SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has rep...

Oct 23, 2025By Padmashree P3 min read

A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has reported blocking over 250 exploitation attempts, underscoring the urgency for administrators to apply patches or mitigations immediately.

Vulnerability Details

SessionReaper (CVE-2025-54236) is a critical improper input validation vulnerability in the Commerce REST API.

  • Exploitation Method:Attackers can upload malicious files disguised as session data via the /customer/address_file/upload endpoint, bypassing authentication controls.
  • Resulting Risk:This creates a nested deserialization vulnerability, which can lead to full remote code execution, particularly on systems using file-based session storage.

A technical analysis with proof-of-concept code was published by Assetnote researchers on October 21, 2025, further increasing the urgency for patching.

Affected Products

Adobe Commerce & Magento Open Source versions:

  • 2.4.9-alpha2 and earlier
  • 2.4.8-p2 and earlier
  • 2.4.7-p7 and earlier
  • 2.4.6-p12 and earlier
  • 2.4.5-p14 and earlier
  • 2.4.4-p15 and earlier

Adobe Commerce B2B versions:

  • 1.5.3-alpha2 and earlier
  • 1.5.2-p2 and earlier
  • 1.4.2-p7 and earlier
  • 1.3.4-p14 and earlier
  • 1.3.3-p15 and earlier

Impact & Exploit Potential

Successful exploitation of SessionReaper can result in severe consequences:

  • Customer account takeover
  • Remote code execution
  • Data breaches
  • Full store compromise

Security researchers at Sansec have compared SessionReaper to prior high-severity Magento vulnerabilities, such as CosmicSting, TrojanOrder, and Shoplift, all of which caused widespread breaches .

Observed Exploit Behavior:Attackers have uploaded PHP web shells and executed phpinfo() probes to extract server configuration details.

Mitigation & Recommendations

Administrators should implement the following immediate mitigations:

  1. Apply the Official Patch: Upgrade to the latest secure release or deploy Adobe’s official patch.
  2. Web Application Firewall (WAF): Enable WAF protection for temporary mitigation. Sansec Shield and Adobe Fastly can block this specific attack.
  3. Scan for Compromises: Use malware scanners to detect potential compromises.
  4. Rotate Cryptographic Keys: Rotate CMS cryptographic keys to prevent attackers from persistently modifying content.

Indicators of Compromise (IOCs)

Sansec has identified active exploit IP addresses:

  • 34.227.25[.]4
  • 44.212.43[.]34
  • 54.205.171[.]35
  • 155.117.84[.]134
  • 159.89.12[.]166

These IPs have been observed delivering payloads, probing server configurations, or installing backdoors.

Tactics, Techniques, and Procedures (TTPs)

The MITRE ATT&CK framework maps the exploitation of SessionReaper to the following tactics:

  • TA0001 – Initial Access: Exploit a public-facing application
  • TA0002 – Execution: Execute arbitrary code via malicious file uploads
  • TA0003 – Persistence: Maintain access to compromised systems
  • TA0011 – Command and Control: Use web shells for remote control
  • T1190 – Exploit Public-Facing Application: Target exposed endpoints
  • T1505 – Server Software Component: Exploit vulnerable server components
  • T1505.003 – Web Shell: Leverage web shells for command execution

Current Threat Landscape

Despite the availability of a patch, only 38% of online Magento stores have applied protections, leaving 62% vulnerable. The slow adoption rate provides attackers a significant window to exploit this critical flaw.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026