By industry
Retail & e-commerce security news
Today · Wed, 16 Sept 2026
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
Infosecurity MagazineWordPress - Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
The Hacker NewsWordPress
Yesterday · Tue, 15 Sept 2026
- Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
BleepingComputerWordPress
Thu, 10 Sept 2026
- Adobe security advisory (AV26-808) – Update 1
Serial number: AV26-808 Date: August 12, 2026 Updated: September 10, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.3 build 9399 Adobe Commerce Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug Adobe Commerce B2B Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul ColdFusion 2023 Prior to or equal to 2023.0.22 ColdFusion 2025 Prior to or equal to 2025.0.11 Content Credentials Command-Line Tool Prior to or equal to c2patool-v0.27.5 Content Credentials JS SDK Prior to or equal to @contentauth/c2pa-web@0.12.0 Content Credentials Rust SDK Prior to or equal to c2pa-v0.90.5 Lightroom Classic Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1 Magento Open Source Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul Update 1 Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as the
CriticalCanadian Centre for Cyber SecurityAdobe - Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
The Record
Wed, 9 Sept 2026
- More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
Malwarebytes Labs
Tue, 8 Sept 2026
- Adobe security advisory (AV26-888) – Update 1
Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal
Canadian Centre for Cyber SecurityAdobe - Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.
CriticalUsed in attacksBleepingComputerAdobe - Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
CriticalUsed in attacksThe Hacker NewsAdobe
Sat, 5 Sept 2026
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
The Hacker NewsAdobe
Latest retail & e-commerce briefing
Retail & e-commerce Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14 →6 stories affecting retail & e-commerce tracked in the last seven days, 3 rated critical, 1 vulnerability added to the CISA Known Exploited catalogue.
Named most often, last 90 days
About retail & e-commerce news
- 12
- Stories
- 5
- In the last 7 days
- 1
- Critical in the last 7 days