Web2Market

PolyShell: Why Magento Merchants Need More Than a Security Patch

Web2Market Team•September 28, 2026
PolyShell: Why Magento Merchants Need More Than a Security Patch

Magento and Adobe Commerce merchants have another serious security issue to pay attention to: PolyShell.

PolyShell is a file-upload vulnerability affecting Magento Open Source and Adobe Commerce. The vulnerability can allow an unauthenticated attacker to disguise a malicious file as an ordinary image and upload it to a Magento store. Depending on the server configuration, that file could potentially be used to execute code, hijack customer or administrator sessions, or remain on the server as a dormant backdoor.

The important takeaway for merchants is simple: applying a patch does not necessarily mean your Magento store is fully protected.

What Is the PolyShell Vulnerability?

Magento allows merchants to offer file-upload options for products — for example, allowing a customer to upload a logo for a customized product.

Before the PolyShell fix, Magento's validation process did not adequately confirm that an uploaded file belonged to a legitimate product upload option or prevent potentially dangerous file types from being uploaded.

An attacker could use a polyglot file — a file that functions both as a valid image and as executable code — to get around the image validation process. Magento could then save the disguised file in the store's media folder.

No customer account or administrative login is required for the attack described in the white paper.

What Could Happen to an Affected Magento Store?

The severity of PolyShell depends partly on how the store's web server is configured.

If the server allows program files to execute from Magento's media directory, an attacker could potentially achieve remote code execution and take control of the store.

Even where code execution is blocked, malicious files can create other risks. They could be used to hijack customer or administrator sessions or remain dormant on the server and become dangerous following a future hosting change, server update, or migration.

Why Applying a Patch May Not Be Enough

Adobe's response to PolyShell did not amount to one universal patch that can simply be applied to every Magento installation.

According to the Web2Market white paper, the comprehensive fix was incorporated into Magento 2.4.9, released May 12, 2026. Adobe later released isolated security patches for supported versions on July 14, 2026, but those patches apply to specific patch levels.

There are several additional reasons merchants shouldn't treat patching as the end of the process.

A security patch can stop new malicious uploads, but it doesn't automatically remove malicious files that may already have been uploaded. Those files can remain on the server until the store is properly scanned and cleaned.

Server configuration also matters. If the web server is configured to execute program files from upload directories, that configuration needs to be reviewed and corrected separately.

Temporary community modules, firewall rules, and custom patches can also create technical debt and may conflict with future Magento updates.

What Should Magento Merchants Do?

The long-term approach outlined in Web2Market's white paper is to:

  • Run a currently supported Magento release, such as Magento 2.4.9.
  • Keep the store current with Adobe's security patch schedule.
  • Make sure the web server cannot execute code from upload directories.
  • Check the store for malicious files that may have been uploaded before the vulnerability was fixed.

For merchants running older Magento installations, PolyShell is also a reminder of a larger issue: security isn't just about reacting to individual vulnerabilities as they appear. Keeping the underlying platform supported, properly configured, and maintained matters just as much.

Learn More About PolyShell

We've prepared a detailed security white paper explaining how PolyShell works, Adobe's response, the limitations of temporary fixes, and why moving to a supported Magento release is the stronger long-term approach.

Download the PolyShell Security White Paper

Concerned about your Magento version or security posture? Contact the Web2Market team to review your current Magento environment and discuss the appropriate next steps.

Transform How Your Team Talks

Convert more customers with automation that responds the moment they reach out.

Book a Call