
- CVE-2025-54236 is actively exploited to hijack accounts via Magento’s REST API
- Over 250 attacks in 24 hours; most stores remain unpatched six weeks after fix
- Attackers upload PHP backdoors using fake sessions; Sansec urges immediate patching and scans
A critical-severity vulnerability recently found in Adobe Commerce and Magento Open Source platforms is being actively exploited in the wild to attack e-commerce sites and take over accounts, experts have warned.