Adobe patches critical SessionReaper flaw in Magento eCommerce platform
ID: 82b66141-5285-5a2d-b5b6-2cd664763301
STIX ID: report--82b66141-5285-5a2d-b5b6-2cd664763301
Feed Name: Bleeping Computer
Threat Score
Adobe released an emergency patch for a critical unauthenticated vulnerability (CVE-2025-54236, “SessionReaper”) in Adobe Commerce and Magento Open Source that can allow account takeover via the Commerce REST API; Adobe deployed a WAF rule for cloud customers and urged immediate patching after researchers reproduced the issue and a hotfix was leaked, though no confirmed exploitation in the wild has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
