Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Security Patch Release

Adobe Commerce SessionReaper exploitation and emergency remediation

Updated 24.10.2025 00:25
Case score 66
Members 4 First seen 09.09.2025 18:53 Latest activity 24.10.2025 00:25

Overview

**CVE-2025-54236** in **Adobe Commerce** has moved into active abuse, with SessionReaper attempts targeting the **Commerce REST API** and Sansec already blocking more than **250** attempts against multiple stores. The flaw can let an attacker take control of customer account sessions without user interaction, which makes exposed commerce deployments an immediate concern. Adobe has already issued an emergency update for **Adobe Commerce** and **Magento Open Source**, and **Adobe Commerce on Cloud** customers had a temporary **WAF rule** while administrators tested and deployed the fix. Available evidence confirms live attack attempts, but the full extent of successful compromise remains unknown.
Latest development Open development history 3 earlier developments SessionReaper exploitation hits Adobe Commerce stores On October 22, 2025, Sansec said SessionReaper had entered active exploitation against Adobe Commerce stores, with Sansec Shield detecting and blocking the first real-world attacks and more than 250 attempts targeting multiple stores, including PHP webshells and phpinfo probes; the same day, Searchlight Cyber published technical analysis of CVE-2025-54236.
  1. Earlier development

    Sansec detects active SessionReaper exploitation

    Sansec said Adobe Commerce stores were under active exploitation for CVE-2025-54236, with Sansec Shield detecting and blocking the first real-world attacks today, more than 250 SessionReaper attempts hitting multiple stores, and payloads including PHP webshells and phpinfo probes while 62% of Magento stores online remained unpatched.

  2. Earlier development

    Sansec detects SessionReaper exploitation and Assetnote publishes PoC

    Sansec said exploitation activity for SessionReaper began on Wednesday, blocked more than 250 attempted attacks against multiple stores with Sansec Shield Web application firewall (WAF), and noted that Assetnote published a full technical analysis and proof-of-concept exploit the same day. Sansec also said attack sources expanded from five IP addresses to 97 different IPs, Adobe confirmed the flaw had been exploited in the wild, and initial payloads included PHP Web shells or phpinfo probes.

  3. Earlier development

    Adobe notifies selected Commerce customers of an emergency fix for CVE-2025-54236

    Adobe notified selected Commerce customers that an emergency fix was planned for Adobe Commerce and Magento Open Source, warning that the update would address a critical vulnerability later identified as CVE-2025-54236 and SessionReaper.

Signals

Exploitation
CVEs/products
Remediation
Threat context

Technical intelligence

Existing Case data

Member happenings

Vulnerability Adobe Commerce SessionReaper improper input validation flaw (CVE-2025-54236)
Updated 22.10.2025 21:41 Lead Contribution 63
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

The **SessionReaper** flaw in **Adobe Commerce** is an actively exploited **CVE-2025-54236** vulnerability that can lead to **customer account takeover** and **account session control**. Adobe identified the bug as an **improper input validation** issue, and the attack path runs through the **Commerce REST API**. The issue affects **2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 (and earlier)**, while Sansec said **more than 250** attempts were blocked against multiple stores. The **security update** is available, but many stores remain **unpatched**.

Exploitation Wave Adobe Commerce SessionReaper exploitation wave (CVE-2025-54236)
Updated 22.10.2025 21:41 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Adobe Commerce** is seeing an **active exploitation wave** for **CVE-2025-54236 / SessionReaper**, with **hundreds of attempts** hitting **multiple stores** and many deployments still **unpatched**. The attacks matter because the flaw can let an attacker **take control of account sessions** without user interaction. **Sansec** says it has already **detected and blocked** the first real-world attacks.

Advisory/Mitigation Adobe mitigation guidance for Adobe Commerce and Magento Open Source urgent remediation for CVE-2025-54236
Updated 09.09.2025 18:53 Context
Urgency Immediate Patch Patch Available

Adobe urged **Adobe Commerce** and **Magento Open Source** administrators to **test and deploy the available patch immediately** for **CVE-2025-54236**, reducing the risk of unauthenticated abuse of the **Commerce REST API**. The advisory centers on the **SessionReaper** flaw, which researchers describe as one of the platform's most severe issues. **Adobe Commerce on Cloud** customers had a temporary **WAF rule** in place while remediation moved forward.

Security Patch Release Adobe security patch release for CVE-2025-54236
Updated 24.10.2025 00:25 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

**Adobe** issued an **emergency update** for **Adobe Commerce** and **Magento open source** to fix **CVE-2025-54236**, an improper input validation flaw that could enable remote session takeover. The patch, disclosed on **Sept. 9**, addressed a high-impact weakness in the e-commerce platform stack. Administrators should treat the release as urgent because the flaw was later confirmed as **exploited in the wild**.