Security Hardening - Magento “PolyShell” File Upload Vulnerability Enhancements

Incident Report for Server Status | Nexcess

Investigating

Following the actions taken to prohibit execution of files exploiting the Magento “PolyShell” unrestricted file upload vulnerability, our engineering teams are continuing to implement additional security enhancements across our managed environment.

These efforts include strengthening file upload validation and execution restrictions, enhancing monitoring and detection mechanisms, and implementing additional hardening measures across Magento platforms. We are also conducting internal reviews to reduce potential attack surfaces and reinforce overall platform security.

These proactive improvements reflect our ongoing commitment to maintaining a secure and resilient hosting environment. While the initial issue has been addressed, we are taking additional steps to further strengthen our systems and help prevent future risks.

While the additional measures that we have deployed should reduce the risk for potential compromise, we strongly urge that our customers take proactive measures to review and secure their sites

If you have any questions or concerns, please reach out to us through the following channels:
Live Chat: https://my.nexcess.net/
Email: support@nexcess.net

We will continue to share updates as these enhancements are completed.
Posted Apr 01, 2026 - 14:37 EDT
This incident affects: Platform Operations (Platform Updates / Other).