Attackers Hijacked 200+ Websites Exploiting Magento Vulnerability to Gain Root-level Access
ID: 89692e02-d34b-59a9-a2bb-814551dc709e
STIX ID: report--89692e02-d34b-59a9-a2bb-814551dc709e
Feed Name: cybersecurityNews.com
A widespread January 2026 campaign exploited CVE-2025-54236 (SessionReaper) in Magento platforms, allowing attackers to replay non-invalidated session tokens to achieve administrator/root access on hundreds of e-commerce sites; operators scanned over 1,000 vulnerable APIs, compromised ~200 sites, deployed web shells for persistence and data theft, and used C2 infrastructure in Finland and Hong Kong—organizations running Magento are urged to patch immediately and audit logs for suspicious session activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
