Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Hundreds of Adobe Magento stores hit after critical security flaw found - here's what we know

Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air.
  • CVE-2025-54236 is actively exploited to hijack accounts via Magento’s REST API
  • Over 250 attacks in 24 hours; most stores remain unpatched six weeks after fix
  • Attackers upload PHP backdoors using fake sessions; Sansec urges immediate patching and scans

A critical-severity vulnerability recently found in Adobe Commerce and Magento Open Source platforms is being actively exploited in the wild to attack e-commerce sites and take over accounts, experts have warned.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.