Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-54236 | Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper) Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched. Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations. | 9.1 | 95% | KEV PoC |
| mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5) | |
| CVE-2025-54261 | Critical Path Traversal Leading to RCE in Adobe ColdFusion 2025/2023/2021 CVE-2025-54261 is an Improper Limitation of a Pathname to a Restricted Directory (path traversal, CWE-22) flaw in Adobe ColdFusion that allows an attacker to escape a restricted directory and achieve arbitrary code execution. It is remotely exploitable over the network with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), but only on servers where certain optional configurations are enabled. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope rating indicates the attacker's impact can cross the vulnerable component's security boundary (e.g., reach other system resources). Affected deployments are ColdFusion 2025, 2023, and 2021 servers on update levels 2025.3, 2023.15, and 2021.21 or earlier that have the relevant optional configuration active. There is no public proof-of-concept and the flaw is not yet in CISA's KEV, but the ~21% EPSS probability (97th percentile) signals elevated risk of exploitation in the next 30 days, so patching should be treated as urgent. Do: Upgrade every ColdFusion 2025, 2023, and 2021 installation to the latest update release beyond 2025.3 / 2023.15 / 2021.21 per Adobe's September 2025 security bulletin, prioritizing internet-facing servers given the elevated EPSS. Inventory deployments for the optional configurations implicated by the advisory and, until patched, restrict network access to ColdFusion endpoints (e.g., at the firewall/reverse-proxy layer). Monitor Adobe's advisory and CISA KEV for confirmation of active exploitation. | 10.0 | 21% |
| large≈10,000–50,000 internet-exposed ColdFusion servers (public internet-wide scans; total installed base unpublished) |
Full article404 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 10, 2025Vulnerability / Software Security
Adobe has warned of a critical security flaw in its Commerce and Magento Open Source platforms that, if successfully exploited, could allow attackers to take control of customer accounts.
The vulnerability, tracked as CVE-2025-54236 (aka SessionReaper), carries a CVSS score of 9.1 out of a maximum of 10.0. It has been described as an improper input validation flaw. Adobe said it's not aware of any exploits in the wild.
"A potential attacker could take over customer accounts in Adobe Commerce through the Commerce REST API," Adobe said in an advisory issued today.
The issue impacts the following products and versions -
Adobe Commerce (all deployment methods):
- 2.4.9-alpha2 and earlier
- 2.4.8-p2 and earlier
- 2.4.7-p7 and earlier
- 2.4.6-p12 and earlier
- 2.4.5-p14 and earlier
- 2.4.4-p15 and earlier
Adobe Commerce B2B:
- 1.5.3-alpha2 and earlier
- 1.5.2-p2 and earlier
- 1.4.2-p7 and earlier
- 1.3.4-p14 and earlier
- 1.3.3-p15 and earlier
Magento Open Source:
- 2.4.9-alpha2 and earlier
- 2.4.8-p2 and earlier
- 2.4.7-p7 and earlier
- 2.4.6-p12 and earlier
- 2.4.5-p14 and earlier
Custom Attributes Serializable module:
- Versions 0.1.0 to 0.4.0
Adobe, in addition to releasing a hotfix for the vulnerability, said it has deployed web application firewall (WAF) rules to protect environments against exploitation attempts that may target merchants using Adobe Commerce on Cloud infrastructure.
"SessionReaper is one of the more severe Magento vulnerabilities in its history, comparable to Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022), and CosmicSting (2024)," e-commerce security company Sansec said.
The Netherlands-based firm said it successfully reproduced one possible way to exploit CVE-2025-54236, but noted that there are other possible avenues to weaponize the vulnerability.
"The vulnerability follows a familiar pattern from last year's CosmicSting attack," it added. "The attack combines a malicious session with a nested deserialization bug in Magento's REST API."
"The specific remote code execution vector appears to require file-based session storage. However, we recommend merchants using Redis or database sessions to take immediate action as well, as there are multiple ways to abuse this vulnerability."
Adobe has also shipped fixes to contain a critical path traversal vulnerability in ColdFusion (CVE-2025-54261, CVSS score: 9.0) that could lead to an arbitrary file system write. It impacts ColdFusion 2021 (Update 21 and earlier), 2023 (Update 15 and earlier), and 2025 (Update 3 and earlier) on all platforms.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/09/adobe-commerce-flaw-cve-2025-54236-lets.html