Adobe security patch release for CVE-2025-54236
Security Patch Release
Summary
Hide ▲
Show ▼
Adobe issued an emergency update for Adobe Commerce and Magento open source to fix CVE-2025-54236, an improper input validation flaw that could enable remote session takeover. The patch, disclosed on Sept. 9, addressed a high-impact weakness in the e-commerce platform stack. Administrators should treat the release as urgent because the flaw was later confirmed as exploited in the wild.
Cases
Related Happenings
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch Release
First: 22.05.2026 11:19
Last: 22.05.2026 11:19
Sources 1
About this happening:
**TrendAI** released **Apex One** security updates after confirming a **zero-day** had been **exploited in the wild**, leaving **on-premises installations** at risk until patched....
TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926
Security Patch ReleaseAbout this happening: **TrendAI** released **Apex One** security updates after confirming a **zero-day** had been **exploited in the wild**, leaving **on-premises installations** at risk until patched....
Microsoft security patch release for CVE-2026-41089
Security Patch Release
First: 13.05.2026 00:46
Last: 13.05.2026 00:46
Sources 1
About this happening:
**Microsoft** and other major software vendors shipped a heavy **May 2026** patch cycle, with fixes spanning **Windows**, **iOS**, **Firefox**, **Oracle** products, and **Chrome**...
Microsoft security patch release for CVE-2026-41089
Security Patch ReleaseAbout this happening: **Microsoft** and other major software vendors shipped a heavy **May 2026** patch cycle, with fixes spanning **Windows**, **iOS**, **Firefox**, **Oracle** products, and **Chrome**...
Microsoft May 2026 Patch Tuesday (120 flaws)
Security Patch Release
First: 12.05.2026 21:08
Last: 12.05.2026 21:08
Sources 1
About this happening:
**Microsoft** released its **May 2026 Patch Tuesday** updates, fixing **120 flaws** and disclosing **no zero-days**. The bundle includes **17 Critical** vulnerabilities, with mult...
Microsoft May 2026 Patch Tuesday (120 flaws)
Security Patch ReleaseAbout this happening: **Microsoft** released its **May 2026 Patch Tuesday** updates, fixing **120 flaws** and disclosing **no zero-days**. The bundle includes **17 Critical** vulnerabilities, with mult...
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch Release
First: 14.04.2026 20:41
Last: 14.04.2026 20:41
Sources 1
About this happening:
Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The rele...
Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Security Patch ReleaseAbout this happening: Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The rele...
Adobe security patch release for CVE-2026-34621
Security Patch Release
First: 12.04.2026 07:25
Last: 12.04.2026 07:25
Sources 1
About this happening:
**Adobe** issued **emergency updates** for **Acrobat Reader**, **Acrobat DC**, and **Acrobat 2024** after **CVE-2026-34621** was found **actively exploited in the wild**. The patc...
Adobe security patch release for CVE-2026-34621
Security Patch ReleaseAbout this happening: **Adobe** issued **emergency updates** for **Acrobat Reader**, **Acrobat DC**, and **Acrobat 2024** after **CVE-2026-34621** was found **actively exploited in the wild**. The patc...
Timeline
-
24.10.2025 00:25 3 articles · 7mo ago
Adobe Commerce emergency update for CVE-2025-54236
Mitigation Patch UpdateAdobe issued an emergency update for Adobe Commerce (formerly Magento) and Magento open source versions to fix CVE-2025-54236, an improper input validation flaw that could let attackers bypass security features and remotely take over Adobe Commerce sessions without user interaction.
Show sources
- Fear the 'SessionReaper': Adobe Commerce Flaw Under Attack — www.darkreading.com — 24.10.2025 00:25
- Fear the 'SessionReaper': Adobe Commerce Flaw Under Attack — www.darkreading.com — 24.10.2025 00:25
- Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts — thehackernews.com — 10.09.2025 04:08
-
24.10.2025 00:25 1 articles · 7mo ago
Sansec detects SessionReaper exploitation and Assetnote publishes PoC
Detection Ioc UpdateSansec said exploitation activity for SessionReaper began on Wednesday, blocked more than 250 attempted attacks against multiple stores with Sansec Shield Web application firewall (WAF), and noted that Assetnote published a full technical analysis and proof-of-concept exploit the same day. Sansec also said attack sources expanded from five IP addresses to 97 different IPs, Adobe confirmed the flaw had been exploited in the wild, and initial payloads included PHP Web shells or phpinfo probes.
Show sources
- Fear the 'SessionReaper': Adobe Commerce Flaw Under Attack — www.darkreading.com — 24.10.2025 00:25