Mark RadarMARK RADAR
EN
Event File FINTECH

Magento 電商平台遭駭客利用 SVG 圖檔側錄交易資料

1 reports · First detected 2026-04-09 · Last active 2026-04-09

資安公司 Sansec 發現大規模 Magecart 感染,駭客利用 Magento 漏洞在電商網站植入 1x1 像素的 SVG 圖檔以隱藏金融卡側錄程式。受害者在偽造的結帳頁面輸入資料後會被導向真實網頁,導致交易資訊在不知不覺中遭竊取。

All Coverage

1 original reports

The Backstory

The history behind this event
Critical RCE Flaw in Magento Extension Affects More Than 6,000 Online Stores2026-06-04 · 2 reports · similarity 0.81

Magento and Adobe Commerce merchants commonly use Mirasvit Cache Warmer to prebuild full-page caches and speed up storefront loading. Sansec found that the extension passed user-controlled data to PHP’s unserialize() function, creating an object-injection vulnerability. Unauthenticated attackers could remotely execute code, putting transaction data and control of affected servers at risk.

Sansec discovered the vulnerability on April 24, 2026, and Mirasvit released version 1.11.12 to patch it on May 25. It was designated CVE-2026-45247 the following day and received a CVSS 3.1 score of 9.8. Sansec scanned more than 6,000 stores using Mirasvit extensions. The U.S. Cybersecurity and Infrastructure Security Agency confirmed exploitation on June 3 and added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to address it by June 6.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)