CVE-2025-54236
published 2025-09-09CVE-2025-54236: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation…
PriorityP195critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2025-11-14
Exploited in the wild
EPSS
96.74%
99.9th percentile
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.4-p15 | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| magento | community-edition | 0 – 2.4.5-p14 | — |
| magento | community-edition | 2.4.6-p1 – 2.4.6-p12 | — |
| magento | community-edition | 2.4.7-beta1 – 2.4.7-p7 | — |
| magento | community-edition | 2.4.8-beta1 – 2.4.8-p2 | — |
| magento | community-edition | 2.4.9-alpha1 – 2.4.9-alpha2 | — |
| magento | project-community-edition | 0 – 2.0.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated POST requests to /customer/address_file/upload followed by crafted JSON payloads to /rest/default/V1/guest-carts/{cart_id}/order — this is the two-step exploit chain used by SessionReaper. ↗
- →Hunt for PHP webshells or phpinfo probes dropped in the default file-based session storage directory on Magento/Adobe Commerce servers as post-exploitation indicators. ↗
- →Patched Magento instances return HTTP 400 Bad Request to the malicious REST API payload; unpatched instances process it — use this response differential to identify vulnerable stores. ↗
- →Check Point IPS signature 'Adobe Multiple Products Remote Code Execution (CVE-2025-54236)' can be used for network-level detection. ↗
- →Exploitation depends on file-based session storage (the Magento default); prioritize detection and patching on stores using the default session savePath configuration. ↗
- →The exploit modifies the session savePath via the REST API to point to an attacker-uploaded file; monitor for unexpected changes to session savePath values in REST API payloads. ↗
- ·Exploitation is conditional on file-based session storage being in use; stores using alternative session backends (e.g., Redis, database) may not be exploitable via this chain. ↗
- ·Adobe Commerce on Cloud customers received interim protection via a WAF rule deployed by Adobe before the patch was released; self-hosted stores did not receive this automatic mitigation. ↗
- ·The patch disables internal Magento functionality that may break custom or third-party code; test before deploying in production. ↗
- ·A leaked hotfix from Adobe may have given threat actors a head start on exploit development prior to the official patch release. ↗
- ·As of active exploitation reporting, 62% of Magento stores online remained unpatched and vulnerable. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck9.1CRITICAL
cisa9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Magento Community Edition Improper Input Validation vulnerability
ghsa·2025-09-09
CVE-2025-54236 [CRITICAL] CWE-20 Magento Community Edition Improper Input Validation vulnerability
Magento Community Edition Improper Input Validation vulnerability
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
OSV
Magento Community Edition Improper Input Validation vulnerability
osv·2025-09-09
CVE-2025-54236 [CRITICAL] Magento Community Edition Improper Input Validation vulnerability
Magento Community Edition Improper Input Validation vulnerability
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
VulnCheck
Adobe Commerce and Magento Improper Input Validation Vulnerability
vulncheck·2025·CVSS 9.1
CVE-2025-54236 [CRITICAL] CWE-20 Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Affected: Adobe Commerce and Magento
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sansec.io/research/sessionreaper-exploitation; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2025-10-27&host_type=src&vulnerability=cve-2025-54236; https://research.checkpoint.co
CISA
Adobe Commerce and Magento Improper Input Validation Vulnerability
cisa·2025-10-24·CVSS 9.1
CVE-2025-54236 [CRITICAL] CWE-20 Adobe Commerce and Magento Improper Input Validation Vulnerability
Vulnerability: Adobe Commerce and Magento Improper Input Validation Vulnerability
Affected: Adobe Commerce and Magento
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236
Remediation Due Date: 2025-11-14
Suricata
ET WEB_SPECIFIC_APPS Adobe Commerce & Magento REST API SessionReaper Execution (CVE-2025-54236)
suricata·2025-11-25·CVSS 9.1
CVE-2025-54236 [CRITICAL] ET WEB_SPECIFIC_APPS Adobe Commerce & Magento REST API SessionReaper Execution (CVE-2025-54236)
ET WEB_SPECIFIC_APPS Adobe Commerce & Magento REST API SessionReaper Execution (CVE-2025-54236)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Adobe Commerce & Magento REST API SessionReaper Execution (CVE-2025-54236)"; flow:established,to_server; flowbits:isset,ET.Adobe.CVE_2025_54236; http.uri; content:"/rest/default/V1/guest-carts/"; fast_pattern; content:"/order"; distance:0; http.request_body; content:"|22|media/customer_address/"; content:!"|22|"; within:1; http.method; content:"PUT"; reference:url,slcyber.io/assetnote-security-research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/; reference:cve,2025-54236; classtype:web-application-attack; sid:2065904; rev:1; metadata:affected_product Magento, affected_product Adobe_Commerce,
Suricata
ET WEB_SPECIFIC_APPS Adobe Commerce & Magento SessionReaper Unauthenticated Remote Code Execution (CVE-2025-54236)
suricata·2025-10-24·CVSS 9.1
CVE-2025-54236 [CRITICAL] ET WEB_SPECIFIC_APPS Adobe Commerce & Magento SessionReaper Unauthenticated Remote Code Execution (CVE-2025-54236)
ET WEB_SPECIFIC_APPS Adobe Commerce & Magento SessionReaper Unauthenticated Remote Code Execution (CVE-2025-54236)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Adobe Commerce & Magento SessionReaper Unauthenticated Remote Code Execution (CVE-2025-54236)"; flow:established,to_server; flowbits:set,ET.Adobe.CVE_2025_54236; http.uri; content:"/customer/address_file/upload"; fast_pattern; http.cookie; content:"form_key|3d|"; http.request_body; content:"name|3d 22|custom_attributes[country_id]|22|"; http.method; content:"POST"; reference:url,slcyber.io/assetnote-security-research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/; reference:cve,2025-54236; classtype:web-application-attack; sid:2065396; rev:3; metadata:affected_product Magento,
Metasploit
Magento SessionReaper
metasploit·CVSS 9.1
CVE-2025-54236 [CRITICAL] Magento SessionReaper
Magento SessionReaper
This module exploits CVE-2025-54236 (SessionReaper), a critical vulnerability in Magento/Adobe Commerce that allows unauthenticated remote code execution. The vulnerability stems from improper handling of nested deserialization in the payment method context, combined with an unauthenticated file upload endpoint. The exploit chain consists of three steps: 1. Upload a malicious PHP session file containing a Guzzle/FW1 deserialization payload via the unauthenticated /customer/address_file/upload endpoint 2. Trigger deserialization by sending a crafted JSON payload to the REST API endpoint /rest/default/V1/guest-carts/{cart_id}/order that modifies the session savePath to point to the uploaded file 3. Execute the uploaded PHP code to gain remote code execution This vulner
Nuclei
Adobe Commerce - Authentication Bypass
nuclei·CVSS 9.1
CVE-2025-54236 [CRITICAL] Adobe Commerce - Authentication Bypass
Adobe Commerce - Authentication Bypass
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
Template:
id: CVE-2025-54236
info:
name: Adobe Commerce - Authentication Bypass
author: DhiyaneshDK,slcyber,johnk3r
severity: critical
description: |
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidential
Hackernews
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
blogs_hackernews·2026-04-20
CVE-2026-20184 ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust.
There’s also a shift in how attacks run. Slower check-ins, multi-stage payloads, andmore code kept in memory. Attackers lean on real tools and normal workflows instead of custom builds. Some cas
Fortinet
Cyberthreats Targeting the 2025 Holiday Season: What CISOs Need to Know | FortiGuard Labs
blogs_fortinet·2025-11-25
Cyberthreats Targeting the 2025 Holiday Season: What CISOs Need to Know | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Cyberthreats Targeting the 2025 Holiday Season: What CISOs Need to Know
A sharp rise in deceptive domains, stolen accounts, and exploited e-commerce platforms is shaping one of the most active holiday threat environments in years
FORTIGUARD SECURITY PORTFOLIO 2025 THREAT LANDSCAPE REPORT
A Rapid Expansion of Malicious Holiday-Themed Infrastructure
Record Volumes of Stolen Account Data Fuel Credential Abuse
Critical Vulnerabilities in E-Commerce Platforms
Industrialized Tools and Services Driving Attack Scale
Monetization: Turning Compromise into Profit
What This Means for Business Leaders
What You Can Do: Best Practices
Best practices for organizations
Best practices for end-users
Want the Full Data Set?
Fortinet Protections
By Fortinet | November 25, 202
Wiz
Crying Out Cloud Monthly Newsletter - November | Wiz
blogs_wiz·2025-11-19·CVSS 9.9
CVE-2025-49844 [CRITICAL] Crying Out Cloud Monthly Newsletter - November | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
🔍 Highlights
RediShell: Critical RCE Vulnerability in Redis
Wiz Research discovered a critical RCE vulnerability (CVE-2025-49844) affecting Enterprise and Community versions of Redis, Valkey and managed Cloud services (ElastiCache, MemoryStore, Azure Cache). The flaw allows an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. Since some distributions of Redis are configured without authentication by default, or use default or weak passwords for authentication, customers are advised to prioritize patching Internet-facin
Checkpoint
27th October – Threat Intelligence Report
blogs_checkpoint·2025-10-27
CVE-2025-33073 27th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th October, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Toys “R” Us Canada has suffered a data breach that resulted in stolen customer records being leaked on the dark web. The compromised data affects an undisclosed number of individuals and includes names, physical addresses, email addresses, and phone numbers, while account passwords and financial details were not exposed.
Bleepingcomputer
Hackers exploiting critical "SessionReaper" flaw in Adobe Magento
blogs_bleepingcomputer·2025-10-22·CVSS 9.1
CVE-2025-54236 [CRITICAL] Hackers exploiting critical "SessionReaper" flaw in Adobe Magento
## Hackers exploiting critical "SessionReaper" flaw in Adobe Magento
## Bill Toulas
Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded.
The activity was spotted by e-commerce security firm Sansec, whose researchers previously described SessionReaper as one of the most severe security bugs in the history of the product.
Adobe warned about CVE-2025-54236 on September 8, saying that it is an improper input validation vulnerability that impacts Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 (and earlier).
An attacker successfully exploiting the flaw can take control of account sessions without any user interaction.
"A potential att
Bleepingcomputer
Adobe patches critical SessionReaper flaw in Magento eCommerce platform
blogs_bleepingcomputer·2025-09-09·CVSS 9.1
CVE-2025-54236 [CRITICAL] Adobe patches critical SessionReaper flaw in Magento eCommerce platform
## Adobe patches critical SessionReaper flaw in Magento eCommerce platform
## Bill Toulas
Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of " the most severe" flaws in the history of the product.
Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API.
According to e-commerce security company Sansec, Adobe notified "selected Commerce customers" on September 4th of an upcoming emergency fix planned for September 9.
"Adobe is planning to release a security update for Adobe Commerce and Magento Open Source on Tuesday, September 9, 2025," reads t
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Recorded Future
October 2025 CVE Landscape
blogs_recorded_future·CVSS 9.8
[CRITICAL] October 2025 CVE Landscape
# October 2025 CVE Landscape: 32 High-Impact Vulnerabilities Demand Immediate Attention
October 2025 saw a significant escalation in vulnerability activity, with Recorded Future's Insikt Group® identifying 32 high-impact vulnerabilities, double the 16 identified in September's CVE report. Twenty-six of these vulnerabilities scored as Very Critical.
What security teams need to know:
- Microsoft dominates: Eight of 32 vulnerabilities affect Microsoft products, including a critical WSUS deserialization flaw (CVE-2025-59287) now being actively exploited
- CL0P ransomware group exploited an Oracle E-Business Suite zero-day (CVE-2025-61882) for data theft and extortion campaigns
- Legacy vulnerabilities persist: Five of the 14 RCE-enabling vulnerabilities are over a decade old, highlighting c
https://helpx.adobe.com/security/products/magento/apsb25-88.htmlhttps://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magentohttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54236
2025-09-09
Published
2025-10-24
Added to CISA KEV
Exploited in the wild