logo

“SessionReaper” Harvests Roots: Mass Exploitation Campaign Hits Over 200 Magento Sites

ID: 4d677451-ee4b-517c-a968-e6943254af62

STIX ID: report--4d677451-ee4b-517c-a968-e6943254af62

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Oasis Security warns of a critical Magento vulnerability (CVE-2025-54236, "SessionReaper") that enables attackers to reuse "zombie" session tokens to bypass authentication and gain root-level control; an active mass exploitation campaign has been observed with hundreds of compromised storefronts, web shells deployed for persistence, and associated C2 infrastructure (notably IP 93.152.230.161). Approximately 1,460 Magento Commerce APIs were identified as vulnerable, and administrators are urged to patch immediately to prevent further full-system compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.