The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Fashion/Apparel
Breach intelligence, attack campaigns, and threat reports targeting the Fashion/Apparel sector.
Explore Other Sectors
Fashion/Apparel Threat Reports
StyleSmuggler Attack: How CVE-2026-75650 Exposes Critical E-Commerce Security Gaps
In September 2026, Adobe disclosed CVE-2026-75650, dubbed 'StyleSmuggler,' a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source platforms. The vulnerability, scoring a maximum CVSS of 10.0, allows unauthenticated attackers to inject PHP code through Magento's email template engine and execute arbitrary commands by triggering payment failure reminder emails. Active exploitation began on September 4, 2026, with threat actors deploying Rust-based Linux backdoors and PHP web shells on compromised e-commerce storefronts worldwide. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog within 24 hours of disclosure, emphasizing the severity and widespread targeting of unpatched Magento installations. This incident highlights the critical security risks facing e-commerce platforms as attackers increasingly target template injection vulnerabilities in widely-deployed content management systems. With millions of online stores running vulnerable Magento versions and the rise of automated exploitation frameworks, organizations must prioritize rapid patching and comprehensive security monitoring for their web applications.
2 weeks ago
Kill Chain
CISA Highlights Critical Magento Vulnerability CVE-2026-45247 Amid Active Exploitation
In early June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. This critical vulnerability, with a CVSS score of 9.8, affects Mirasvit's Full Page Cache Warmer extension for Magento 2 versions prior to 1.11.12. The flaw allows unauthenticated attackers to execute arbitrary PHP code on affected servers by sending crafted serialized PHP objects via the CacheWarmer cookie. Exploitation has been observed targeting gaming and business websites, particularly in the U.S., U.K., France, and Australia. Organizations are urged to apply the provided patches by June 6, 2026, and audit for suspicious CacheWarmer cookie values indicative of exploitation attempts. The inclusion of CVE-2026-45247 in the KEV catalog underscores the persistent threat posed by deserialization vulnerabilities in widely used web applications. This incident highlights the importance of timely patching and vigilant monitoring to prevent unauthorized code execution and potential data breaches.
3 months ago
Kill Chain
PolyShell Attacks Compromise Over Half of Vulnerable Magento Stores
In March 2026, attackers began exploiting the 'PolyShell' vulnerability in Magento Open Source and Adobe Commerce installations, affecting over half of all vulnerable stores. The flaw resides in Magento's REST API, which improperly handles file uploads, allowing attackers to execute remote code or perform account takeovers via stored cross-site scripting (XSS). Adobe released a fix in version 2.4.9-beta1 on March 10, 2026, but it has not yet reached the stable branch. This incident underscores the critical importance of timely patch management and the need for robust security configurations to prevent exploitation of known vulnerabilities. The rapid exploitation following public disclosure highlights the urgency for organizations to stay vigilant and proactive in their cybersecurity practices.
6 months ago
Kill Chain
Over 250 Magento Stores Breached Overnight Through Critical Adobe Commerce Flaw
In October 2025, over 250 Magento and Adobe Commerce online stores were compromised in less than 24 hours after attackers exploited a newly disclosed critical vulnerability, CVE-2025-54236 (CVSS 9.1). The flaw, stemming from improper input validation, allowed threat actors to compromise e-commerce shops directly via their web applications, enabling unauthorized access, data exfiltration, and potential payment card theft. Security researchers observed an automated wave of exploitation attempts soon after public disclosure, underlining how rapidly threat actors weaponize emerging vulnerabilities for financial gain and to cause operational disruption. This incident highlights the urgent need for rapid patch management and layered web application defenses, as attackers increasingly leverage zero-day and recently disclosed vulnerabilities to target widely used commerce platforms, further increasing risks to consumer data and regulatory compliance for online retailers.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports