The PolyShell Threat: A Critical Zero-Day Alert for Magento & Adobe Commerce
A new critical vulnerability, dubbed PolyShell, has sent shockwaves through the e-commerce community. Disclosed in March 2026, this zero-day exploit allows unauthenticated Remote Code Execution (RCE), giving attackers the keys to your storefront without needing a single login credential. What is PolyShell? The vulnerability (tracked under APSB25-94) targets the Magento REST API. It exploits the…

