Skip to content
MAGEKWIKScanner

Threat intelligence

The Vault

The exact intelligence this scanner checks your store against — named breaches, the end-of-life matrix, and every detection signature. It is versioned and printed on every report, so you always know which snapshot produced your grade.

Vault version

2026.08.2

Released

2026-08-05

4 named CVEs
47 checks
5 malware signatures
9 skimmer domains
411 advisories tracked 3 actively exploited (CISA KEV) Advisory index: synced 2026-08-10T09:09:29Z

Known breaches we scan for

Version-inferred and always hedged — we flag exposure by branch, never assert a CVE from a version string alone. Verify your exact patch level against each advisory.

SessionReaper

actively exploited critical

CVE-2025-54236 APSB25-88 Adobe Commerce / Magento 2.x

Store appears to be running the store. If it is 2.4.8-p2 or earlier without the APSB25-88 emergency hotfix (VULN-32437), an unauthenticated improper-input-validation flaw in the Commerce REST API allows customer-session takeover and, under certain configurations, remote code execution. This is actively exploited in the wild — verify the exact patch level urgently.

CosmicSting

actively exploited critical

CVE-2024-34102 APSB24-40 Adobe Commerce / Magento 2.x

Store appears to be running the store. If it is 2.4.7 or earlier without the isolated CVE-2024-34102 patch, an unauthenticated XXE chains to remote code execution and encryption-key theft. Verify the exact patch level.

TrojanOrder

actively exploited critical

CVE-2022-24086 APSB22-12 Adobe Commerce / Magento 2.x

Store appears to be running the store. If it is 2.4.3-p1 or earlier without the APSB22-12 patch, an unauthenticated template-injection leads to remote code execution. Verify the exact patch level.

Magento 1 SUPEE gap

critical

SUPEE SUPEE Magento 1.x

Store appears to be running the store. Magento 1 is end-of-life and only protected by cumulative SUPEE (or OpenMage LTS) patches; unpatched instances are actively exploited. Verify the applied SUPEE level.

Adobe release & end-of-life matrix

Which branches still receive Adobe security patches. An unsupported branch gets no fixes for new CVEs.

Branch Status Notes
2.4 supported The 2.4 line is the current supported line; confirm you are on the latest 2.4.x-pN patch.
2.3 end of life The 2.3 line reached end of support; it no longer receives security patches. (EOL 2022-09-08)
2.2 end of life The 2.2 line is long past end of support. (EOL 2019-12-31)
2.1 end of life The 2.1 line is long past end of support. (EOL 2018-06-30)
2.0 end of life The 2.0 line is long past end of support. (EOL 2018-03-31)
1.9 end of life Magento 1.x is end of life; only community LTS (OpenMage) provides patches. (EOL 2020-06-30)

Detection coverage — 47 checks

Every check the engine runs on a store, grouped by surface. Signature internals are intentionally not published.

Version & CVEs

  • Magento version disclosure
  • CosmicSting (CVE-2024-34102)
  • TrojanOrder (CVE-2022-24086)
  • SUPEE security patches
  • Supported release / end-of-life

Exposed files

  • app/etc/env.php
  • app/etc/local.xml (Magento 1)
  • .env file
  • .git repository
  • .svn metadata
  • composer.lock
  • composer.lock SBOM (exact versions + modules)
  • app/etc/config.php
  • Setup / upgrade application
  • Legacy downloader
  • phpinfo() page
  • var/log exposure
  • RELEASE_NOTES.txt
  • pub/errors config
  • Media directory listing

Malware & skimmers

  • Known malware signatures (Visbot / Gurulnc)
  • Known-bad script domains
  • Obfuscated JavaScript
  • Leaked keys in JavaScript

Data exposure

  • Public order RSS feed
  • Public stock RSS feed
  • REST API schema disclosure
  • SOAP WSDL disclosure
  • GraphQL introspection
  • robots.txt / sitemap disclosure

Transport & headers

  • Content-Security-Policy
  • Strict-Transport-Security (HSTS)
  • Clickjacking (X-Frame-Options)
  • X-Content-Type-Options
  • Referrer-Policy
  • Permissions-Policy
  • Cookie Secure flag
  • Cookie HttpOnly flag
  • Cookie SameSite
  • TLS certificate & protocol
  • Server software disclosure

Access surface

  • Default admin path
  • Exposed admin tools (Magmi, Adminer)
  • Frontend stack detection

Email & exposure

  • SPF record
  • DMARC (spoofing / deliverability)
  • Subdomain exposure (Certificate Transparency)
5 named malware / skimmer signatures
9 known-bad skimmer domains
2 static-asset version fingerprints

How the vault stays current

Auto-synced advisory index

The advisory index — every tracked CVE and its actively exploited flag — is pulled on a schedule from two authoritative feeds: NVD for the CVE records and CISA KEV for real-world exploitation. Last synced 2026-08-10T09:09:29Z. Every release is integrity-checked — each signature must compile, each CVE must carry working remediation — before it goes out.

Sources

  • NVD — the National Vulnerability Database (CVE records, CVSS)
  • CISA KEV — Known Exploited Vulnerabilities (real-world exploitation)
  • Adobe Commerce PSIRT security advisories (APSB25-88, APSB24-40, APSB22-12)
  • Sansec threat research (sansec.io/research)
  • gwillem/magento-version-identification
  • Adobe Commerce release lifecycle policy

Live, per scan

What runs in real time is the scan itself. Against your store, the engine issues only passive GET/HEAD requests, inspects the live TLS handshake, and runs a WAF-aware transport that escalates through browser and TLS-impersonation tiers if the store challenges the scanner.

  • Passive & read-only — nothing is written to your store
  • The intelligence travels with the engine — no external call is needed to run a scan
  • Every report prints the vault version that produced it

Scan your store against this vault →