ZeroHour
Sansec (Magento / e-commerce security)published ()ingested Sansec Forensics Team

SessionReaper attacks have started, 3 in 5 stores still vulnerable

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-54236CVE-2026-75650

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-54236
Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper)

Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched.

Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations.

9.195% KEV PoC
  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier (all listed 2.4.x lines and older releases)
  • Adobe Commerce B2B Listed via CPE as affected alongside Adobe Commerce; no separate version range given in the source data — treat B2B deployments on the affected Commerce 2.4.x l
  • Adobe Magento Open Source (Magento) 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5)
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts

Indicators of compromiseAll →

TypeIndicatorContext
ipv4155.117.84.134m the following IPs. 34.227.25.4 44.212.43.34 54.205.171.35 155.117.84.134 159.89.12.166 Attack payloads so far contained PHP webshell
ipv4159.89.12.166IPs. 34.227.25.4 44.212.43.34 54.205.171.35 155.117.84.134 159.89.12.166 Attack payloads so far contained PHP webshells or phpinfo p
ipv434.227.25.4ce attacks here. Attacks are coming from the following IPs. 34.227.25.4 44.212.43.34 54.205.171.35 155.117.84.134 159.89.12.166 Att
ipv444.212.43.34ere. Attacks are coming from the following IPs. 34.227.25.4 44.212.43.34 54.205.171.35 155.117.84.134 159.89.12.166 Attack payloads
ipv454.205.171.35are coming from the following IPs. 34.227.25.4 44.212.43.34 54.205.171.35 155.117.84.134 159.89.12.166 Attack payloads so far contain
Full article427 words · extracted from sansec.io · click to collapse

Six weeks after Adobe's emergency patch for SessionReaper (CVE-2025-54236), the vulnerability has entered active exploitation. Sansec Shield detected and blocked the first real-world attacks today, which is bad news for the thousands of stores that remain unpatched.

Security researchers at Assetnote published a detailed technical analysis of the vulnerability today, demo'ing the nested deserialization flaw that enables remote code execution. With proof-of-concept code circulating, the window for safe patching has effectively closed.

3 in 5 stores remain vulnerable

When we first reported on SessionReaper in September, fewer than one in three Magento stores had been patched. Six weeks later, that figure has barely improved: only 38% of stores are now protected. This means that 62% of Magento stores remain vulnerable to a critical remote code execution attack with publicly available exploit details.

For context, SessionReaper is comparable in severity to CosmicSting (2024), TrojanOrder (2022), and Shoplift (2015). Each of these vulnerabilities led to thousands of compromised stores, often within hours of exploit publication.

With exploit details now public and active attacks already observed, we expect mass exploitation within the next 48 hours. Automated scanning and exploitation tools typically emerge quickly after technical writeups are published, and SessionReaper's high impact makes it an attractive target for attackers.

See the full SessionReaper timeline in our initial article.

If you are already using Sansec Shield, you have been protected against SessionReaper attacks since the initial discovery in September. No further action is needed.

If you are not using Sansec Shield, you must act immediately:

  1. Deploy the patch now: Test and deploy the patch or upgrade to the latest security release. Adobe's developer guide provides instructions.
  2. Activate WAF protection: If you cannot deploy the patch immediately, activate a web application firewall. Sansec Shield blocks SessionReaper attacks.
  3. Scan for compromise: If you delayed patching, run a malware scanner like eComscan to check for signs of compromise.

Active exploitation

Sansec tracks ecommerce attacks in real-time around the globe. Today we blocked over 250 SessionReaper exploitation attempts in the wild targeting multiple stores. We will update this article as new details about attack patterns and methods emerge.

Attacks are coming from the following IPs.

34.227.25.4
44.212.43.34
54.205.171.35
155.117.84.134
159.89.12.166

Attack payloads so far contained PHP webshells or phpinfo probes.

Read more

Text extracted automatically; images, tables and formatting may be missing. Original: https://sansec.io/research/sessionreaper-exploitation