Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

9 / 9 results
Active filter:tag: #e-commerce✕ clear
GiveWP WordPress plugin RCE allows unauthenticated server takeovercriticalbug_reportVulnerability
bug_reportVulnerability

GiveWP WordPress plugin RCE allows unauthenticated server takeover

GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).

GiveWP28 Aug · 16:18 UTC
Adobe Commerce critical vulnerability under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce critical vulnerability under active exploitation

Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.

Adobe17 Aug · 07:14 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accountscriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce/Magento flaw CVE-2026-71362 exploited to hijack accounts

Adobe Commerce and Magento Open Source e-commerce platforms, all currently supported release lines. The vulnerability affects customer account session handling and requires no authentication to exploit.

CVE-2026-7136212 Aug · 18:54 UTC
SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)

SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.

CVE-2026-5823112 Aug · 05:31 UTC
Quick.Cart stores hardcoded admin credentials in plaintext config filehighbug_reportVulnerability
bug_reportVulnerability

Quick.Cart stores hardcoded admin credentials in plaintext config file

OpenSolution Quick.Cart all versions through 6.7. Vulnerability requires attacker access to server file system to retrieve hardcoded plaintext admin credentials from configuration file.

CVE-2026-4187428 Jul · 09:55 UTC
Shopify Shop app abused for callback phishing via fake order receiptshighbug_reportVulnerability
bug_reportVulnerability

Shopify Shop app abused for callback phishing via fake order receipts

Shopify Shop order-tracking app users. Threat actors inject fraudulent purchase receipts into legitimate user order histories, leveraging Shopify's trusted platform to deliver phishing lures.

Shopify25 Jun · 17:45 UTC
South Korea issues record $409M fine to Coupang for 37M-user breachhighpublicGeopolitical
publicGeopolitical

South Korea issues record $409M fine to Coupang for 37M-user breach

The unprecedented fine against Coupang reflects South Korea's increasingly assertive regulatory posture on data protection, aligning Seoul with global trends toward stringent enforcement of privacy frameworks.

Coupang11 Jun · 10:52 UTC
SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloudcriticalbug_reportVulnerability
bug_reportVulnerability

SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud

SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.

SAP9 Jun · 17:36 UTC