logo

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

ID: 82b66141-5285-5a2d-b5b6-2cd664763301

STIX ID: report--82b66141-5285-5a2d-b5b6-2cd664763301

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-09-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Adobe released an emergency patch for a critical unauthenticated vulnerability (CVE-2025-54236, “SessionReaper”) in Adobe Commerce and Magento Open Source that can allow account takeover via the Commerce REST API; Adobe deployed a WAF rule for cloud customers and urged immediate patching after researchers reproduced the issue and a hotfix was leaked, though no confirmed exploitation in the wild has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.