Magento Stores Hit by WebRTC Payment Skimmer Exploiting PolyShell

A WebRTC-based payment skimmer is exploiting the PolyShell vulnerability in Magento Open Source and Adobe Commerce to steal checkout payment data.

Part of the PlainSec briefing for 2026-03-27

Sources