SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has rep...

Oct 23, 2025By Padmashree P3 min read

A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has reported blocking over 250 exploitation attempts, underscoring the urgency for administrators to apply patches or mitigations immediately.

Vulnerability Details

SessionReaper (CVE-2025-54236) is a critical improper input validation vulnerability in the Commerce REST API.

  • Exploitation Method:Attackers can upload malicious files disguised as session data via the /customer/address_file/upload endpoint, bypassing authentication controls.
  • Resulting Risk:This creates a nested deserialization vulnerability, which can lead to full remote code execution, particularly on systems using file-based session storage.

A technical analysis with proof-of-concept code was published by Assetnote researchers on October 21, 2025, further increasing the urgency for patching.

Affected Products

Adobe Commerce & Magento Open Source versions:

  • 2.4.9-alpha2 and earlier
  • 2.4.8-p2 and earlier
  • 2.4.7-p7 and earlier
  • 2.4.6-p12 and earlier
  • 2.4.5-p14 and earlier
  • 2.4.4-p15 and earlier

Adobe Commerce B2B versions:

  • 1.5.3-alpha2 and earlier
  • 1.5.2-p2 and earlier
  • 1.4.2-p7 and earlier
  • 1.3.4-p14 and earlier
  • 1.3.3-p15 and earlier

Impact & Exploit Potential

Successful exploitation of SessionReaper can result in severe consequences:

  • Customer account takeover
  • Remote code execution
  • Data breaches
  • Full store compromise

Security researchers at Sansec have compared SessionReaper to prior high-severity Magento vulnerabilities, such as CosmicSting, TrojanOrder, and Shoplift, all of which caused widespread breaches .

Observed Exploit Behavior:Attackers have uploaded PHP web shells and executed phpinfo() probes to extract server configuration details.

Mitigation & Recommendations

Administrators should implement the following immediate mitigations:

  1. Apply the Official Patch: Upgrade to the latest secure release or deploy Adobe’s official patch.
  2. Web Application Firewall (WAF): Enable WAF protection for temporary mitigation. Sansec Shield and Adobe Fastly can block this specific attack.
  3. Scan for Compromises: Use malware scanners to detect potential compromises.
  4. Rotate Cryptographic Keys: Rotate CMS cryptographic keys to prevent attackers from persistently modifying content.

Indicators of Compromise (IOCs)

Sansec has identified active exploit IP addresses:

  • 34.227.25[.]4
  • 44.212.43[.]34
  • 54.205.171[.]35
  • 155.117.84[.]134
  • 159.89.12[.]166

These IPs have been observed delivering payloads, probing server configurations, or installing backdoors.

Tactics, Techniques, and Procedures (TTPs)

The MITRE ATT&CK framework maps the exploitation of SessionReaper to the following tactics:

  • TA0001 – Initial Access: Exploit a public-facing application
  • TA0002 – Execution: Execute arbitrary code via malicious file uploads
  • TA0003 – Persistence: Maintain access to compromised systems
  • TA0011 – Command and Control: Use web shells for remote control
  • T1190 – Exploit Public-Facing Application: Target exposed endpoints
  • T1505 – Server Software Component: Exploit vulnerable server components
  • T1505.003 – Web Shell: Leverage web shells for command execution

Current Threat Landscape

Despite the availability of a patch, only 38% of online Magento stores have applied protections, leaving 62% vulnerable. The slow adoption rate provides attackers a significant window to exploit this critical flaw.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026