Active Attacks Hit Adobe Commerce & SAP: Patch Now
Two max-severity vulnerabilities are being exploited right now, and they hit software millions of businesses rely on every day: online stores and enterprise back-office systems. Here's what happened and what you should do about it.
Online Stores Under Attack: Adobe Commerce's "StyleSmuggler" Flaw
Hackers are actively breaking into online stores running Adobe Commerce and Magento by exploiting a critical, unauthenticated flaw nicknamed "StyleSmuggler." Attackers don't even need a login to take over a store's backend, and they've already been planting hidden backdoors since early September to maintain long-term access. If you run an e-commerce site on this platform, this matters because a compromised store can mean stolen customer payment data, defaced pages, or a silent backdoor sitting on your servers for months. Adobe has released an emergency patch, but security researchers warn that patching alone isn't enough for stores that may already be compromised — you need to check for existing infections too.
SAP's "OVERPASS" Bug Could Hand Attackers the Keys to the Kingdom
SAP just patched 20 vulnerabilities, but one stands out: a maximum-severity flaw in how SAP systems process network requests, which could let an attacker with no special privileges run commands as an administrator. A second bug in the same update could let an unauthenticated attacker execute malicious commands across an entire SAP system cluster. SAP software runs the finance, HR, and supply chain operations for huge numbers of enterprises, so a successful attack here isn't just "one server gets hacked" — it can mean an attacker gaining control over the systems that run core parts of a business. If your organization uses SAP, this is a patch-immediately situation, not a get-to-it-eventually one.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment