CVE-2025-54236

Published Sep 9, 2025

Last updated a day ago

Exploit knownCVSS critical 9.1
Adobe Commerce
SessionReaper
Magento

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-54236, also known as SessionReaper, is a vulnerability affecting Adobe Commerce and Magento installations. It stems from improper input validation in the Magento Web API. Successful exploitation could lead to security feature bypass, potentially allowing attackers to take over customer accounts, steal data, and place fraudulent orders. The vulnerability allows unauthenticated remote code execution. The attack combines a malicious session with a nested deserialization bug in Magento's REST API. Exploitation appears to require file-based session storage. Adobe has released an emergency patch to address this critical flaw.

Description
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Source
psirt@adobe.com
NVD status
Modified
Products
commerce, commerce_b2b, magento

Insights

Analysis from the Intruder Security Team
Published Oct 23, 2025

This vulnerability is described as an account takeover, however there were rumours early on that this may be more significant.

Assetnote released a research article on the 22nd of October breaking down the vulnerability, highlighting that this is far more serious than Adobe have described. Ultimately through the deserialization vulnerability, an attacker can gain code execution by the creation of a backdoor php file. In order to achieve that, the attacker must know, or be able to guess the (e.g. default) installation path of Magento.

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe Commerce and?Magento Improper Input Validation Vulnerability
Exploit added on
Oct 24, 2025
Exploit action due
Nov 14, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@adobe.com
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

19

  1. 🛡️ Cyber Threat Digest – 2025-10-25 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2021-43768 — In Malwarebytes For Teams News: Hackers launch mass attacks exploiting outdated… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    25 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Wah, CISA lagi update Katalog Vulnerabilitas yang Dieksploitasi! Tambahan panas: Adobe CVE-2025-54236 (deserialisasi jahat di Magento, hacker bisa kuasai akun customer via REST API – bayangin belanja gratis ala pencuri!) dan Microsoft CVE-2025-59287 (RCE di Windows Server Updat

    @BJORKANISM_REAL

    25 Oct 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Akamai security researchers have observed SessionReaper (CVE-2025-54236) activity following exploit POC publication. In 48 hours, we saw: 🔵 300+ exploit attempts against 130+ hosts 🟠 11 unique source IPs 🔵 Multiple payloads, some that allow persistent access https://t.

    @akamai_research

    24 Oct 2025

    916 Impressions

    3 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-54236 #Adobe Commerce and Magento Improper Input Validation Vulnerability https://t.co/dPc6ZobP4I

    @ScyScan

    24 Oct 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🛡️ We added Adobe CVE-2025-54236 and Microsoft CVE-2025-59287 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/EFWCDkQlNd

    @CISACyber

    24 Oct 2025

    8673 Impressions

    29 Retweets

    74 Likes

    10 Bookmarks

    0 Replies

    2 Quotes

  6. Yet another @Adobe #Magento vulnerability. CVE-2025-54236 (CVSS score: 9.1), a critical improper input validation flaw, could be abused to take over customer accounts in #Adobe Commerce through the Commerce REST API. HT @TheHackersNews https://t.co/CLpre3tduk

    @benrothke

    24 Oct 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Hackers Actively Exploiting “SessionReaper” Flaw in Adobe Magento! A dangerous new vulnerability (CVE-2025-54236) dubbed SessionReaper is being actively abused by attackers to hijack user sessions and drop webshells — over 250 exploit attempts were blocked within 24 hours.

    @ChbibAnas

    24 Oct 2025

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨URGENT🚨CVE-2025-54236 exploited in Adobe Commerce/Magento! 250+ attacks in 24hrs. Remote code exec & acct takeover risk via Commerce REST API. 62% unpatched, 5 attacker IPs. Patch now, block IPs (34.227.25.4,

    @bigmacd16684

    24 Oct 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  9. #threatreport #LowCompleteness SessionReaper (CVE-2025-54236): Critical Adobe Commerce Vulnerability Actively Exploited | 23-10-2025 Source: https://t.co/qQgcCtafVC Key details below ↓ 💀Threats: Cosmicsting_vuln, Trojanorder_vuln, 🎯Victims: Online stores, Ecommerce site

    @rst_cloud

    24 Oct 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 SessionReaper [Critical] Oct 24, 2025 This report analyzes the SessionReaper vulnerability (CVE-2025-54236) affecting Adobe Commerce and Magento platforms, its exploitation in the wild, and provides recommendations for mitigation. Checkout our Threat Intelligence Platform:..

    @transilienceai

    24 Oct 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 CRITICAL alert: 'SessionReaper' flaw (CVE-2025-54236) lets remote attackers hijack sessions in Adobe Commerce. No active exploits yet, but risk is high for EU e-commerce sites. Act now — review session security! https://t.co/IwxKpkCRQf... https://t.co/m87bmDxH6N

    @offseq

    24 Oct 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Adobe Commerceの重大な脆弱性CVE-2025-54236によるeコマースサイトの危険性 https://t.co/HtNn9XsJ1t #Security #セキュリティー #ニュース

    @SecureShield_

    24 Oct 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. https://t.co/xQeshm7i8B

    @blackwired32799

    23 Oct 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Over 250 Magento stores hacked via new Adobe Commerce flaw (CVE-2025-54236)! • Exploits target unpatched REST API input bug. • 62% of sites still vulnerable six weeks post-disclosure. Adobe urges immediate patching to stop active attacks. https://t.co/UrIOWXbkN2

    @arix_world

    23 Oct 2025

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🛡️ Si tu tienda online usa Magento o Adobe Commerce, podrías estar expuesto Más de 250 tiendas Magento fueron atacadas en un solo día por una nueva vulnerabilidad crítica (CVE-2025-54236). Permite a los atacantes tomar el control de cuentas de clientes y ejecutar códi

    @CycuraMX

    23 Oct 2025

    1264 Impressions

    13 Retweets

    24 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Les plateformes Adobe Commerce et Magento sont ciblées par des attaques exploitant CVE-2025-54236 (#SessionReaper), permettant la prise de contrôle de comptes clients ou, dans certains cas, l’exécution de code arbitraire. https://t.co/rGMRwOdgl2

    @cert_ist

    23 Oct 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Active Exploits Hit Magento & Adobe Commerce with RCE Attacks Unauthenticated attackers are exploiting CVE-2025-54236, known as SessionReaper, a critical remote code execution flaw affecting all Adobe Commerce and Magento versions. This vulnerability allows remote RCE and ht

    @Secwiserapp

    23 Oct 2025

    38 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  18. Critical #Adobe #Commerce, #Magento vulnerability under attack (#CVE-2025-54236) https://t.co/KQggVbwKoJ

    @ScyScan

    23 Oct 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Critical Adobe Commerce, Magento vulnerability under attack (CVE-2025-54236) https://t.co/cU5xPjFdFF #HelpNetSecurity #Cybersecurity https://t.co/hPdvcJ8b7h

    @PoseidonTPA

    23 Oct 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Over 250 Magento Stores Targeted in New Adobe Commerce Flaw Exploits Sansec warns threat actors exploit CVE-2025-54236, a critical flaw in Adobe Commerce/Magento Open Source, with over 250 attack attempts in 24 hours. Despite a patch last month, 62% of Magento stores remain http

    @Secwiserapp

    23 Oct 2025

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 Over 250 #Magento stores hacked overnight! Hackers are exploiting a critical flaw (CVE-2025-54236 – SessionReaper) in #AdobeCommerce to hijack customer accounts via the REST API. 🧩 Full details + mitigation: 👉 https://t.co/aH1IOSYZIo

    @vulert_official

    23 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Cloudflare has released new WAF rule addressing the following CVE to enhance customer protection. Adobe Commerce RCE (CVE-2025-54236) https://t.co/593ZdOlXgZ

    @Cloudforce_One

    23 Oct 2025

    265 Impressions

    1 Retweet

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 📝 𝐎𝐯𝐞𝐫 𝟐𝟓𝟎 𝐌𝐚𝐠𝐞𝐧𝐭𝐨 𝐒𝐭𝐨𝐫𝐞𝐬 𝐇𝐢𝐭 𝐎𝐯𝐞𝐫𝐧𝐢𝐠𝐡𝐭 𝐚𝐬 𝐇𝐚𝐜𝐤𝐞𝐫𝐬 𝐄𝐱𝐩𝐥𝐨𝐢𝐭 𝐍𝐞𝐰 𝐀𝐝𝐨𝐛𝐞 𝐂𝐨𝐦𝐦𝐞𝐫𝐜𝐞 𝐅

    @PurpleOps_io

    23 Oct 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Hackers exploiting critical "SessionReaper" flaw in Adobe Magento Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Co… https://t.co/yPBrXlcmZx https://t.co/FXieZoNUb1

    @DConsultinguk

    23 Oct 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. ⚠️ Over 250 Magento stores compromised overnight via SessionReaper, a critical Adobe Commerce flaw (CVE-2025-54236). Remote code execution & webshells deployed. Patch NOW to avoid takeover! https://t.co/iJ0PLYdfXu... https://t.co/2sxCbRotln

    @offseq

    23 Oct 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Over 250 Magento stores targeted in 24 hours exploiting Adobe Commerce flaw CVE-2025-54236. Attackers use remote code execution via REST API to deploy PHP webshells and steal system data. #MagentoStores #AdobeFlaw #RemoteCodeExecution https://t.co/JALHmvIO0k

    @TweetThreatNews

    23 Oct 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. ⚠️⚠️ CVE-2025-54236: Critical 9.1/10 Flaw in Magento / Adobe Commerce Enables Unauthenticated File-Upload & Account Takeover 🔥Deep Dive: https://t.co/RRXWh6NGKB 🎯131k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link: https://t.co/qBwD

    @fofabot

    23 Oct 2025

    2584 Impressions

    19 Retweets

    55 Likes

    16 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 Over 250 Adobe Commerce & Magento stores hacked overnight due to new flaw (CVE-2025-54236)! E-commerce security alert. https://t.co/xCVhZyLdln #MagentoHack #AdobeCommerce #CyberSecurity #CVE202554236

    @0xT3chn0m4nc3r

    23 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🚨⚠️ ¡Alerta de seguridad! Más de 250 tiendas Magento comprometidas por la vulnerabilidad CVE-2025-54236 (puntuación CVSS: 9.1). Asegura tu plataforma Adobe Commerce para protegerte de estos ataques masivos. 🛡️🔓 #CiberSeguridad #Hacking https://t.co/pY9TP0s5t3

    @kalirsec

    23 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 📌 حذرت شركة أمان التجارة الإلكترونية "سانسيك" من استغلال المهاجمين لثغرة أمنية جديدة في منصات Adobe Commerce وMagento Open Source، حيث تم تسجيل أكثر من 250 محاولة هجوم ضد

    @Cybercachear

    23 Oct 2025

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. 🚨 New Adobe Commerce flaw (CVE-2025-54236, CVSS 9.1) under active attack. Over 250 exploit attempts in 24 hours—mostly on unpatched Magento sites. PoC is public. Patch now. Details → https://t.co/cNYlLIs9xA

    @TheHackersNews

    23 Oct 2025

    11114 Impressions

    28 Retweets

    51 Likes

    8 Bookmarks

    0 Replies

    1 Quote

  32. Reports indicate that hackers are exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce platforms, with hundreds of attempts recorded. #CyberSecurity #Magento https://t.co/cUG0UnmjDO

    @Cyber_O51NT

    23 Oct 2025

    677 Impressions

    1 Retweet

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  33. Adobe Commerce(旧Magento)のCVE-2025-54236 "SessionReaper"脆弱性が活発に悪用されている。Sansec社報告。9/8に開示された不適切な入力検証の脆弱性。Searchlight Cyber社からは技術的解説が出ており、さらなる悪用の増加も

    @__kokumoto

    22 Oct 2025

    708 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  34. ⚠️Hackers are now actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms. Patch now if you haven't! https://t.co/WhpHKWURgx

    @BleepinComputer

    22 Oct 2025

    9733 Impressions

    36 Retweets

    90 Likes

    16 Bookmarks

    14 Replies

    2 Quotes

  35. Session Reaper Bug – kritischer Bug in Magento Onlineshop (CVE-2025-54236) #beratung #magento #magento-2 #magento-patch https://t.co/hOR2hOaSht

    @konvis

    22 Oct 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🚨 SessionReaper (CVE-2025-54236) is now actively exploited while 62% of Adobe Commerce/Magento stores remain unpatched. We expect automated mass attacks within 48 hours. https://t.co/Po4qMTgAb6

    @sansecio

    22 Oct 2025

    788 Impressions

    6 Retweets

    9 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  37. 🚨 New plugin: SessionReaperPlugin (CVE-2025-54236). Multiple Adobe Commerce / Magento instances exposed. Details: https://t.co/maGUzIypZ1 https://t.co/7DSymZggZQ

    @leak_ix

    22 Oct 2025

    1378 Impressions

    0 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    1 Quote

  38. Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236) https://t.co/IDMettk55e https://t.co/ABqGLwgtrC

    @secharvesterx

    22 Oct 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Our Security Researcher @softpoison_ published his first research post, reverse engineering CVE-2025-54236 (SessionReaper) - a critical unauthenticated RCE in Magento. From understanding @Blaklis_'s original discovery, we wrote up our analysis here: https://t.co/xOVdFwrWQ8

    @assetnote

    22 Oct 2025

    5970 Impressions

    19 Retweets

    77 Likes

    25 Bookmarks

    0 Replies

    0 Quotes

  40. CVE-2025-54236 (SessionReaper): In-Depth Technical Analysis and Exploitation Mechanics Introduction https://t.co/PGxf1c8u8t #BugBounty #Magento #Adobe

    @NullSecurityX

    27 Sept 2025

    484 Impressions

    2 Retweets

    10 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  41. Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts #CISO https://t.co/WHNqZXmDZl https://t.co/WbTm3DkHmG

    @compuchris

    26 Sept 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. NCERT Warns Of Critical SessionReaper Vulnerability In Adobe Commerce And Magento Platforms https://t.co/fSJPENc7QH Advisory, Adobe Commerce, CVE-2025-54236, Cybersecurity Advisory, eCommerce Security, Magento Open Source, nCERT, Pakistan, Remote Code Ex… https://t.co/1S9I8hmfG

    @spinidg

    24 Sept 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 CVE-2025-54236: Vulnerabilidad crítica en Adobe Commerce y Magento Open Source. Una falla en la API REST permite la toma de control de sesiones sin autenticación. 🔧 Actualiza de inmediato si gestionas tiendas en #Magento o #AdobeCommerce 📎 https://t.co/I0jHyHMb

    @henryraul

    13 Sept 2025

    225 Impressions

    6 Retweets

    9 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  44. 🚨 Critical Magento / Adobe Commerce vuln: CVE-2025-54236 - SessionReaper 🕵️‍♂️ Hijack sessions 🔑 Potential RCE on file-based storage 💥 Read more: https://t.co/PGxf1c7WiV #Magento #AdobeCommerce #Cybersecurity #RCE

    @NullSecurityX

    13 Sept 2025

    1639 Impressions

    3 Retweets

    30 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨 Critical Alert for #AdobeCommerce & #Magento 🚨 New vulnerability (CVE-2025-54236) could let attackers hijack customer accounts. ⚡ Apply hotfix VULN-32437-2-4-X-patch immediately. No active exploits yet — act now! Need help? 👉 https://t.co/oqLsEe6Dtk https://t

    @plumrocket

    12 Sept 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 🚨 Warning to Adobe Commerce users! A critical flaw, CVE-2025-54236, lets hackers completely take over customer accounts. Urgent patching required to protect your users! #CyberSecurity #Vulnerability https://t.co/UqggMspe6h

    @xcybersecnews

    12 Sept 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  47. ⚠️Actualizaciones de seguridad para productos Adobe ❗CVE-2025-54236 ❗CVE-2025-54261 ❗CVE-2025-54256 ➡️Más info: https://t.co/ueii1rzbC1 https://t.co/jqgbPMqyUY

    @CERTpy

    11 Sept 2025

    152 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 1)🚨 Critical Patch Notice 🚨 We want to keep everyone informed about a critical vulnerability recently published by Adobe: APSB25-88 (CVE-2025-54236). What Adobe reported: - A security feature bypass vulnerability affecting Adobe Commerce & Magento Open Source versions

    @PixieCommerce

    11 Sept 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  49. CVE-2025-54236: Adobe Commerce just dropped the ultimate "Hack Me" invite, 🕵️‍♂️ say less!🔥💀 #GameOver https://t.co/zW5Abc2RoZ

    @TechTrendEcho

    11 Sept 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Adobe warned of a critical security flaw in its Commerce and Magento Open Source platforms that, if successfully exploited, could allow attackers to take control of customer accounts. CVE-2025-54236 carries a CVSS score of 9.1 out of a maximum of 10.0. https://t.co/PTK5xqA1xe htt

    @riskigy

    11 Sept 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations