CVE-2025-54236

Published Sep 9, 2025

Last updated 9 days ago

Exploit knownCVSS critical 9.1
Adobe Commerce
SessionReaper
Magento

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-54236, also known as SessionReaper, is a vulnerability affecting Adobe Commerce and Magento installations. It stems from improper input validation in the Magento Web API. Successful exploitation could lead to security feature bypass, potentially allowing attackers to take over customer accounts, steal data, and place fraudulent orders. The vulnerability allows unauthenticated remote code execution. The attack combines a malicious session with a nested deserialization bug in Magento's REST API. Exploitation appears to require file-based session storage. Adobe has released an emergency patch to address this critical flaw.

Description
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Source
psirt@adobe.com
NVD status
Analyzed
Products
commerce, commerce_b2b, magento

Insights

Analysis from the Intruder Security Team
Published Oct 23, 2025

This vulnerability is described as an account takeover, however there were rumours early on that this may be more significant.

Assetnote released a research article on the 22nd of October breaking down the vulnerability, highlighting that this is far more serious than Adobe have described. Ultimately through the deserialization vulnerability, an attacker can gain code execution by the creation of a backdoor php file. In order to achieve that, the attacker must know, or be able to guess the (e.g. default) installation path of Magento.

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe Commerce and?Magento Improper Input Validation Vulnerability
Exploit added on
Oct 24, 2025
Exploit action due
Nov 14, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@adobe.com
CWE-20

Social media

Hype score
Not currently trending
  1. 🔵 pgx (Go), SQL Injection via Placeholder Confusion, #CVE-2025-54236 (Low severity) https://t.co/ZEmqEF81FW

    @dailycve

    23 Apr 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Check if your Magento site is safe from Session Reaper (CVE-2025-54236) https://t.co/tqPoeo91Jx #magento2 #security #devsecops #magento-cloud #adobe-commerce

    @dmnlk

    15 Apr 2026

    260 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CRITICAL: CVE-2025-54236 (CVSS 9.1) - Adobe Commerce Improper Input Validation enables session takeover. No user interaction required. Affects versions 2.4.4-p15 through 2.4.9-alpha2. Patch immediately. #CVE #PatchNow #ThreatIntel

    @DFIR_Lab

    7 Apr 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CRITICAL ALERT: Adobe Commerce Session Takeover Vulnerability CVE-2025-54236 | CVSS 9.1 | CWE-20: Improper Input Validation KEY DETAILS: • Affected Products: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier • Attack

    @DFIR_Lab

    5 Apr 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Voltei, tava brincando com a CVE-2025-54236 bem bosta, mas da para brincar! @BolhaSec #bolhasec #bolhadev #CyberAttack #deface #hacking https://t.co/Nhgf63Cv6c

    @h4xxz_x

    5 Apr 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Attackers exploited Magento's PolyShell vulnerability (CVE-2025-54236) to upload malicious PHP files through the REST API, achieving unauthenticated RCE. Post-compromise lateral movement across connected databases highlights how runtime segmentation can limit blast radius in

    @aviatrixtrc

    20 Mar 2026

    107 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Attackers are exploiting Magento's 'SessionReaper' vulnerability (CVE-2025-54236) to upload malicious polyglot files via the REST API, achieving unauthenticated remote code execution. Post-compromise lateral movement highlights how runtime segmentation can help contain breach

    @aviatrixtrc

    20 Mar 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Top 5 Trending CVEs: 1 - CVE-2025-54236 2 - CVE-2025-38617 3 - CVE-2026-21513 4 - CVE-2026-3102 5 - CVE-2017-7921 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    10 Mar 2026

    173 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236) https://t.co/LrdQCrAe4s

    @reverseame

    19 Feb 2026

    1260 Impressions

    3 Retweets

    16 Likes

    20 Bookmarks

    0 Replies

    0 Quotes

  10. Magento ストア 200 件超を侵害:脆弱性 CVE-2025-54236 の悪用と Rootkit の展開 https://t.co/t5yvZcC6pS Magento (Adobe Commerce) の深刻な脆弱性 CVE-2025-54236 (SessionReaper)

    @iototsecnews

    6 Feb 2026

    152 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Magentoの脆弱性 CVE-2025-54236がサイバー攻撃へ悪用-日本ドメインへのWebシェル設置も https://t.co/ZSkLTl2kxK

    @cybersecnews_jp

    3 Feb 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Magentoの脆弱性CVE-2025-54236がサイバー攻撃へ悪用-日本ドメインへのWebシェル設置も https://t.co/Y45305grE1 #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    @securityLab_jp

    3 Feb 2026

    142 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. #threatreport #LowCompleteness Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment | 28-01-2026 Source: https://t.co/JV8WWU4DL3 Key details below ↓ 💀Threats: Sessionreaper_vuln, 🎯Victims: Magento websites, h

    @rst_cloud

    2 Feb 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Attackers exploited critical Magento flaw CVE-2025-54236 "SessionReaper" in Jan 2026 to hijack 200+ e-commerce sites, gaining full system control across multiple regions. #Magento https://t.co/KqJi6uYxwn

    @threatcluster

    30 Jan 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 Magento “SessionReaper” Zero-Day Compromises 200+ Stores With Root-Level Takeover (CVE-2025-54236) Attackers exploited CVE-2025-54236 (“SessionReaper”) to replay invalidated Magento session tokens, hijack admin sessions, and escalate to full root compromise across 2

    @ThreatSynop

    30 Jan 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Hackers Hijack 200 Magento Stores via “SessionReaper” Token Replay (CVE-2025-54236) Attackers exploited CVE-2025-54236 (“SessionReaper”) to reuse invalidated Magento session tokens, impersonate admins, and escalate to root before installing web shells for persistent

    @ThreatSynop

    30 Jan 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 200+ Magento Stores Hijacked via “SessionReaper” (CVE-2025-54236) Session-Token Replay Attackers exploited CVE-2025-54236 (“SessionReaper”) to replay improperly invalidated Magento session tokens, impersonate admins, and escalate to root—then deploy web shells for

    @ThreatSynop

    30 Jan 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Exploitation of Magento CVE-2025-54236: Independent Intrusions Leading to Root Compromise and Web Shell Deployment 📌 New TI Report ▶ https://t.co/yfJRJV8KTR

    @OASIS_SECURITY_

    28 Jan 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. New Metasploit module for CVE-2025-54236 (SessionReaper) - Unauthenticated RCE in Magento https://t.co/mR8mSe1BSw https://t.co/6NVGSRevsj

    @Chocapikk_

    24 Nov 2025

    9236 Impressions

    35 Retweets

    125 Likes

    30 Bookmarks

    1 Reply

    0 Quotes

  22. 🚨 In this week's threat alert report, we break down active exploitation of CVE-2025-54236 “SessionReaper,” a Magento flaw enabling instant account hijacking. CrowdSec telemetry shows over 1,300 attack attempts in 20 days. Read the full analysis and protect your systems

    @Crowd_Security

    24 Nov 2025

    245 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🚨 In this week's threat alert newsletter, we break down active exploitation of CVE-2025-54236 “SessionReaper,” a Magento flaw enabling instant account hijacking. CrowdSec telemetry shows over 1,300 attack attempts in 20 days. Read the full analysis and protect your system

    @Crowd_Security

    24 Nov 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CVE-2025-54236 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality,

    @AnonOzzyDude

    15 Nov 2025

    125 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 CVE-2025-54236 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality,

    @AnonOzzyDude

    11 Nov 2025

    72 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 Search at https://t.co/RQho6O078k: 👉 Link: https://t.co/EqYiyP010U 👉 Dork: https://t.co/brvpIdlz6U:"magento" AND http.headers.server:"Apache" Vendor's advisory: https://t.co/HUl80VPfZq

    @Anastasis_King

    6 Nov 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🛡️ Major WAF update! We've boosted protection against account takeovers & potential remote code execution in Adobe Commerce/Magento. Enhanced detection for CVE-2025-54236 now blocks exploitation attempts. Stay secure! ➡️ https://t.co/m1zafW8K3c

    @CFchangelog

    6 Nov 2025

    308 Impressions

    1 Retweet

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 SessionReaper [Critical] Nov 02, 2025 A comprehensive threat intelligence report on the SessionReaper vulnerability, CVE-2025-54236, affecting Adobe Commerce and Magento Open Source platforms. This report details the vulnerability, its exploitation, impact, and provides... h

    @transilienceai

    2 Nov 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. CVE-2025-54236 (CVSS 9.1) afecta Adobe Commerce/Magento por validación de entradas indebida, permitiendo secuestro de sesión sin interacción del usuario. Versiones impactadas: 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 y anteriores. Nuestros escaneos htt

    @tpx_Security

    30 Oct 2025

    93 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 Exploitation alert: SessionReaper (CVE-2025-54236) Last week, hackers exploited a critical Magento and Adobe Commerce vulnerability, known as SessionReaper, with hundreds of attacks detected in a single day. Fewer than half of all Magento stores have applied Adobe’s hotf

    @LiquidWeb

    30 Oct 2025

    298 Impressions

    5 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 A critical vulnerability disclosed in a recent advisory allows attackers to perform RCE. Exploitation attempts have already been recorded! Search at https://t.co/yEPe175ofA: 👉 Link: https:

    @HackingTeam777

    30 Oct 2025

    856 Impressions

    0 Retweets

    18 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  32. Session Reaper Bug – kritischer Bug in Magento Onlineshop (CVE-2025-54236) #beratung #magento #magento-2 #magento-patch https://t.co/hOR2hOaSht

    @konvis

    29 Oct 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CVE-2025-54236: Improper Input Validation in Magento (Adobe Commerce), 9.1 rating 🔥 A critical vuln disclosed in a recent advisory allows attackers to perform RCE. Exploitation attempts have been recorded! Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/Z3k9b8yZ79

    @Netlas_io

    29 Oct 2025

    776 Impressions

    4 Retweets

    9 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  34. EMERGENCY: Magento Flaw (CVE-2025-54236) Actively Exploited for RCE. Your 3-Step Emergency Fix & Action Plan. Read the full report on - https://t.co/897flw1GSn https://t.co/mx2ersmtdG

    @cyberbivash

    29 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Deepfake scams, massive credential leaks, critical zero-days, and sprawling cyberfraud rings dominate the cyber threat landscape in the last hour. Here's what you must know: 🛡️ Adobe Commerce’s critical CVE-2025-54236 “SessionReaper” vulnerability enables session hija

    @np_cyber_news

    28 Oct 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🛡️ Cyber Threat Digest – 2025-10-28 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12280 — vulnerability was found in News: New Atroposia malware comes with a… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    28 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 28, 2025 This report details the SessionReaper vulnerability (CVE-2025-54236) affecting Adobe Commerce and Magento Open Source platforms. It outlines the vulnerability's nature, its exploitation in the wild, the... http

    @transilienceai

    28 Oct 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. ⚠️ Critical CVEs Under Active Exploitation: Adobe Commerce, Lanscope, WSUS RCE Three critical vulnerabilities are actively exploited right now. CVE-2025-54236 (Adobe Commerce/Magento RCE)—attackers actively exploiting storefronts. CVE-2025-61932 (Lanscope Endpoint

    @the_c_protocol

    27 Oct 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. CVE-2025-54236, yani “SessionReaper”, Adobe Commerce ve Magento sistemlerinde kritik bir güvenlik açığıdır. Bu açık, REST API üzerinden hiçbir kullanıcı etkileşimi olmadan saldırganın oturumları ele geçirmesine ve sisteme webshell yüklemesine izin verir. htt

    @KamCyberTR

    27 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🛡️ Cyber Threat Digest – 2025-10-27 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12275 — Mail Configuration File Manipulation News: CISA orders feds to patch Windows… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    27 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 27, 2025 This report details the SessionReaper (CVE-2025-54236) vulnerability, a critical flaw affecting Adobe Commerce and Magento Open Source platforms. The vulnerability allows for unauthenticated remote code... http

    @transilienceai

    27 Oct 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 CVE-2025-54236 - critical 🚨 Adobe Commerce - Authentication Bypass > Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4... 👾 https://t.co/TUY7c86IYD @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    26 Oct 2025

    180 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  43. 🛡️ Cyber Threat Digest – 2025-10-26 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2025-12216 — Malicious / Malformed App News: New CoPhish attack steals OAuth tokens… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    26 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🚨 SessionReaper Threat Intelligence Report [Critical] Oct 26, 2025 This report details the SessionReaper (CVE-2025-54236) vulnerability, its exploitation in the wild, and recommendations for mitigation. The vulnerability affects Adobe Commerce and Magento Open Source... https:

    @transilienceai

    26 Oct 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Active exploitation of CVE-2025-54236 "SessionReaper" in Adobe Commerce/Magento. Adobe patched Sep 9, 2025, but Sansec blocked 250+ attacks and ~62% of stores are still vulnerable. Researchers warn of unauthenticated session takeover and possible RCE. Patch now. #Magento #Infosec

    @cyber_sec_raj

    26 Oct 2025

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. CVE-2025-54236 - Ribuan E-CommerceTerancam: Celah Kritis “SessionReaper” di Adobe Magento Dieksploitasi Hacker Secara Aktif: https://t.co/HSwiUsGKY8

    @SavaBenediktus

    26 Oct 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  47. 🚨 Vulnerabilidad crítica en tiendas Adobe Magento 🛒 Explotación activa de la vulnerabilidad crítica CVE-2025-54236 (“SessionReaper”) https://t.co/wxqvtEcVbO

    @elhackernet

    25 Oct 2025

    2993 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🛡️ Cyber Threat Digest – 2025-10-25 KEV: CVE-2025-54236 — Adobe Commerce and Magento NVD: CVE-2021-43768 — In Malwarebytes For Teams News: Hackers launch mass attacks exploiting outdated… #cybersecurity #infosec #CVE More: https://t.co/J1fpKfnDnv

    @dpharristech

    25 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. CVE-2025-54236 in Adobe Commerce lets attackers inject bad input for unauthorized access. Affects Magento shops—check your plugins and patch via Oct 2025 updates. Simple fix, big headache avoided. Thoughts on e-comm risks? #CyberSecurity #Vulnerability #InfoSec https://t.co/Jy3

    @cr34t0r_Cyxac

    25 Oct 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨 Critical Adobe Commerce/Magento users! Our WAF just got a boost 💪, adding robust protection against CVE-2025-54236 exploits. Blocking unauthorized account takeovers & potential remote code execution. Stay secure! 🛡️ https://t.co/DKCwl27W8r

    @mveracf

    25 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations