A WebRTC-based payment skimmer is exploiting the PolyShell vulnerability in Magento Open Source and Adobe Commerce to steal checkout payment data.
Part of the PlainSec briefing for 2026-03-27