logo

Hackers exploiting critical "SessionReaper" flaw in Adobe Magento

ID: c32f6c12-16c1-5434-a714-a107f0b59807

STIX ID: report--c32f6c12-16c1-5434-a714-a107f0b59807

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-22

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Executive summary:** Adobe Commerce's critical SessionReaper vulnerability (CVE-2025-54236) is being actively exploited in the wild—Sansec blocked over 250 exploitation attempts (including PHP webshell installs and phpinfo probes) originating from multiple IPs, while roughly 62% of Magento stores remain unpatched; administrators should apply Adobe's emergency patch or recommended mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.