Adobe Commerce SessionReaper exploitation and emergency remediation
Case score 66
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 66
- Main story score
- 63
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 2
- Vulnerability Core flaw in Adobe Commerce with session takeover impact through the Commerce REST API. main
- Security Patch Release Emergency update for the same CVE and product line; remediation context. context
- Advisory Mitigation Urgent guidance to deploy the patch and use temporary WAF protection. context
- Exploitation Wave Confirms live exploitation, blocked attempts, and attack patterns tied to SessionReaper. contributes
Overview
Latest development Open development history SessionReaper exploitation hits Adobe Commerce stores On October 22, 2025, Sansec said SessionReaper had entered active exploitation against Adobe Commerce stores, with Sansec Shield detecting and blocking the first real-world attacks and more than 250 attempts targeting multiple stores, including PHP webshells and phpinfo probes; the same day, Searchlight Cyber published technical analysis of CVE-2025-54236.
-
Sansec detects active SessionReaper exploitation
Sansec said Adobe Commerce stores were under active exploitation for CVE-2025-54236, with Sansec Shield detecting and blocking the first real-world attacks today, more than 250 SessionReaper attempts hitting multiple stores, and payloads including PHP webshells and phpinfo probes while 62% of Magento stores online remained unpatched.
-
Sansec detects SessionReaper exploitation and Assetnote publishes PoC
Sansec said exploitation activity for SessionReaper began on Wednesday, blocked more than 250 attempted attacks against multiple stores with Sansec Shield Web application firewall (WAF), and noted that Assetnote published a full technical analysis and proof-of-concept exploit the same day. Sansec also said attack sources expanded from five IP addresses to 97 different IPs, Adobe confirmed the flaw had been exploited in the wild, and initial payloads included PHP Web shells or phpinfo probes.
-
Adobe notifies selected Commerce customers of an emergency fix for CVE-2025-54236
Adobe notified selected Commerce customers that an emergency fix was planned for Adobe Commerce and Magento Open Source, warning that the update would address a critical vulnerability later identified as CVE-2025-54236 and SessionReaper.