Dossier
Magento
Coverage of Magento in the Nexus archive.
- CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
CISA added a critical remote code execution (RCE) vulnerability in Mirasvit Cache Warmer, a Magento extension, to its KEV catalog due to active exploitation. The flaw, CVE-2026-45247 with a CVSS score of 9.8, involves deserialization of untrusted data.
- Hackers use pixel-large SVG trick to hide credit card stealer
Hackers executed a large-scale attack on nearly 100 Magento-powered e-commerce stores by embedding credit card-stealing malware in a pixel-sized SVG image. The malicious code leverages the SVG format to evade detection and compromise customer payment data.