Adobe Commerce A.I CyberSecurity Scoring
Adobe Commerce
Company Information
Website:https://adobe.ly/adobecommerce
Employees number:541
Number of followers:125,191
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:adobe.ly
Adobe Commerce Risk Score (AI oriented)
Between 550 and 599
Adobe CommerceTechnology, Information and Internet
Updated:
23/09/2026
23/09/2026
554/1000
Very Poor
Ca
Adobe Commerce Global Score (TPRM)
xxxx
Adobe CommerceTechnology, Information and Internet
Score locked

Adobe CommerceVery Poor
Current Score
554Ca (VERY POOR)
01000
13 incidents
-23.44 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
589
Cyber Attack
23 Sep 2026 • Adobe Commerce
Magento and Gambit Security: Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards
AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from Online Retailers
554
CRITICAL-35
GAMADO1790151984
AI-Powered Cybercrime Campaign Steals 600K+ Credit Cards from Online Retailers
A financially motivated threat actor has leveraged autonomous AI agents to target hundreds of online retailers since July 2026, stealing over 600,000 unexpired credit card records in an ongoing campaign uncovered by Gambit Security. The operation, which remains active, automates vulnerability discovery, exploitation, data theft, and payment card skimming with some attacks including destructive cleanup actions that erase database tables or wipe payment fields post-exfiltration.
### Attack Mechanics & AI Tools
The campaign employs three open-source AI agents:
- Strix: Conducts deep reconnaissance and vulnerability scanning.
- Cairn: Executes autonomous exploitation, securing shell or admin access over hours.
- Hermes: Orchestrates attacks, maintains persistence, and directs impact-stage actions.
A human operator, issuing brief prompts in Chinese, initiated attacks by directing agents to probe targets, validate exploits, and deploy JavaScript skimmers often by hijacking legitimate scripts, modifying Google Tag Manager, or poisoning cloud-hosted content. Between September 10–15, 2026, the actor launched 105 attack projects, compromising at least 27 organizations.
### Cost & Scale
The operator used OpenRouter for AI model access, spending $7,005.71 over four weeks with estimated total campaign costs between $12,000–$18,000. The average cost per successful target was $25.46, though expenses ranged from $3.13 to $79.31 depending on the attack’s complexity.
### Techniques & Impact
Beyond skimming, the threat actor employed destructive automation, including:
- Wiping Magento payment card fields after exfiltration.
- Deleting 180 database tables (including backups) via broad cleanup criteria.
The campaign highlights how AI-driven tools accelerate attacks, reducing the time between exposure and compromise while enabling a single operator to manage large-scale intrusions.
### Indicators of Compromise (IoCs)
Gambit Security identified multiple IPs, domains, and skimmer payloads linked to the operation, including:
- Staging/C2 IPs: `155.254.22.215`, `209.126.4.170`, `213.21.239.62`
- Skimmer hosts: `b8t[.]shop`, `cdn[.]netlfjs[.]com`, `x1opay[.]co`
- Proxy services: IPRoyal, 711proxy, 1024proxy
The full list of IoCs is available in the original report.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
614
Cyber Attack
08 Sep 2026 • Adobe Commerce
Fortinet, Microsoft, Palo Alto Networks, Odido, Revolut, Magento/Adobe Commerce, MikroTik and Check Point: Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
Cybersecurity Roundup: Zero-Days, AI-Driven Attacks, and Major Breaches Dominate the Week
587
CRITICAL-27
FORCHEMIKPALMICODIADOITR1789359970
Cybersecurity Roundup: Zero-Days, AI-Driven Attacks, and Major Breaches Dominate the Week
This week’s cybersecurity landscape was marked by a surge in critical vulnerabilities, active exploitation campaigns, and high-profile breaches highlighting persistent threats to enterprises, governments, and consumers.
### Microsoft’s Record-Breaking Patch Tuesday
Microsoft’s September 2026 Patch Tuesday addressed 973 vulnerabilities, the largest single release in its history. The update spanned Windows, Office, SQL Server, Exchange, SharePoint, Azure, and developer tools, with 438 elevation-of-privilege flaws and 258 remote code execution (RCE) bugs. Notably, 64 vulnerabilities were tied to the Windows Biometric Service, suggesting systemic weaknesses in authentication.
Two zero-days under active exploitation were patched:
- CVE-2026-85880 (Windows ALPC) – Elevation-of-privilege flaw.
- CVE-2026-81963 (Windows Update Stack) – Also an elevation-of-privilege bug.
Critical fixes were also issued for Windows Secure Kernel Mode, VBS Enclave, and Excel/Word RCE flaws, making this one of the most urgent patch cycles of the year for enterprise IT teams.
### Fortinet Under Fire: Active Exploitation and Critical Flaws
Security researchers uncovered an active campaign exploiting CVE-2025-25249, a 9.8-rated heap overflow in FortiOS and FortiSwitchManager’s CAPWAP service. Attackers deployed PivotC2, a custom Node.js RAT that bypasses firewalls via outbound TLS connections, harvests device configurations, and decrypts VPN credentials.
- 30,000 FortiGate IPs scanned, with 178 devices compromised.
- U.S. organizations targeted, with Exchange mailbox data exfiltrated to Wasabi cloud storage.
- A Russian-speaking, financially motivated group is suspected, also exploiting FortiManager and ArubaOS flaws.
Fortinet also disclosed CVE-2026-84393, a 7.3-rated certificate validation flaw in FortiOS and FortiProxy’s Agentless ZTNA portal, allowing man-in-the-middle attacks on internet-facing portals. No in-the-wild exploitation has been observed, but upgrades to FortiOS 7.6.7+ are strongly recommended.
### Palo Alto Networks PAN-OS RCE Flaw
Palo Alto Networks revealed CVE-2026-0310, a 9.2-rated buffer overflow in PAN-OS XML processing that enables root-level RCE on PA-Series firewalls. While exploitation complexity is high, VM-Series firewalls face only a denial-of-service impact.
- No workaround exists upgrades to PAN-OS 12.2.3+ are required.
- The flaw was discovered internally; no exploitation has been reported.
### AI-Powered Cyberattacks: A New Threat Frontier
Anthropic’s Threat Intelligence team reported that state-sponsored groups and cybercriminals are weaponizing Claude AI to automate attack chains:
- A Russian-linked group (GTG-20006) used Claude to rewrite malware upon detection, hijack hotel Wi-Fi for phishing, and steal 300,000 national ID records from a North African government.
- ShinyHunters scaled credential harvesting across 10 cloud workers, decompiling 1.8 million Android apps for hardcoded secrets.
- A suspected Chinese exploit foundry (GTG-10007) generated over a dozen zero-day candidates in a single month using AI agent swarms.
### Major Breaches: Revolut, Odido, and More
- Revolut disclosed a KYC data breach after attackers impersonated a government agency via a fraudulent email under an official domain. Exposed data included passports, driver’s licenses, transaction histories, and Bitcoin activity.
- Odido (Dutch telecom) suffered a 6.39 million-record breach after a vishing attack a Dutch-speaking caller impersonated an IT colleague to obtain credentials, then exfiltrated 90 GB of data via Salesforce APIs. The data was later leaked after a €1 million ransom demand was refused.
- ShinyHunters was linked to the attack, using identical tactics against 100+ organizations, including SoundCloud and Betterment.
### Zero-Days and Emerging Threats
- PostGREShell (CVE-2026-6471): A 12-year-old PostgreSQL flaw allows low-privileged accounts to execute code via shared libraries. Patches are available in PostgreSQL 18.6+.
- StyleSmuggler: An unpatched Magento/Adobe Commerce zero-day lets attackers execute malicious PHP via email templates. No official fix exists; hardening patches are recommended.
- WeWorm: A zero-click WeChat VoIP exploit demonstrated cross-platform worming between iOS and Android, granting full account control.
- BlueMoon Exploit Kit: Chains Chromium V8 and Windows ALPC flaws to deploy backdoors against government and defense targets, with China-linked groups adopting it within days.
### Enterprise and Consumer Risks
- LG OLED TVs were found scanning home networks and recording audio even in standby mode, raising concerns for hospitals, hotels, and corporate environments.
- MikroTik RouterOS suffered an unauthenticated SSH flaw, leading to unauthorized shell access on exposed devices.
- Check Point VPN flaws (CVE-2026-85102/85103) enable unauthenticated RCE on Quantum Security Gateways.
- Google Chrome 153 patched 230 vulnerabilities, including an actively exploited V8 zero-day (CVE-2026-87491).
### Government and Infrastructure Shifts
- Switzerland’s Federal Council is piloting an open-source digital workplace to reduce reliance on Microsoft 365, aiming for 3,000 employees by 2027.
- Windows Server RDP freezes were reported after September updates, creating a security vs. stability dilemma for enterprises.
### Key Takeaways
This week underscored the growing sophistication of cyber threats, from AI-driven attacks to zero-day exploitation and social engineering breaches. Organizations must prioritize patch management, credential security, and AI threat monitoring to mitigate risks in an increasingly complex threat landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
619
Vulnerability
05 Sep 2026 • Adobe Commerce
Magento and Adobe Commerce: Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
Critical Zero-Day Exploit in Magento & Adobe Commerce Under Active Attack (StyleSmuggler)
614
CRITICAL-5
ADO1788668623
Critical Zero-Day Exploit in Magento & Adobe Commerce Under Active Attack
A severe zero-day vulnerability, dubbed StyleSmuggler, is being actively exploited to gain full control of online stores running Magento Open Source and Adobe Commerce. Disclosed by Dutch security firm Sansec on September 5, 2026, the flaw allows unauthenticated attackers to execute remote code (RCE) on vulnerable systems, with attacks confirmed as early as September 4.
The vulnerability affects all current versions of Magento and Adobe Commerce, including the latest 2.4.9 release, and requires no authentication to exploit. Even fully patched stores such as one running 2.4.6-p15 with all July and August 2026 security updates have been compromised, demonstrating the flaw’s severity.
### Exploit Mechanics & Attack Chain
The attack unfolds in two stages, leveraging Magento’s template rendering and email systems:
1. Initial Exploitation – Attackers manipulate "styles" properties in a GraphQL request to inject malicious PHP code into a file Magento generates during normal operations (e.g., payment failure reports).
2. Trigger Execution – The exploit forces Magento to send a "Payment Transaction Failed Reminder" email, executing the poisoned code without requiring the email to be opened or received.
Once triggered, the malware deploys a Rust-based implant (1.9MB, compiled for x86-64 and ARM64) disguised as a Linux kernel thread ([kworker/u:8:0]) to evade detection. The implant persists via a cron job, restarts every five minutes, and avoids standard logging by writing directly to the crontab spool file.
### Evasion & Detection Challenges
- The malware mimics legitimate kernel processes, making detection difficult.
- It modifies its in-memory binary, requiring defenders to hash both the file and live process.
- Some variants avoid external connections, instead querying the site’s Redis instance to steal session data, bypassing network monitoring.
- Sansec’s detection guidance suggests checking `var/report`, but compromised stores have also been found with infections in `var/log/system.log`.
### Mitigation & Response
With no official patch from Adobe as of September 6, store owners are relying on temporary measures:
- Disabling GraphQL for stores not using headless or PWA frontends.
- Unofficial patches from Disrex, ProxiBlue, and Graycore, which harden specific Magento classes but do not fully resolve the vulnerability.
- Server-level protections, such as disabling `proc_open` and mounting temporary directories with `noexec`, to block payload execution.
Adobe’s next scheduled security release is September 8, but there is no confirmation that it will address this flaw. The company has yet to issue an advisory, assign a CVE, or provide an official workaround.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
696
Breach
20 Aug 2026 • Adobe Commerce
WooCommerce, ClickFunnels, Magento and Stripe: Hacker Leaks 1,033 Stripe Merchant API Keys and 688K Customer Records
Threat Actor 'Satanic' Leaks 33GB of Stripe Merchant Data on Cybercrime Forum
617
CRITICAL-79
ADOSTRCLIWOO1787611224
Threat Actor "Satanic" Leaks 33GB of Stripe Merchant Data on Cybercrime Forum
On 18 August 2026, the threat actor known as "Satanic" uploaded over 33GB of allegedly stolen Stripe-related files to the cybercrime forum PwnForums. The actor, previously linked to breaches involving ClickFunnels, WooCommerce, and Magento, claimed possession of 20,000 compromised Stripe API keys, though only 1,033 exposed keys many with the sk_live_ prefix for live payment environments were verified in the leaked dataset.
Analysis by Hackread.com revealed 669 merchant account folders and 323 unique business domains after filtering duplicates and generic email providers. The breach did not stem from a compromise of Stripe’s systems but rather from exposed merchant credentials. Potential sources include hardcoded API keys in public GitHub repositories, unsecured configuration files, infostealer malware, or automated scans for exposed .env files.
The leaked data contained 688,363 customer records, including:
- Personal details (names, emails, phone numbers, addresses)
- Partial payment card data (last four digits, brand, expiry dates)
- Transaction histories (billing amounts, invoices, IP addresses)
- Active discount codes and internal identifiers
For 519 merchant accounts with both payment and payout capabilities, the exposure could enable fraudulent charges, unauthorized refunds, or payout redirection if the keys remain active. While the dataset does not confirm whether all keys are still valid, the financial and privacy risks for affected merchants and customers are significant.
Stripe has not commented on the incident, but the breach underscores the dangers of unsecured API keys and poor credential hygiene in payment processing environments.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
693
JUNE 2026
691
MAY 2026
688
APRIL 2026
693
Vulnerability
24 Apr 2026 • Adobe Commerce
Adobe Commerce and Mirasvit: Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks
Critical Magento Extension Vulnerability Exposes Thousands of Stores to RCE Attacks
688
CRITICAL-5
ADOMIR1780324139
Critical Magento Extension Vulnerability Exposes Thousands of Stores to RCE Attacks
A severe security flaw in the Mirasvit Cache Warmer plugin for Magento and Adobe Commerce is leaving thousands of online stores vulnerable to remote code execution (RCE) attacks. Tracked as CVE-2026-45247 with a CVSS score of 9.8, the vulnerability allows unauthenticated attackers to execute arbitrary code on affected servers by exploiting improper input handling in the plugin’s caching mechanism.
The flaw stems from the plugin’s use of PHP’s `unserialize()` function on user-controlled CacheWarmer cookies, enabling PHP object injection (CWE-502). Since the plugin does not restrict class instantiation during deserialization, attackers can craft malicious payloads to escalate the attack into full RCE, particularly when combined with existing gadget chains in Magento or its dependencies.
Key Details:
- Affected Software: Mirasvit Cache Warmer (all versions prior to 1.11.12).
- Discovery & Disclosure: Identified by Sansec on April 24, 2026, with Mirasvit notified on May 21 and a patch (v1.11.12) released on May 25.
- Scope: Sansec estimates at least 6,000 Magento stores are running vulnerable versions, though the actual number may be higher due to CDN masking.
- Exploitation Footprint: Malicious requests contain a CacheWarmer cookie with base64-encoded serialized data, often starting with prefixes like Tz, Qz, or YT.
Impact & Response:
The vulnerability is easily exploitable at scale, with no authentication required. Sansec’s Shield protection blocked attacks for its customers as early as April 24. While Mirasvit has released a patch, security experts warn that exploitation activity is expected to rise following public disclosure.
Administrators are advised to upgrade to v1.11.12 immediately or deploy a web application firewall (WAF) as a temporary mitigation. Compromise assessments, including scans for webshells and unauthorized PHP files in the pub/ directory, are recommended to detect potential breaches.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2026
695
Vulnerability
19 Mar 2026 • Adobe Commerce
Adobe and Unnamed Car Manufacturer: WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
New WebRTC-Based Payment Skimmer Bypasses Security Controls in Major E-Commerce Attack
690
CRITICAL-5
ADOCMB1774536907
New WebRTC-Based Payment Skimmer Bypasses Security Controls in Major E-Commerce Attack
Cybersecurity researchers at Sansec have uncovered a sophisticated payment skimmer that leverages WebRTC data channels to exfiltrate stolen payment data, evading traditional security measures. Unlike conventional skimmers that rely on HTTP requests or image beacons, this malware establishes a peer-to-peer WebRTC connection to transmit payloads and stolen information, making detection significantly harder.
The attack targeted an e-commerce website of a car manufacturer and exploited PolyShell, a critical vulnerability in Magento Open Source and Adobe Commerce. The flaw allows unauthenticated attackers to upload arbitrary executables via the REST API, enabling remote code execution. Since March 19, 2026, the vulnerability has been massively exploited, with over 50 IP addresses scanning for vulnerable stores. Sansec reports that 56.7% of all exposed stores have already been compromised.
The skimmer operates as a self-executing script that connects to a hard-coded IP address (202.181.177[.]177) over UDP port 3479 using WebRTC. Once connected, it retrieves malicious JavaScript code, injecting it into the webpage to steal payment details. The use of DTLS-encrypted UDP traffic rather than HTTP allows the attack to bypass Content Security Policy (CSP) restrictions, rendering many network security tools ineffective.
Adobe released a beta patch (version 2.4.9-beta1) on March 10, 2026, but the fix has yet to reach production versions. While mitigations include blocking access to the *pub/media/custom_options/* directory and scanning for web shells, the attack highlights a growing trend of skimmers exploiting non-HTTP protocols to evade detection.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
712
Cyber Attack
01 Mar 2026 • Adobe Commerce
WooCommerce, Stripe, PayPal, PrestaShop and Magento: Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
HexMage Magecart Campaign Exploits Ethereum Smart Contracts to Skim Payment Data from 40+ E-Commerce Sites
694
CRITICAL-18
PREPAYSTRADOWOO1788171946
HexMage Magecart Campaign Exploits Ethereum Smart Contracts to Skim Payment Data from 40+ E-Commerce Sites
A sophisticated Magecart campaign, dubbed HexMage, has compromised over 40 e-commerce storefronts across 15+ countries, leveraging Ethereum smart contracts to deliver and conceal payment-card skimmers. The attack combines traditional client-side checkout theft with EtherHiding, a technique that uses Ethereum’s Sepolia testnet to dynamically rotate malicious infrastructure, evading detection.
### How the Attack Works
HexMage primarily targets WooCommerce sites but has also infected PrestaShop, Magento, and WordPress installations. Attackers first compromise the merchant’s server, injecting a lightweight JavaScript loader disguised as a Google Tag Manager (GTM) snippet complete with fake GTM comments and obfuscated Base64 data. Unlike legitimate GTM code, however, the loader fetches ethers.js from jsDelivr CDN and queries 0xrpc.io, a public Ethereum Sepolia endpoint.
The loader then calls a public `getText()` function on an attacker-controlled smart contract, which returns a disposable payload domain hosting the final skimmer. This approach minimizes the attacker’s visible footprint, as the checkout page initially contains no hardcoded malicious domains, complicating static detection.
### Skimmer Execution & Data Theft
The final-stage skimmer overlays or replaces legitimate payment fields, capturing card numbers, CVVs, expiry dates, cardholder names, and billing emails. The stolen data is Base64-encoded and exfiltrated before the original payment interface is restored, allowing transactions to complete normally. The malware is tailored to specific payment gateways, including Stripe, PayPal, ePay, PhonePe, and HyperPay, and often avoids execution when a WordPress admin is logged in, reducing detection risk.
### Attacker Infrastructure & Resilience
Researchers at Confiant traced the campaign to a single Ethereum wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee), which deployed 156 malicious contracts between March and August 2026. The contracts function as decentralized dead drops, storing payload hostnames in plaintext or encrypted form. If defenders block a domain, attackers can update the contract or deploy a new one without reinfecting the merchant site.
The campaign also includes a fallback loader that bypasses blockchain retrieval entirely, decoding a Base64-encoded skimmer URL directly. This redundancy ensures persistence even if Ethereum RPC activity is detected.
### Impact & Detection Challenges
HexMage’s use of blockchain-backed staging makes infrastructure harder to disrupt, but its public nature allows defenders to enumerate contracts, wallets, and delivery hosts. Security teams are advised to monitor checkout pages for:
- Unexpected Web3 library loads (ethers.js)
- JSON-RPC requests to public blockchain endpoints
- GTM-like code that fails to fetch `gtm.js`
- Unauthorized JavaScript in payment templates
The campaign underscores the evolving tactics of Magecart groups, blending server-side compromises, browser-based malware delivery, and decentralized infrastructure to maximize stealth and persistence.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
731
Cyber Attack
27 Feb 2026 • Adobe Commerce
Citroën, Fiat, Diesel, Asus, Bandai, Toyota, Fila, BenQ, Yamaha, Lindt, Trump Organization and Magento: Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data
Massive Magento Cyberattack Compromises 7,500+ E-Commerce Sites Since February 2026
712
CRITICAL-19
DIETOYFILASUCITBENMAGLINYAMFIATHEBAN1774023969
Massive Magento Cyberattack Compromises 7,500+ E-Commerce Sites Since February 2026
A large-scale cyberattack campaign has compromised over 7,500 Magento-powered e-commerce websites since late February 2026, with attackers uploading malicious files to publicly accessible web directories across 15,000+ hostnames. The campaign, tracked by Netcraft researchers, marks one of the most extensive Magento-focused attacks in recent years, affecting businesses, government agencies, universities, and non-profits worldwide.
### Scope and Impact
The attack exploited a file upload vulnerability in Magento environments, allowing threat actors to deposit unauthorized files without authentication. Victims include high-profile brands such as Toyota, Fiat, Citroën, Asus, Diesel, Fila, Bandai, FedEx, BenQ, Yamaha, and Lindt, as well as government and university domains in Latin America and Qatar. Several Trump Organization-affiliated sites including trumpstore.com, trumphotels.com, and booktrump.com were also compromised, though researchers confirmed these were incidental targets in an indiscriminate sweep.
Most defacements occurred on subdomains, staging environments, or regional storefronts, with only a few live customer-facing sites briefly impacted before remediation. Attackers left behind text files displaying aliases L4663R666H05T, Simsimi, Brokenpipe, and Typical Idiot Security alongside "greetz" messages, a common practice in defacement circles. A subset of defacements on March 7, 2026, included geopolitical messaging, though analysts determined this was not the campaign’s primary motive.
### Technical Details
The attack leveraged an unauthenticated file upload flaw in Magento, enabling attackers to write files directly to web servers without credentials. Netcraft researchers successfully replicated the behavior on a Magento Community 2.4.9-beta1 test instance, demonstrating that even updated installations could remain vulnerable under certain configurations. The affected platforms include Magento Open Source, Magento Enterprise, Adobe Commerce, and Adobe Commerce with the B2B module.
While Adobe released security bulletins around this period, the observed exploit does not directly align with the published fixes. The campaign shares similarities with the SessionReaper Magento vulnerability from October 2025, which also involved unauthorized file access.
### Attacker Activity and Documentation
The threat actor behind the campaign, operating under the handle "Typical Idiot Security," self-reported many compromised sites to Zone-H, a public defacement archive. This suggests the attacker sought recognition within the defacement community rather than pursuing financial or political objectives.
As of the latest reports, new compromised sites were still emerging, indicating the campaign remained active. Organizations running Magento-based infrastructure were urged to review file upload endpoints, apply security updates, and monitor web directories for unauthorized changes.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
730
DECEMBER 2025
747
Cyber Attack
24 Dec 2025 • Adobe Commerce
Google, Stripe and Magento/Adobe Commerce: Credit card theft campaign abuses Stripe to host stolen payment info
New Magecart Campaign Exploits Stripe API to Steal Payment Data
729
CRITICAL-18
ADOSTRGOO1780611936
New Magecart Campaign Exploits Stripe API to Steal Payment Data
Researchers at Sansec have uncovered a sophisticated Magecart campaign leveraging Stripe’s API infrastructure and Google Tag Manager (GTM) to steal credit card details from e-commerce checkout pages. The attack, active since at least December 24, 2025, abuses trusted domains googletagmanager.com and api.stripe.com to bypass security filters and exfiltrate stolen data undetected.
The malware is embedded in legitimate-looking GTM containers, which execute when a shopper reaches a checkout page. It targets Magento/Adobe Commerce stores, capturing payment details (card number, CVV, expiration date), billing information, and customer contact data. The stolen data is obfuscated using XOR encryption, stored locally, and later exfiltrated via Stripe’s API by creating fake customer records under the attacker’s account (cus_TfFjAAZQNOYENR).
A variant of the campaign uses Google Firestore (project: braintree-payment-app, document: tracking/captcha) to host the payload and store stolen data, blending in with legitimate payment and bot-protection traffic. Once exfiltrated, the malware wipes local traces to avoid detection.
The attack highlights how threat actors exploit trusted platforms to evade security measures, turning payment processors into unwitting storage for stolen financial data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
747
OCTOBER 2025
746
SEPTEMBER 2025
750
Vulnerability
09 Sep 2025 • Adobe Commerce
Adobe
Exploitation Attempts Targeting CVE-2025-54236 (SessionReaper) in Adobe Commerce and Magento Open Source
745
CRITICAL-5
ADO5132051102325
Adobe is facing active exploitation attempts targeting CVE-2025-54236 (SessionReaper), a critical Improper Input Validation vulnerability in Adobe Commerce and Magento Open Source. The flaw allows attackers to take over customer accounts and, in certain configurations (e.g., file-based session storage), achieve unauthenticated remote code execution (RCE). Over 250 exploitation attempts were blocked in a single day, with expectations of mass exploitation within 48 hours due to publicly available exploit details.Only 38% of Magento stores have applied the patch, leaving a vast majority exposed. Attackers are deploying PHP webshells and phpinfo probes, indicating reconnaissance for deeper compromise. The vulnerability affects multiple versions of Adobe Commerce, Magento Open Source, and B2B editions. While Adobe released a hotfix on September 9, 2025, the leak of technical details a week prior accelerated attacker activity. Sansec researchers warn of automated scanning tools emerging rapidly, increasing the risk of large-scale breaches. Administrators are urged to patch immediately and scan for signs of intrusion, as delayed action could lead to widespread account takeovers, data theft, or financial fraud through compromised e-commerce platforms.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2025
753
Vulnerability
16 Jun 2025 • Adobe Commerce
Adobe (Adobe Commerce / Magento)
Active Exploitation of SessionReaper Vulnerability (CVE-2025-54236) in Adobe Commerce (Magento)
749
CRITICAL-4
ADO0402304102325
Hackers are actively exploiting CVE-2025-54236 (SessionReaper), a critical improper input validation vulnerability in Adobe Commerce (formerly Magento). The flaw allows attackers to take over customer accounts via the Commerce REST API without user interaction, potentially leading to unauthorized access to sensitive customer data, financial fraud, or full account compromise.Over 250 exploitation attempts were blocked in a single day, with 62% of Magento stores remaining unpatched and vulnerable. Attackers are deploying PHP webshells and reconnaissance probes (phpinfo) to assess system configurations, escalating the risk of large-scale data breaches or financial theft. The vulnerability affects multiple versions, including 2.4.9-alpha2, 2.4.8-p2, and earlier, with default configurations (file-based session storage) being the primary attack vector.Adobe issued an emergency patch, but slow adoption—only 40% of stores patched after six weeks—exposes thousands of e-commerce platforms to account takeovers, payment fraud, and reputational damage. Security firms warn of increased attack volumes following public technical analyses, urging immediate patching to prevent widespread customer data compromise and operational disruptions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
758
Vulnerability
01 May 2025 • Adobe Commerce
Adobe
Critical SessionReaper Vulnerability (CVE-2025-54236) in Adobe Commerce and Magento Open Source
753
CRITICAL-5
ADO1892518090925
Adobe has disclosed a critical vulnerability (CVE-2025-54236, dubbed *SessionReaper*) in its Commerce and Magento Open Source platforms, allowing unauthenticated attackers to bypass security features and hijack customer accounts via the Commerce REST API. Though no active exploitation has been observed yet, a leaked hotfix may accelerate threat actor development of exploits. The flaw, deemed one of the most severe in Magento’s history, enables session forging, privilege escalation, and potential code execution—mirroring past high-impact vulnerabilities like CosmicSting and Shoplift.Adobe released an emergency patch on September 9, 2025, urging immediate deployment, as delayed action leaves systems exposed to automated, large-scale attacks. Cloud-based Adobe Commerce users received temporary protection via a WAF rule, but on-premise and unpatched instances remain at risk. The vulnerability’s exploitation relies on default session storage configurations, increasing its reach. Failure to patch could lead to widespread account takeovers, financial fraud, and operational disruptions for e-commerce businesses, with Adobe offering limited remediation support post-breach.Researchers warn of high automation potential, emphasizing the urgency for administrators to test and apply fixes despite potential compatibility issues with custom code.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2024
773
Vulnerability
16 Jun 2024 • Adobe Commerce
Adobe
Exploitation of CVE-2025-54236 (SessionReaper) in Adobe Commerce and Magento Open Source Platforms
756
CRITICAL-17
ADO0092800102325
Threat actors are actively exploiting CVE-2025-54236 (CVSS 9.1), a critical improper input validation vulnerability in Adobe Commerce and Magento Open Source, enabling account takeovers via the Commerce REST API. Over 250 attack attempts were recorded in 24 hours, with 62% of Magento stores remaining unpatched six weeks post-disclosure. Exploits involve dropping PHP webshells and extracting PHP configuration data via fake sessions, risking full customer account compromise. The flaw, dubbed SessionReaper, follows a similar 2024 deserialization vulnerability (CosmicSting, CVE-2024-34102), highlighting a pattern of high-severity exploits in Adobe’s e-commerce platforms. Public proof-of-concept (PoC) exploits and technical analyses (e.g., by Searchlight Cyber) accelerate attack adoption. Adobe confirmed in-the-wild exploitation, urging immediate patching to prevent widespread account hijacking, data theft, or backend system infiltration—potentially disrupting payment processes, customer trust, and operational integrity for affected stores.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Adobe Commerce ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in August 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in July 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in June 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in May 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in April 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in March 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in February 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in January 2026 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in December 2025 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in November 2025 ??
What was Adobe Commerce's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Adobe Commerce's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Adobe Commerce ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Adobe Commerce's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?