Magento — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
18
occurrences
First Seen
October 28, 2025
Last Seen
September 5, 2026

Magento is a widely used e-commerce platform for building online stores.

Overview

Magento is a widely used e-commerce platform for building online stores. It is a high-value target in cybersecurity due to its large install base and extensible plugin ecosystem; the article notes a Magento-focused exploit campaign called SessionReaper, illustrating active threat activity targeting Magento installations.

Related Threat Clusters

  • Active Exploitation of Magento Zero-Day Vulnerability 'StyleSmuggler'

    A new unpatched vulnerability, named StyleSmuggler, has been discovered in Magento Open Source and Adobe Commerce, allowing unauthenticated attackers to execute remote code. The attacks began on September 4, 2026, and…

    2 articles · Updated September 5, 2026
  • Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks

    A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication,…

    5 articles · Updated May 15, 2026
  • Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer

    A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on…

    8 articles · Updated June 4, 2026
  • Critical Adobe Commerce Flaw Allows Account Takeover

    A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms has been exploited, allowing unauthenticated attackers to hijack customer accounts. The flaw, rated 9.1 on the CVSS scale, enables…

    6 articles · Updated August 12, 2026
  • Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover

    A newly disclosed vulnerability named 'PolyShell' affects all stable versions of Magento Open Source and Adobe Commerce, allowing unauthenticated remote code execution (RCE) and account takeover. The flaw arises from…

    10 articles · Updated March 20, 2026
  • Magecart Campaign Targets 99 Magento Stores with SVG Skimmer

    A large-scale Magecart campaign has compromised 99 Magento e-commerce stores, utilizing an innovative evasion technique involving invisible SVG elements to inject credit card skimmers directly into checkout pages.…

    2 articles · Updated April 10, 2026
  • Magecart Campaign Exploits Stripe for Credit Card Theft

    A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into…

    3 articles · Updated June 5, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025
  • Global Hacking Campaign Defaces 7,500+ Magento Sites

    Since February 27, 2026, hackers have defaced over 7,500 Magento-powered websites, targeting e-commerce platforms, government services, and various organizations. The attackers uploaded plaintext defacement files and…

    2 articles · Updated March 20, 2026
  • Magento Vulnerability Exploited in Attack on 200+ Websites

    In January 2026, attackers exploited a critical vulnerability in Magento, tracked as CVE-2025-54236, to hijack over 200 e-commerce websites. This severe authentication flaw allowed threat actors to gain complete control…

    2 articles · Updated January 30, 2026

Recent Intelligence Reports

  • StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack — Sansec · September 5, 2026
  • Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — Bleepingcomputer · August 13, 2026
  • CVE-2026-45247 — nvd.nist.gov · June 4, 2026
  • Mirasvit Cache Warmer Object Injection — sansec.io · June 4, 2026
  • Credit card theft campaign abuses Stripe to host stolen payment info — Bleepingcomputer · June 4, 2026
  • 9.8 Mirasvit bug actively exploited on Magento servers | news — Scworld · June 4, 2026
  • Sansec detected the malicious activity — sansec.io · May 15, 2026
  • Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages — Cybersecuritynews · April 10, 2026

CVSS v3.1 Breakdown