Magento “PolyShell” File Upload Vulnerability

Incident Report for Server Status | Nexcess

Resolved

We have taken steps to prohibit execution of files exploiting the "PolyShell" unrestricted file upload vulnerability across our managed fleet.

If you have any questions or concerns. You can reach us through the following channels:

Live Chat: https://my.nexcess.net/
Email: support@nexcess.net
Posted Mar 18, 2026 - 18:23 EDT

Investigating

We are aware of recent reports regarding a potential unrestricted file upload vulnerability, commonly referred to as “PolyShell”, affecting Magento and Adobe Commerce.

At this time, our teams are actively reviewing our environment to assess any potential impact and determine whether any systems/customer sites may be affected.

We will provide further updates as more information becomes available.
If you have any questions or concerns. You can reach us through the following channels:

Live Chat: https://my.nexcess.net/
Email: Nexcess Support
Posted Mar 18, 2026 - 12:17 EDT
This incident affected: Platform Operations (Platform Updates / Other).