Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of " the most severe" flaws in the history of the product. Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API. According to e-commerce security company Sansec, Adobe notified "selected Commerce customers" on September 4th of an upcoming emergency fix planned for September 9. "Adobe is planning to release a security update for Adobe Commerce and Magento Open Source on Tuesday, September 9, 2025," reads the notice. "This update resolves a critical vulnerability. Successful exploitation could lead to security feature bypass." Customers using Adobe Commerce on Cloud are already protected by a web application firewall (WAF) rule deployed by Adobe as an intermediate measure. Adobe says in the security bulletin that it is not aware of any exploitation activity in the wild. Sansec's advisory also notes that the researchers have not seen any active exploitation of SessionReaper. However, Sansec says that an initial hotfix for CVE-2025-54236 was leaked last week, which may give threat actors a potential head start on creating an exploit. According to the researchers, successful exploitation "appears" to depend on storing session data on the file system, a default configuration that most stor...
Adobe patches critical SessionReaper flaw in Magento eCommerce platform
BleepingComputer
·Bill Toulas
·Published Sep 9, 2025
·Updated
Affected Software
3 affected components
Adobe Commerce
Adobe Magento Open Source
Adobe Commerce on Cloud
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability known as SessionReaper in Adobe's Magento eCommerce platforms.
2
What security implications are discussed regarding the SessionReaper flaw?
The SessionReaper flaw is described as one of the most severe vulnerabilities in the history of Adobe Commerce and Magento, posing significant risks to users.
3
What products or software are affected by the SessionReaper vulnerability?
The affected products include Adobe Commerce, Adobe Magento Open Source, and Adobe Commerce on Cloud.
4
What is the identifier for the SessionReaper vulnerability?
The vulnerability is identified as CVE-2025-54236.
5
How critical is the SessionReaper flaw compared to other vulnerabilities?
The SessionReaper flaw is characterized as one of the most severe vulnerabilities ever identified in Adobe's eCommerce platforms.