Adobe Commerce is a technology platform tracked across 6 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed March 11, 2026; most recent activity July 14, 2026.
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication,…
A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on…
A newly disclosed vulnerability named 'PolyShell' affects all stable versions of Magento Open Source and Adobe Commerce, allowing unauthenticated remote code execution (RCE) and account takeover. The flaw arises from…
A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into…
Adobe has released patches for 80 vulnerabilities across eight products, including Commerce, Illustrator, Acrobat Reader, and Premiere Pro. Less than half of these vulnerabilities have been linked to specific threat…