Guides
The 2025 Magento Security Year in Review
December 18, 2025 - by Alexandru-Manuel Carabus
2025 was the year Magento security stopped being optional. Here is the year in one place: CosmicSting fallout, SessionReaper, the backdoor epidemic, and the PHP 8.1 deadline.

If 2025 taught Magento merchants one thing, it is that store security is an operating discipline, not a one-time setup. The year stacked one serious event on another. Here is the whole picture in one place, and what to check before 2026.
CosmicSting kept paying out
The 2024 flaw known as CosmicSting continued to hit stores well into 2025, largely because patched sites that never rotated their encryption keys stayed exploitable. Thousands of stores were skimmed, including major brands. We covered the anniversary and its lessons in CosmicSting, one year later.
SessionReaper raised the ceiling
In September, Adobe issued an emergency fix for CVE-2025-54236, nicknamed SessionReaper, a critical flaw in the Commerce REST API that could lead to account takeover and remote code execution, rated 9.1 on the severity scale. Mass exploitation followed in October, with security researchers reporting hundreds of stores hit in a single night and more than half of all stores probed. It was the most dangerous Magento bug of the year.
The backdoor epidemic
The quieter story was persistence. By late October, researchers estimated that 16 to 18 percent of all Magento stores carried one or more injected backdoors, often left behind from earlier compromises. A patched store is not automatically a clean store, and 2025 made that painfully clear.
PHP 8.1 closed the year as a deadline
On December 31, PHP 8.1 reached end of life. Stores on Magento 2.4.4 through 2.4.6 run on it, so they entered 2026 on an unsupported runtime, which is a PCI compliance problem as much as a technical one. The fix is the upgrade to 2.4.8 and PHP 8.4.
The pattern, and what to check before 2026
Every event this year rewarded the same habits: patch within hours not weeks, rotate secrets after any exposure, run file-integrity monitoring on the checkout, and stay on a supported PHP release. If you want a clean read on where your store stands going into 2026, book a free strategy call with LIQUIDLAB.