• News/
  • https://www.bleepingcomputer.com/news/security/adobe-patches-critical-sessionreaper-flaw-in-magento-ecommerce-platform/

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

BleepingComputer
·
Bill Toulas
·
Published Sep 9, 2025
·
Updated

Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of " the most severe" flaws in the history of the product. Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API. According to e-commerce security company Sansec, Adobe notified "selected Commerce customers" on September 4th of an upcoming emergency fix planned for September 9. "Adobe is planning to release a security update for Adobe Commerce and Magento Open Source on Tuesday, September 9, 2025," reads the notice. "This update resolves a critical vulnerability. Successful exploitation could lead to security feature bypass." Customers using Adobe Commerce on Cloud are already protected by a web application firewall (WAF) rule deployed by Adobe as an intermediate measure. Adobe says in the security bulletin that it is not aware of any exploitation activity in the wild. Sansec's advisory also notes that the researchers have not seen any active exploitation of SessionReaper. However, Sansec says that an initial hotfix for CVE-2025-54236 was leaked last week, which may give threat actors a potential head start on creating an exploit. According to the researchers, successful exploitation "appears" to depend on storing session data on the file system, a default configuration that most stor...

Read full article

Affected Software

3 affected components
Adobe Commerce
Adobe Magento Open Source
Adobe Commerce on Cloud
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability known as SessionReaper in Adobe's Magento eCommerce platforms.

2

What security implications are discussed regarding the SessionReaper flaw?

The SessionReaper flaw is described as one of the most severe vulnerabilities in the history of Adobe Commerce and Magento, posing significant risks to users.

3

What products or software are affected by the SessionReaper vulnerability?

The affected products include Adobe Commerce, Adobe Magento Open Source, and Adobe Commerce on Cloud.

4

What is the identifier for the SessionReaper vulnerability?

The vulnerability is identified as CVE-2025-54236.

5

How critical is the SessionReaper flaw compared to other vulnerabilities?

The SessionReaper flaw is characterized as one of the most severe vulnerabilities ever identified in Adobe's eCommerce platforms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203