Attackers Hijacked 200+ Websites Exploiting Magento Vulnerability to Gain Root-level Access
## Cybersecurity Update: Exploitation of Magento Vulnerability
Cybersecurity Update: Exploitation of Magento Vulnerability
A major security incident has affected multiple Magento e-commerce platforms globally, as threat actors have exploited a critical authentication vulnerability to gain full system control.
The attack campaign, identified in January 2026, is among the most significant recent web server compromise events, impacting numerous online stores across various regions and industries.
The vulnerability, identified as CVE-2025-54236 or SessionReaper, permits unauthorized access by reusing session tokens that were not correctly invalidated by the Magento application . These session tokens act as digital keys to verify user identity.
Failure to destroy these tokens after user logout allows attackers to intercept and reuse them, enabling administrative access without needing passwords or bypassing security measures.
Oasis Security analysts identified numerous independent intrusion incidents where various threat actors exploited CVE-2025-54236 against Magento systems globally. This indicates widespread knowledge and exploitation of the vulnerability.
This indicates widespread knowledge and exploitation of the vulnerability.
Attackers conducted large-scale scans to identify vulnerable systems, discovering over 1,000 susceptible Magento APIs and successfully compromising 200 websites with root-level access.
The attackers systematically leveraged this vulnerability to gain full control over affected infrastructures. After initial access through session hijacking, they escalated privileges to root access on Linux servers. This allowed for the deployment of web shells, enabling remote command execution and data theft.
Compromised systems contained sensitive files, including user accounts and credentials, indicating extensive system exploration and potential data exfiltration.
The investigation revealed command and control operations from Finland and Hong Kong, with separate threat actors targeting Magento sites in Canada and Japan. Attackers maintained organized logs of compromised sites and shell paths, demonstrating systematic targeting strategies.
Organizations using Magento should promptly patch this vulnerability and review server logs for unusual session token activity.
The extensive nature of this campaign highlights the importance of timely security updates and continuous monitoring of e-commerce platforms safeguarding critical customer data and payment information.
Based on reporting by Cyber Security News.
