Back to Feed
VulnerabilitiesApr 8, 2026

‼️ Advanced Magento 2.x exploitation tool for unauthenticated RCE via polyglot file upload throug...

Advanced Magento 2.x RCE exploitation tool released leveraging polyglot file uploads.

Vendor Watch

Run Adobe?

Get an email when a reviewed story names Adobe, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy

Summary

A new exploitation tool has been publicly released that targets Magento 2.x instances, enabling unauthenticated remote code execution through polyglot file uploads via the REST API. The tool tests 45+ PHP extensions with multi-header support (PNG/GIF) to maximize exploitation coverage. This represents a significant security risk for Magento deployments lacking proper patching and input validation.

Indicators of Compromise

  • url — https://github.com/[repository-url]

Entities

Magento 2.x (product)Adobe (vendor)REST API (technology)PHP (technology)