CVE-2025-54236 is actively exploited to hijack accounts via Magento’s REST API Over 250 attacks in 24 hours; most stores remain unpatched six weeks after fix Attackers upload PHP backdoors using fake ...