Magento Vulnerability Exploited in Attack on 200+ Websites
First seen 30 Jan 2026, 19:15 UTC
•
•50
Export
Article Content
Browse articles
In January 2026, attackers exploited a critical vulnerability in Magento, tracked as CVE-2025-54236, to hijack over 200 e-commerce websites. This severe authentication flaw allowed threat actors to gain complete control of the affected systems, marking a significant wave of coordinated web server compromises across various regions.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer
Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks
Critical Adobe Commerce Flaw Allows Account Takeover
Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover
Magecart Campaign Targets 99 Magento Stores with SVG Skimmer
Magecart Campaign Exploits Stripe for Credit Card Theft