The checkout was already theirs. Sansec says attackers began exploiting an unpatched Magento Open Source and Adobe Commerce bug on September 4, running malicious code on store servers with no login. There is no patch. If you take cards or catalog orders on that stack, you are in incident response whether anyone opened a ticket. The same week, Elementor Pro’s form handler (CVE-2026-32475, CVSS 9.8) is being used to plant files on WordPress. This is a cybersecurity week about revenue platforms that accept untrusted uploads.

No Patch Turns Checkout Into Persistence
StyleSmuggler is Sansec’s name for the Magento zero-day. Unauthenticated request, code on the store, backdoor left behind. The firm published early on September 5 because waiting for a tidy Adobe advisory donates hours to whoever already has a shell under pub/.
You know this movie. Payment skimmers ride in after the first dropper. New admin users appear. Cron jobs call home. The catalog still renders. Shoppers still pay. Uptime stays green while the card flow belongs to someone else.
A firewall that never saw a port scan will not save you. The request looks like commerce. Threat detection tuned for brute-force noise against wp-login.php or SSH will score a successful 200. Threat-protection filters that still key off last quarter’s Magento CVE list have nothing to match yet.
Elementor Pro is the parallel failure on WordPress. The bug sits in the function that handles form submissions. Marketing wanted a resume upload. Attackers wanted a PHP dropper. A 9.8 is a polite way to say the form is a privileged write into the document root. SecurityWeek reports active exploitation. Treat every site with Pro forms as compromised until you have a patched build and a file tree you can explain.

Hunt after you patch. Look for PHP in upload directories, modified themes, unexpected must-use plugins, and the web user making outbound connections your baseline never recorded. Rebuild from git when a file has no owner.
Magento operators cannot wait on a package. Isolate the admin path. Freeze third-party extensions. Diff the live tree against a known-good artifact from before September 4. Rotate admin passwords, 2FA devices, integration tokens, and payment gateway keys. Cyber security teams that still file Magento under “digital experience” will lose the cardholder environment in that labeling gap. The real problem here is an unauthenticated POST to checkout still gets a production interpreter.
Vendor CI Failure Becomes Your Cloud Incident
JetBrains ate the same class of bug in its own house. Attackers used an unpatched TeamCity flaw, breached Cadence, and walked out with AWS credentials. Cadence runs other people’s workflows. Workflows hold the secrets that deploy, query, and bill.
Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions.
That is the invoice. A vendor CI hole became your cloud identity incident. Rotate every key, token, and role that ever launched a Cadence execution. Then prove the old material is dead. Read CloudTrail for the window you do not have a ticket for. Start with the credential, not the vendor’s timeline.

TeamCity reachable from the internet is a build-system domain controller. Defense in depth that ends at the corporate edge and trusts a vendor patch calendar just failed in public. Assume jobs ran. Assume artifacts were pulled. Assume static keys and OIDC both leaked.
Broadcom shipped Workstation and Fusion updates for CVE-2026-59346, a 9.3 integer overflow. A VM administrator can execute code on the host under certain conditions. You thought you handed a contractor a disposable guest. You handed them a path onto the laptop or lab box that still holds VPN profiles, SSH agents, and browser cookies.
Security hardening here is simple and routinely skipped. VM admin is host admin. Enroll those machines like jump hosts: disk encryption, EDR, no cached domain creds, no standing path to production. Patch the hypervisor before the next lab day.
Unauthenticated Surfaces Bypass Your Cybersecurity Program
Your program keeps scoring plugins and storefronts as application risk. This week they behaved like perimeter devices with no patch SLA. Cut the surface on the hosts you actually run.
- Inventory Magento, Adobe Commerce, Elementor Pro, TeamCity, and VMware Workstation or Fusion with version proof. Flag which of those listeners answer without auth.
- On Magento, apply vendor and Sansec guidance the hour it exists, then hunt. Take admin and API paths off the public internet. Compare the live tree to a signed artifact. Rotate admin, 2FA, integration tokens, and payment keys. Assume a backdoor until a clean binary says otherwise.
- On Elementor, ship the CVE-2026-32475 fix, disable file uploads on forms that do not need them, and search web roots for files written in the exploitation window. Rebuild when you cannot explain a path.
- For Cadence and any TeamCity you operate, revoke every secret that ever touched a job. Treat AWS keys as burned. Review CI users, tokens, and outbound callbacks.
- On Workstation and Fusion, patch, then strip VM-admin from accounts that only needed a guest. A lab host that can reach production AD is a production host.
After the emergency, keep a register of every unauthenticated form, template engine, and upload endpoint next to your VPN concentrators. Assign owners. Set patch clocks in hours for anything that takes payment or publishes files. Write the store-offline playbook before DNS is the only lever you have at 2 a.m.
Instrument what most stacks skip: new files under web roots, checkout 200s with odd user-agents, CI jobs fetching unexpected URLs, AWS calls from unfamiliar clients. Your brute-force panels can stay quiet the entire time. The damage already happened in a POST you filed as normal traffic.
Sources
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
