store software that lets them secretly take control of the store without logging in. They can do bad things like steal money or change prices.

Analysis

{"heading_1":"The Vulnerability","paragraph_1":"Sansec advises merchants to temporarily disable GraphQL until Adobe releases a fix, as headless and progressive web app storefronts require GraphQL.","paragraph_2":"Disrex found that the implant is a background process disguised under [kworker/u:8:0], with a binary installed at ~/.local/share/.gvfsd/gvfsd-user and a cron entry that restarts it every five minutes.","paragraph_3":"Both stores were contained the same day, with no evidence of data exfiltration, rogue admin accounts, or database backdoors found.","heading_2":"Impact and Detection","heading_3":"Defenses and Mitigation"}

Key points

  • Sansec discovered a new unpatched vulnerability in Magento and Adobe Commerce
  • The vulnerability allows attackers to run malicious code without logging in
  • Disrex found evidence of exploitation on two compromised stores
  • Both stores were contained quickly, with no evidence of data exfiltration or other damage
  • Sansec advises merchants to temporarily disable GraphQL until a fix is released
The Upside

With quick detection and containment, the damage from this bug can be limited, and merchants can recover their stores.

The Downside

If the bug is not caught quickly, attackers could cause significant damage, including stealing money and changing prices on many stores.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityvulnerabilitymagentoadobecybersecurity

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 5, 2026

Source

thehackernews.com

Share

Topics

securityvulnerabilitymagentoadobecybersecurity

Related

More from this desk

Sep 5·thehackernews.com

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains warns Cadence users to revoke and rotate all credentials after attackers exploited a critical vulnerability in TeamCity to breach its environment and extract AWS credentials.

Sep 5·thehackernews.com

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom patches two VMware vulnerabilities with CVSS scores of 9.3 and 8.1, allowing arbitrary code execution and buffer overflow.

Sep 5·bleepingcomputer.com

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked sites deliver ClickFix payloads stored on the BNB Smart Chain (BSC).

Sep 5·thehackernews.com

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor reveals another 67,000 U.S. customers impacted in a breach at its shipping provider ShipMonk, exposing names, email addresses, phone numbers, and order numbers from 2019-2021. Trezor requested and received assurance of data deletion, but it was not removed.