Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. The activity was spotted by e-commerce security firm Sansec, whose researchers previously described SessionReaper as one of the most severe security bugs in the history of the product. Adobe warned about CVE-2025-54236 on September 8, saying that it is an improper input validation vulnerability that impacts Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 (and earlier). An attacker successfully exploiting the flaw can take control of account sessions without any user interaction. "A potential attacker could take over customer accounts in Adobe Commerce through the Commerce REST API," Adobe explains. Sansec previously stated that successful exploitation likely depends on storing session data on the file system, the default configuration used by most stores, and that a leaked hotfix from the vendor could provide clues on how it can be leveraged.. Roughly six weeks after the emergency patch for SessionReaper became available, Sansec is confirming active exploitation in the wild. "Six weeks after Adobe's emergency patch for SessionReaper (CVE-2025-54236), the vulnerability has entered active exploitation," reads Sansec's bulletin. "Sansec Shield detected and blocked the first real-world attacks today, which is bad news for the thousands of stores that remain unpatched," the...
Hackers exploiting critical "SessionReaper" flaw in Adobe Magento
BleepingComputer
·Bill Toulas
·Published Oct 22, 2025
·Updated
Affected Software
6 affected components
Adobe Commerce=2.4.9-alpha2
Adobe Commerce=2.4.8-p2
Adobe Commerce=2.4.7-p7
Adobe Commerce=2.4.6-p12
Adobe Commerce=2.4.5-p14
Adobe Commerce=2.4.4-p15
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a critical vulnerability known as 'SessionReaper' in Adobe Commerce platforms.
2
What security implications are discussed in relation to the SessionReaper flaw?
The article highlights the active exploitation of the SessionReaper flaw, resulting in hundreds of attack attempts on affected platforms.
3
What versions of Adobe Commerce are affected by the vulnerability?
The affected versions of Adobe Commerce include 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15.
4
Who identified the exploitation of the SessionReaper vulnerability?
The exploitation was spotted by the e-commerce security firm Sansec.
5
What is the severity level of the SessionReaper vulnerability?
The SessionReaper vulnerability is classified as critical, indicating a significant risk to affected systems.