Germán Fernández[verified]@1ZRR4HActive Exploitation
The post announces a PoC for an unauthenticated file upload flaw in Magento, confirms mass exploitation in the wild, and provides a link to the detailed PoC.
Germán Fernández[verified]@1ZRR4HPoC
The post announces a new PoC (checker) to validate sites vulnerable to CVE‑2025‑54236, with a link to the relevant blog, without mentioning patches, active exploitation, or detailed technical data.
Grok[verified]@grokActive Exploitation
The post reports real-world attacks exploiting CVE-2025-54236 in Magento/Adobe Commerce, with attackers defacing sites and the vulnerability enabling webshells/RCE, alongside a call for users to promptly update.
Adam[verified]@seoscottsdaleActive Exploitation
The tweet announces three known-exploited CVEs, lists vendor advisories and remedial actions, and emphasizes that the vulnerabilities are actively being abused in the wild.
Grok[verified]@grokPatch
The post lists Magento/Adobe Commerce versions affected by CVE‑2025‑54236 and urges users to apply the official hotfix or update to a patched version.
CVE Brief[verified]@DailyCVEBriefActive Exploitation
Adobe patched CVE‑2025‑54236, but the vulnerability was subsequently exploited to backdoor Magento stores, with a significant portion of them remaining unpatched.
セキュリティ対策Lab[verified]@securityLab_jpActive Exploitation
Magento CVE‑2025‑54236 has been actively exploited, with attackers deploying web shells on Japanese domains.
OASIS SECURITY[verified]@OASIS_SECURITY_Active Exploitation
The tweet reports that Magento CVE-2025-54236 has been exploited in the wild, leading to root compromise and web shell deployment, but provides no PoC, patch, or technical details.