• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-sessionreaper-flaw-in-adobe-magento/

Hackers exploiting critical "SessionReaper" flaw in Adobe Magento

BleepingComputer
·
Bill Toulas
·
Published Oct 22, 2025
·
Updated

Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. The activity was spotted by e-commerce security firm Sansec, whose researchers previously described SessionReaper as one of the most severe security bugs in the history of the product. Adobe warned about CVE-2025-54236 on September 8, saying that it is an improper input validation vulnerability that impacts Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 (and earlier). An attacker successfully exploiting the flaw can take control of account sessions without any user interaction. "A potential attacker could take over customer accounts in Adobe Commerce through the Commerce REST API," Adobe explains. Sansec previously stated that successful exploitation likely depends on storing session data on the file system, the default configuration used by most stores, and that a leaked hotfix from the vendor could provide clues on how it can be leveraged.. Roughly six weeks after the emergency patch for SessionReaper became available, Sansec is confirming active exploitation in the wild. "Six weeks after Adobe's emergency patch for SessionReaper (CVE-2025-54236), the vulnerability has entered active exploitation," reads Sansec's bulletin. "Sansec Shield detected and blocked the first real-world attacks today, which is bad news for the thousands of stores that remain unpatched," the...

Read full article

Affected Software

6 affected components
Adobe Commerce=2.4.9-alpha2
Adobe Commerce=2.4.8-p2
Adobe Commerce=2.4.7-p7
Adobe Commerce=2.4.6-p12
Adobe Commerce=2.4.5-p14
Adobe Commerce=2.4.4-p15
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical vulnerability known as 'SessionReaper' in Adobe Commerce platforms.

2

What security implications are discussed in relation to the SessionReaper flaw?

The article highlights the active exploitation of the SessionReaper flaw, resulting in hundreds of attack attempts on affected platforms.

3

What versions of Adobe Commerce are affected by the vulnerability?

The affected versions of Adobe Commerce include 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15.

4

Who identified the exploitation of the SessionReaper vulnerability?

The exploitation was spotted by the e-commerce security firm Sansec.

5

What is the severity level of the SessionReaper vulnerability?

The SessionReaper vulnerability is classified as critical, indicating a significant risk to affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203