Magento — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
16
occurrences
First Seen
October 28, 2025
Last Seen
June 4, 2026

Magento is a technology platform tracked across 12 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity June 4, 2026.

Overview

Magento is a widely used e-commerce platform for building online stores. It is a high-value target in cybersecurity due to its large install base and extensible plugin ecosystem; the article notes a Magento-focused exploit campaign called SessionReaper, illustrating active threat activity targeting Magento installations.

Related Threat Clusters

  • Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks

    A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication,…

    5 articles · Updated May 15, 2026
  • Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer

    A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on…

    8 articles · Updated June 4, 2026
  • Critical 'PolyShell' Vulnerability Exposes Magento to RCE and Account Takeover

    A newly disclosed vulnerability named 'PolyShell' affects all stable versions of Magento Open Source and Adobe Commerce, allowing unauthenticated remote code execution (RCE) and account takeover. The flaw arises from…

    10 articles · Updated March 20, 2026
  • Magecart Campaign Targets 99 Magento Stores with SVG Skimmer

    A large-scale Magecart campaign has compromised 99 Magento e-commerce stores, utilizing an innovative evasion technique involving invisible SVG elements to inject credit card skimmers directly into checkout pages.…

    2 articles · Updated April 10, 2026
  • Magecart Campaign Exploits Stripe for Credit Card Theft

    A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into…

    3 articles · Updated June 5, 2026
  • Critical React Flaw CVE-2025-55182 Exposes Major Security Risks

    A maximum-severity vulnerability in the React JavaScript library, tracked as CVE-2025-55182, allows unauthenticated remote code execution on affected instances. Security researchers report that 39 percent of cloud…

    47 articles · Updated December 3, 2025
  • Global Hacking Campaign Defaces 7,500+ Magento Sites

    Since February 27, 2026, hackers have defaced over 7,500 Magento-powered websites, targeting e-commerce platforms, government services, and various organizations. The attackers uploaded plaintext defacement files and…

    2 articles · Updated March 20, 2026
  • Magento Vulnerability Exploited in Attack on 200+ Websites

    In January 2026, attackers exploited a critical vulnerability in Magento, tracked as CVE-2025-54236, to hijack over 200 e-commerce websites. This severe authentication flaw allowed threat actors to gain complete control…

    2 articles · Updated January 30, 2026
  • UK Retail Cyber Attacks Show No Seasonal Spike Amid Holiday Concerns

    Analysis of cybersecurity incidents in the UK retail and manufacturing sectors reveals that 1,381 breaches occurred between Q3 2024 and Q2 2025, with no significant concentration around major shopping events. Security…

    61 articles · Updated November 28, 2025
  • BlueNoroff Launches New Campaigns Targeting Crypto Professionals

    North Korea-aligned threat actor BlueNoroff has initiated two new campaigns, GhostCall and GhostHire, targeting fintech executives and Web3 developers. These campaigns utilize social engineering tactics on platforms…

    4 articles · Updated October 29, 2025

Recent Intelligence Reports

  • CVE-2026-45247 — nvd.nist.gov · June 4, 2026
  • Mirasvit Cache Warmer Object Injection — sansec.io · June 4, 2026
  • Credit card theft campaign abuses Stripe to host stolen payment info — Bleepingcomputer · June 4, 2026
  • 9.8 Mirasvit bug actively exploited on Magento servers | news — Scworld · June 4, 2026
  • Sansec detected the malicious activity — sansec.io · May 15, 2026
  • Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages — Cybersecuritynews · April 10, 2026
  • Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse — Gbhackers · April 9, 2026
  • PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks — Securityaffairs.Co · March 21, 2026

CVSS v3.1 Breakdown