Vulnerabilities · 173 days ago
A WebRTC-based payment skimmer is exploiting the PolyShell vulnerability in Magento Open Source and Adobe Commerce to steal checkout payment data.
1 source covering this story
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
WebRTC skimmer exploits PolyShell flaw since March 19, hitting 56.7% stores, enabling stealth data theft bypassing CSP.
Part of the PlainSec briefing for 2026-03-27