By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Adobe patches critical SessionReaper flaw in Magento eCommerce platform
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Adobe patches critical SessionReaper flaw in Magento eCommerce platform
Tech News

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

By admin 3 Min Read
Share
SHARE

Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of ” the most severe” flaws in the history of the product.

Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API.

According to e-commerce security company Sansec, Adobe notified “selected Commerce customers” on September 4th of an upcoming emergency fix planned for September 9.

“Adobe is planning to release a security update for Adobe Commerce and Magento Open Source on Tuesday, September 9, 2025,” reads the notice.

“This update resolves a critical vulnerability. Successful exploitation could lead to security feature bypass.”

Customers using Adobe Commerce on Cloud are already protected by a web application firewall (WAF) rule deployed by Adobe as an intermediate measure.

Adobe's notice to Magento customers
<strong>Adobe&#8217;s notice to Magento customers</strong><br /><em>Source: Sansec</em>

Adobe says in the security bulletin that it is not aware of any exploitation activity in the wild. Sansec’s advisory also notes that the researchers have not seen any active exploitation of SessionReaper.

However, Sansec says that an initial hotfix for CVE-2025-54236 was leaked last week, which may give threat actors a potential head start on creating an exploit.

According to the researchers, successful exploitation “appears” to depend on storing session data on the file system, a default configuration that most stores use.

Administrators are strongly recommended to test and deploy the available patch (direct download, ZIP archive) immediately. The researchers warn that the fix disables internal Magento functionality that could lead to some custom or external code breaking.

To this end, Adobe updated its documentation for changes in the Adobe Commerce REST API constructor parameter injection.

“Please apply the hotfix as soon as possible. If you fail to do so, you will be vulnerable to this security issue, and Adobe will have limited means to help remediate” – Adobe

Sansec researchers expect CVE-2025-54236 to be abused via automation, at scale. They note that the vulnerability is among the most severe Magento vulnerabilities in the history of the platform, alongside CosmicSting, TrojanOrder, Ambionics SQLi, and Shoplift.

Similar issues in the past were leveraged for session forging, privilege escalation, internal service access, and code execution.

The security firm was able to reproduce the SessionReaper exploit but did not disclose the code or technical details, saying only that “the vulnerability follows a familiar pattern from last year’s CosmicSting attack.”

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

You Might Also Like

Five SETU scientists listed among world’s top 2pc on Stanford list

7 Key Workflows for Maximum Impact

At a Conspiracy Conference in Rural Ireland, Charlie Kirk Was the Star

Samsung Project Moohan gets Rumoured Release Date

How Nothing OS Uses AI to Personalize Your Digital World

TAGGED: adobe, Magento, Patch, Patch Gap, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Gyokeres shoots, Nwaneri scores, Martinelli talks
Next Article Polestar 5: The 884-HP Grand Tourer is Finally Here
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Five SETU scientists listed among world’s top 2pc on Stanford list
Tech News
Here’s why the US shutdown may prove more painful than past crises
Business
Black Ops 7 returns to Call of Duty's three-lane map design, and that's a good thing
Gaming News
7 Key Workflows for Maximum Impact
Tech News
Tesla vehicle sales made a comeback last quarter. Will a lost EV tax credit end the rebound?
Business
Thailand To Expand Crypto ETF Lineup Beyond Bitcoin In Early 2026 – Report
Crypto
At a Conspiracy Conference in Rural Ireland, Charlie Kirk Was the Star
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Five SETU scientists listed among world’s top 2pc on Stanford list

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Five SETU scientists listed among world’s top 2pc on Stanford list
October 3, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?