More

    Hundreds of Adobe Magento stores hit after critical security flaw found – here’s what we know



    • CVE-2025-54236 is actively exploited to hijack accounts via Magento’s REST API
    • Over 250 attacks in 24 hours; most stores remain unpatched six weeks after fix
    • Attackers upload PHP backdoors using fake sessions; Sansec urges immediate patching and scans

    A critical-severity vulnerability recently found in Adobe Commerce and Magento Open Source platforms is being actively exploited in the wild to attack e-commerce sites and take over accounts, experts have warned.

    Researchers at Sansec said in less than 24 hours, they observed more than 250 attacks leveraging CVE-2025-54236, a critical-severity flaw (9.1/10) described as an “improper input validation” vulnerability.


    https://cdn.mos.cms.futurecdn.net/vUGGQXBvMLxK65oJegUwgk-2000-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img