Unauthenticated RCE in PrestaShop MyPresta Module
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
CVE-2026-85520 lets unauthenticated attackers write and execute arbitrary PHP via feed.php in the MyPresta Google Merchant Center Feed module for PrestaShop; fixed in v2.3.9.
CERT Polska coordinated disclosure of a critical vulnerability in the MyPresta Google Merchant Center Feed (gmfeed) module for PrestaShop, an e-commerce platform. The flaw resides in the feed.php endpoint, which accepts unauthenticated requests that let an attacker control the output file's name, path, extension, and content through request parameters. Because the endpoint lacks authentication and proper input validation, an attacker can write a file with a .php extension containing malicious code to a web-accessible location and then execute it, achieving remote code execution on the underlying server.
This is an arbitrary file write leading to RCE — a high-impact vulnerability class for any online store running the affected module, since successful exploitation gives full control of the web application (and potentially the host) without any credentials. The vendor fixed the issue in version 2.3.9. There is no indication in this advisory that the vulnerability is being exploited in the wild; it was reported and coordinated through CERT Polska's responsible disclosure process, credited to Today Group sp. z o.o.
Defenders running PrestaShop with the MyPresta gmfeed module should upgrade to version 2.3.9 or later immediately. Where immediate patching isn't possible, restrict or disable public access to feed.php, monitor for unexpected .php files being written to web-accessible directories, and review web server logs for anomalous requests to the feed.php endpoint with suspicious file path/extension parameters.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-85520
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,271 reports from 154 sources, 2,726 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs