
Right now, a critical Magento PolyShell vulnerability requires your emergency attention. Simply put, it allows unauthenticated attackers to upload malicious files (e.g., .php) and bypass file upload validation. As a result, they may achieve remote code execution (RCE) and affect Magento 2 stores, depending on the configuration.
Even though a PolyShell vulnerability is a critical security flaw, there is no official patch yet. Meanwhile, let’s act now and take some protective measures. Here, we discuss how serious PolyShell is and how to test your store for this flaw. Most importantly, we provide recommended actions to help you protect your store. Let’s go over.
Continue reading →