By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Adobe patches critical SessionReaper flaw in Magento eCommerce platform
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Adobe patches critical SessionReaper flaw in Magento eCommerce platform
Tech News

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

By admin 3 Min Read
Share
SHARE

Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of ” the most severe” flaws in the history of the product.

Today, the software company released a patch for the security issue that could be exploited without authentication to take control of customer accounts through the Commerce REST API.

According to e-commerce security company Sansec, Adobe notified “selected Commerce customers” on September 4th of an upcoming emergency fix planned for September 9.

“Adobe is planning to release a security update for Adobe Commerce and Magento Open Source on Tuesday, September 9, 2025,” reads the notice.

“This update resolves a critical vulnerability. Successful exploitation could lead to security feature bypass.”

Customers using Adobe Commerce on Cloud are already protected by a web application firewall (WAF) rule deployed by Adobe as an intermediate measure.

Adobe's notice to Magento customers
<strong>Adobe&#8217;s notice to Magento customers</strong><br /><em>Source: Sansec</em>

Adobe says in the security bulletin that it is not aware of any exploitation activity in the wild. Sansec’s advisory also notes that the researchers have not seen any active exploitation of SessionReaper.

However, Sansec says that an initial hotfix for CVE-2025-54236 was leaked last week, which may give threat actors a potential head start on creating an exploit.

According to the researchers, successful exploitation “appears” to depend on storing session data on the file system, a default configuration that most stores use.

Administrators are strongly recommended to test and deploy the available patch (direct download, ZIP archive) immediately. The researchers warn that the fix disables internal Magento functionality that could lead to some custom or external code breaking.

To this end, Adobe updated its documentation for changes in the Adobe Commerce REST API constructor parameter injection.

“Please apply the hotfix as soon as possible. If you fail to do so, you will be vulnerable to this security issue, and Adobe will have limited means to help remediate” – Adobe

Sansec researchers expect CVE-2025-54236 to be abused via automation, at scale. They note that the vulnerability is among the most severe Magento vulnerabilities in the history of the platform, alongside CosmicSting, TrojanOrder, Ambionics SQLi, and Shoplift.

Similar issues in the past were leveraged for session forging, privilege escalation, internal service access, and code execution.

The security firm was able to reproduce the SessionReaper exploit but did not disclose the code or technical details, saying only that “the vulnerability follows a familiar pattern from last year’s CosmicSting attack.”

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

You Might Also Like

Best Duffel Bags: Eastpak, Patagonia, Baboon to the Moon (2026)

Google Pixel 11 With Pixel Glow Previewed at I/O

SpaceX files publicly for what could be largest IPO in history

Google I/O 2026 Recap: Gemini 3.5, AI Agents, and Smart Glasses

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

TAGGED: adobe, Magento, Patch, Patch Gap, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Gyokeres shoots, Nwaneri scores, Martinelli talks
Next Article Polestar 5: The 884-HP Grand Tourer is Finally Here
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Best Duffel Bags: Eastpak, Patagonia, Baboon to the Moon (2026)
Tech News
Italy requests EU sanctions on Israeli minister over treatment of activists, Tajani says
World News
Oleksandr Usyk snubs Tyson Fury and Anthony Joshua in naming hardest puncher
Sports
Hoskinson Warns Cardano Could Lose Its ‘Science Coin’ Edge
Crypto
Vanessa Trump Health: Updates on Her Breast Cancer Diagnosis
Celebrity
Subnautica 2 Team Apologizes for Earlier Statements, Working on Creature Balance and Mitigation Tools
Gaming News
SpaceX’s financials are out ahead of its IPO. What this means for Scottish Mortgage shares
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Best Duffel Bags: Eastpak, Patagonia, Baboon to the Moon (2026)

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Best Duffel Bags: Eastpak, Patagonia, Baboon to the Moon (2026)
May 21, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?