CVE-2025-54236

Published Sep 9, 2025

Last updated a day ago

Exploit knownCVSS critical 9.1
Adobe Commerce
SessionReaper
Magento

Overview

Description
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Source
psirt@adobe.com
NVD status
Analyzed
Products
commerce, commerce_b2b, magento

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe Commerce and?Magento Improper Input Validation Vulnerability
Exploit added on
Oct 24, 2025
Exploit action due
Nov 14, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@adobe.com
CWE-20

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2025-54236 2 - CVE-2025-38617 3 - CVE-2026-21513 4 - CVE-2026-3102 5 - CVE-2017-7921 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    10 Mar 2026

    173 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236) https://t.co/LrdQCrAe4s

    @reverseame

    19 Feb 2026

    1260 Impressions

    3 Retweets

    16 Likes

    20 Bookmarks

    0 Replies

    0 Quotes

  3. Magento ストア 200 件超を侵害:脆弱性 CVE-2025-54236 の悪用と Rootkit の展開 https://t.co/t5yvZcC6pS Magento (Adobe Commerce) の深刻な脆弱性 CVE-2025-54236 (SessionReaper)

    @iototsecnews

    6 Feb 2026

    152 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Magentoの脆弱性 CVE-2025-54236がサイバー攻撃へ悪用-日本ドメインへのWebシェル設置も https://t.co/ZSkLTl2kxK

    @cybersecnews_jp

    3 Feb 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Magentoの脆弱性CVE-2025-54236がサイバー攻撃へ悪用-日本ドメインへのWebシェル設置も https://t.co/Y45305grE1 #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    @securityLab_jp

    3 Feb 2026

    142 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. #threatreport #LowCompleteness Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment | 28-01-2026 Source: https://t.co/JV8WWU4DL3 Key details below ↓ 💀Threats: Sessionreaper_vuln, 🎯Victims: Magento websites, h

    @rst_cloud

    2 Feb 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Attackers exploited critical Magento flaw CVE-2025-54236 "SessionReaper" in Jan 2026 to hijack 200+ e-commerce sites, gaining full system control across multiple regions. #Magento https://t.co/KqJi6uYxwn

    @threatcluster

    30 Jan 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Magento “SessionReaper” Zero-Day Compromises 200+ Stores With Root-Level Takeover (CVE-2025-54236) Attackers exploited CVE-2025-54236 (“SessionReaper”) to replay invalidated Magento session tokens, hijack admin sessions, and escalate to full root compromise across 2

    @ThreatSynop

    30 Jan 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Hackers Hijack 200 Magento Stores via “SessionReaper” Token Replay (CVE-2025-54236) Attackers exploited CVE-2025-54236 (“SessionReaper”) to reuse invalidated Magento session tokens, impersonate admins, and escalate to root before installing web shells for persistent

    @ThreatSynop

    30 Jan 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 200+ Magento Stores Hijacked via “SessionReaper” (CVE-2025-54236) Session-Token Replay Attackers exploited CVE-2025-54236 (“SessionReaper”) to replay improperly invalidated Magento session tokens, impersonate admins, and escalate to root—then deploy web shells for

    @ThreatSynop

    30 Jan 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. New Metasploit module for CVE-2025-54236 (SessionReaper) - Unauthenticated RCE in Magento https://t.co/mR8mSe1BSw https://t.co/6NVGSRevsj

    @Chocapikk_

    24 Nov 2025

    9236 Impressions

    35 Retweets

    125 Likes

    30 Bookmarks

    1 Reply

    0 Quotes

  15. 🚨 In this week's threat alert report, we break down active exploitation of CVE-2025-54236 “SessionReaper,” a Magento flaw enabling instant account hijacking. CrowdSec telemetry shows over 1,300 attack attempts in 20 days. Read the full analysis and protect your systems

    @Crowd_Security

    24 Nov 2025

    245 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 In this week's threat alert newsletter, we break down active exploitation of CVE-2025-54236 “SessionReaper,” a Magento flaw enabling instant account hijacking. CrowdSec telemetry shows over 1,300 attack attempts in 20 days. Read the full analysis and protect your system

    @Crowd_Security

    24 Nov 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 CVE-2025-54236 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality,

    @AnonOzzyDude

    15 Nov 2025

    125 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 CVE-2025-54236 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality,

    @AnonOzzyDude

    11 Nov 2025

    72 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 Search at https://t.co/RQho6O078k: 👉 Link: https://t.co/EqYiyP010U 👉 Dork: https://t.co/brvpIdlz6U:"magento" AND http.headers.server:"Apache" Vendor's advisory: https://t.co/HUl80VPfZq

    @Anastasis_King

    6 Nov 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🛡️ Major WAF update! We've boosted protection against account takeovers & potential remote code execution in Adobe Commerce/Magento. Enhanced detection for CVE-2025-54236 now blocks exploitation attempts. Stay secure! ➡️ https://t.co/m1zafW8K3c

    @CFchangelog

    6 Nov 2025

    308 Impressions

    1 Retweet

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 SessionReaper [Critical] Nov 02, 2025 A comprehensive threat intelligence report on the SessionReaper vulnerability, CVE-2025-54236, affecting Adobe Commerce and Magento Open Source platforms. This report details the vulnerability, its exploitation, impact, and provides... h

    @transilienceai

    2 Nov 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2025-54236 (CVSS 9.1) afecta Adobe Commerce/Magento por validación de entradas indebida, permitiendo secuestro de sesión sin interacción del usuario. Versiones impactadas: 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 y anteriores. Nuestros escaneos htt

    @tpx_Security

    30 Oct 2025

    93 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 Exploitation alert: SessionReaper (CVE-2025-54236) Last week, hackers exploited a critical Magento and Adobe Commerce vulnerability, known as SessionReaper, with hundreds of attacks detected in a single day. Fewer than half of all Magento stores have applied Adobe’s hotf

    @LiquidWeb

    30 Oct 2025

    298 Impressions

    5 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 A critical vulnerability disclosed in a recent advisory allows attackers to perform RCE. Exploitation attempts have already been recorded! Search at https://t.co/yEPe175ofA: 👉 Link: https:

    @HackingTeam777

    30 Oct 2025

    856 Impressions

    0 Retweets

    18 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  25. Session Reaper Bug – kritischer Bug in Magento Onlineshop (CVE-2025-54236) #beratung #magento #magento-2 #magento-patch https://t.co/hOR2hOaSht

    @konvis

    29 Oct 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 A critical vuln disclosed in a recent advisory allows attackers to perform RCE. Exploitation attempts have been recorded! Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/Z3k9b8yZ79

    @Netlas_io

    29 Oct 2025

    776 Impressions

    4 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  27. EMERGENCY: Magento Flaw (CVE-2025-54236) Actively Exploited for RCE. Your 3-Step Emergency Fix & Action Plan. Read the full report on - https://t.co/897flw1GSn https://t.co/mx2ersmtdG

    @cyberbivash

    29 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Deepfake scams, massive credential leaks, critical zero-days, and sprawling cyberfraud rings dominate the cyber threat landscape in the last hour. Here's what you must know: 🛡️ Adobe Commerce’s critical CVE-2025-54236 “SessionReaper” vulnerability enables session hija

    @np_cyber_news

    28 Oct 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🛡️ Cyber Threat Digest – 2025-10-28 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12280 — vulnerability was found in News: New Atroposia malware comes with a… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    28 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 28, 2025 This report details the SessionReaper vulnerability (CVE-2025-54236) affecting Adobe Commerce and Magento Open Source platforms. It outlines the vulnerability's nature, its exploitation in the wild, the... http

    @transilienceai

    28 Oct 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. ⚠️ Critical CVEs Under Active Exploitation: Adobe Commerce, Lanscope, WSUS RCE Three critical vulnerabilities are actively exploited right now. CVE-2025-54236 (Adobe Commerce/Magento RCE)—attackers actively exploiting storefronts. CVE-2025-61932 (Lanscope Endpoint

    @the_c_protocol

    27 Oct 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. CVE-2025-54236, yani “SessionReaper”, Adobe Commerce ve Magento sistemlerinde kritik bir güvenlik açığıdır. Bu açık, REST API üzerinden hiçbir kullanıcı etkileşimi olmadan saldırganın oturumları ele geçirmesine ve sisteme webshell yüklemesine izin verir. htt

    @KamCyberTR

    27 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🛡️ Cyber Threat Digest – 2025-10-27 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12275 — Mail Configuration File Manipulation News: CISA orders feds to patch Windows… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    27 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 27, 2025 This report details the SessionReaper (CVE-2025-54236) vulnerability, a critical flaw affecting Adobe Commerce and Magento Open Source platforms. The vulnerability allows for unauthenticated remote code... http

    @transilienceai

    27 Oct 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨 CVE-2025-54236 - critical 🚨 Adobe Commerce - Authentication Bypass > Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4... 👾 https://t.co/TUY7c86IYD @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    26 Oct 2025

    180 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  36. 🛡️ Cyber Threat Digest – 2025-10-26 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12216 — Malicious / Malformed App News: New CoPhish attack steals OAuth tokens… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    26 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 26, 2025 This report details the SessionReaper (CVE-2025-54236) vulnerability, its exploitation in the wild, and recommendations for mitigation. The vulnerability affects Adobe Commerce and Magento Open Source... https:

    @transilienceai

    26 Oct 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Active exploitation of CVE-2025-54236 "SessionReaper" in Adobe Commerce/Magento. Adobe patched Sep 9, 2025, but Sansec blocked 250+ attacks and ~62% of stores are still vulnerable. Researchers warn of unauthenticated session takeover and possible RCE. Patch now. #Magento #Infosec

    @cyber_sec_raj

    26 Oct 2025

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. CVE-2025-54236 - Ribuan E-CommerceTerancam: Celah Kritis “SessionReaper” di Adobe Magento Dieksploitasi Hacker Secara Aktif: https://t.co/HSwiUsGKY8

    @SavaBenediktus

    26 Oct 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  40. 🚨 Vulnerabilidad crítica en tiendas Adobe Magento 🛒 Explotación activa de la vulnerabilidad crítica CVE-2025-54236 (“SessionReaper”) https://t.co/wxqvtEcVbO

    @elhackernet

    25 Oct 2025

    2993 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🛡️ Cyber Threat Digest – 2025-10-25 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2021-43768 — In Malwarebytes For Teams News: Hackers launch mass attacks exploiting outdated… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    25 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. CVE-2025-54236 in Adobe Commerce lets attackers inject bad input for unauthorized access. Affects Magento shops—check your plugins and patch via Oct 2025 updates. Simple fix, big headache avoided. Thoughts on e-comm risks? #CyberSecurity #Vulnerability #InfoSec https://t.co/Jy3

    @cr34t0r_Cyxac

    25 Oct 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 Critical Adobe Commerce/Magento users! Our WAF just got a boost 💪, adding robust protection against CVE-2025-54236 exploits. Blocking unauthorized account takeovers & potential remote code execution. Stay secure! 🛡️ https://t.co/DKCwl27W8r

    @mveracf

    25 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Wah, CISA lagi update Katalog Vulnerabilitas yang Dieksploitasi! Tambahan panas: Adobe CVE-2025-54236 (deserialisasi jahat di Magento, hacker bisa kuasai akun customer via REST API – bayangin belanja gratis ala pencuri!) dan Microsoft CVE-2025-59287 (RCE di Windows Server Updat

    @BJORKANISM_REAL

    25 Oct 2025

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Akamai security researchers have observed SessionReaper (CVE-2025-54236) activity following exploit POC publication. In 48 hours, we saw: 🔵 300+ exploit attempts against 130+ hosts 🟠 11 unique source IPs 🔵 Multiple payloads, some that allow persistent access https://t.

    @akamai_research

    24 Oct 2025

    916 Impressions

    3 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  46. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-54236 #Adobe Commerce and Magento Improper Input Validation Vulnerability https://t.co/dPc6ZobP4I

    @ScyScan

    24 Oct 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 🛡️ We added Adobe CVE-2025-54236 and Microsoft CVE-2025-59287 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/EFWCDkQlNd

    @CISACyber

    24 Oct 2025

    8673 Impressions

    29 Retweets

    74 Likes

    10 Bookmarks

    0 Replies

    2 Quotes

  48. Yet another @Adobe #Magento vulnerability. CVE-2025-54236 (CVSS score: 9.1), a critical improper input validation flaw, could be abused to take over customer accounts in #Adobe Commerce through the Commerce REST API. HT @TheHackersNews https://t.co/CLpre3tduk

    @benrothke

    24 Oct 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Hackers Actively Exploiting “SessionReaper” Flaw in Adobe Magento! A dangerous new vulnerability (CVE-2025-54236) dubbed SessionReaper is being actively abused by attackers to hijack user sessions and drop webshells — over 250 exploit attempts were blocked within 24 hours.

    @ChbibAnas

    24 Oct 2025

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨URGENT🚨CVE-2025-54236 exploited in Adobe Commerce/Magento! 250+ attacks in 24hrs. Remote code exec & acct takeover risk via Commerce REST API. 62% unpatched, 5 attacker IPs. Patch now, block IPs (34.227.25.4,

    @bigmacd16684

    24 Oct 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

Configurations