Threat intelligence
The Vault
The exact intelligence this scanner checks your store against — named breaches, the end-of-life matrix, and every detection signature. It is versioned and printed on every report, so you always know which snapshot produced your grade.
Vault version
2026.08.2
Released
2026-08-05
Known breaches we scan for
Version-inferred and always hedged — we flag exposure by branch, never assert a CVE from a version string alone. Verify your exact patch level against each advisory.
SessionReaper
actively exploited criticalCVE-2025-54236 APSB25-88 Adobe Commerce / Magento 2.x
Store appears to be running the store. If it is 2.4.8-p2 or earlier without the APSB25-88 emergency hotfix (VULN-32437), an unauthenticated improper-input-validation flaw in the Commerce REST API allows customer-session takeover and, under certain configurations, remote code execution. This is actively exploited in the wild — verify the exact patch level urgently.
CosmicSting
actively exploited criticalCVE-2024-34102 APSB24-40 Adobe Commerce / Magento 2.x
Store appears to be running the store. If it is 2.4.7 or earlier without the isolated CVE-2024-34102 patch, an unauthenticated XXE chains to remote code execution and encryption-key theft. Verify the exact patch level.
TrojanOrder
actively exploited criticalCVE-2022-24086 APSB22-12 Adobe Commerce / Magento 2.x
Store appears to be running the store. If it is 2.4.3-p1 or earlier without the APSB22-12 patch, an unauthenticated template-injection leads to remote code execution. Verify the exact patch level.
Magento 1 SUPEE gap
criticalSUPEE SUPEE Magento 1.x
Store appears to be running the store. Magento 1 is end-of-life and only protected by cumulative SUPEE (or OpenMage LTS) patches; unpatched instances are actively exploited. Verify the applied SUPEE level.
Adobe release & end-of-life matrix
Which branches still receive Adobe security patches. An unsupported branch gets no fixes for new CVEs.
| Branch | Status | Notes |
|---|---|---|
| 2.4 | supported | The 2.4 line is the current supported line; confirm you are on the latest 2.4.x-pN patch. |
| 2.3 | end of life | The 2.3 line reached end of support; it no longer receives security patches. (EOL 2022-09-08) |
| 2.2 | end of life | The 2.2 line is long past end of support. (EOL 2019-12-31) |
| 2.1 | end of life | The 2.1 line is long past end of support. (EOL 2018-06-30) |
| 2.0 | end of life | The 2.0 line is long past end of support. (EOL 2018-03-31) |
| 1.9 | end of life | Magento 1.x is end of life; only community LTS (OpenMage) provides patches. (EOL 2020-06-30) |
Detection coverage — 47 checks
Every check the engine runs on a store, grouped by surface. Signature internals are intentionally not published.
Version & CVEs
- Magento version disclosure
- CosmicSting (CVE-2024-34102)
- TrojanOrder (CVE-2022-24086)
- SUPEE security patches
- Supported release / end-of-life
Exposed files
- app/etc/env.php
- app/etc/local.xml (Magento 1)
- .env file
- .git repository
- .svn metadata
- composer.lock
- composer.lock SBOM (exact versions + modules)
- app/etc/config.php
- Setup / upgrade application
- Legacy downloader
- phpinfo() page
- var/log exposure
- RELEASE_NOTES.txt
- pub/errors config
- Media directory listing
Malware & skimmers
- Known malware signatures (Visbot / Gurulnc)
- Known-bad script domains
- Obfuscated JavaScript
- Leaked keys in JavaScript
Data exposure
- Public order RSS feed
- Public stock RSS feed
- REST API schema disclosure
- SOAP WSDL disclosure
- GraphQL introspection
- robots.txt / sitemap disclosure
Transport & headers
- Content-Security-Policy
- Strict-Transport-Security (HSTS)
- Clickjacking (X-Frame-Options)
- X-Content-Type-Options
- Referrer-Policy
- Permissions-Policy
- Cookie Secure flag
- Cookie HttpOnly flag
- Cookie SameSite
- TLS certificate & protocol
- Server software disclosure
Access surface
- Default admin path
- Exposed admin tools (Magmi, Adminer)
- Frontend stack detection
Email & exposure
- SPF record
- DMARC (spoofing / deliverability)
- Subdomain exposure (Certificate Transparency)
How the vault stays current
Auto-synced advisory index
The advisory index — every tracked CVE and its actively exploited flag — is pulled on a schedule from two authoritative feeds: NVD for the CVE records and CISA KEV for real-world exploitation. Last synced 2026-08-10T09:09:29Z. Every release is integrity-checked — each signature must compile, each CVE must carry working remediation — before it goes out.
Sources
- NVD — the National Vulnerability Database (CVE records, CVSS)
- CISA KEV — Known Exploited Vulnerabilities (real-world exploitation)
- Adobe Commerce PSIRT security advisories (APSB25-88, APSB24-40, APSB22-12)
- Sansec threat research (sansec.io/research)
- gwillem/magento-version-identification
- Adobe Commerce release lifecycle policy
Live, per scan
What runs in real time is the scan itself. Against your store, the engine issues only passive GET/HEAD requests, inspects the live TLS handshake, and runs a WAF-aware transport that escalates through browser and TLS-impersonation tiers if the store challenges the scanner.
- Passive & read-only — nothing is written to your store
- The intelligence travels with the engine — no external call is needed to run a scan
- Every report prints the vault version that produced it