Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk

Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk

Posted on October 23, 2025October 23, 2025 By CWS

Hackers have began exploiting a critical-severity vulnerability in Adobe Commerce and Magento Open Supply, cybersecurity agency Sansec studies.

Tracked as CVE-2025-54236 (CVSS rating of 9.1), the flaw is described as an improper enter validation subject resulting in safety function bypass.

On September 9, Adobe launched hotfixes for the safety defect, urging customers of Commerce and Magento Open Supply variations between 2.4.4 and a couple of.4.7 to replace their deployments.

Sansec warned on the time that menace actors have been probably engaged on weaponizing the bug, known as SessionReaper, after Adobe’s patch leaked one week earlier than the hotfix was launched.

Now, Sansec says lively exploitation of CVE-2025-54236 has began, with roughly 250 assaults noticed on Wednesday. The recognized payloads contained PHP webshells and phpinfo probes.

The exploitation exercise is anticipated to surge quick, as lower than half of the ecommerce websites have been patched towards the vulnerability.

Moreover, on Wednesday, Searchlight Cyber printed technical info on SessionReaper and its exploitation, that are anticipated to gas the bug’s in-the-wild concentrating on.

“With exploit particulars now public and lively assaults already noticed, we anticipate mass exploitation inside the subsequent 48 hours. Automated scanning and exploitation instruments sometimes emerge shortly after technical writeups are printed, and SessionReaper’s excessive affect makes it a sexy goal for attackers,” Sansec notes.Commercial. Scroll to proceed studying.

The cybersecurity agency factors out that solely 38% of shops have utilized Adobe’s hotfix, which means that 62% of the Magento shops are in danger.

One of many fundamental points with the safety defect, Adobe warned roughly a month in the past, is the truth that it may result in buyer account takeover by the Commerce REST API.

On Wednesday, Adobe up to date its advisory to verify the safety defect’s in-the-wild exploitation. “Adobe is conscious of CVE-2025-54236 being exploited within the wild,” the replace reads.

Associated: Organizations Warned of Exploited Adobe AEM Varieties Vulnerability

Associated: Lanscope Endpoint Supervisor Zero-Day Exploited within the Wild

Associated: TARmageddon Flaw in Widespread Rust Library Results in RCE

Associated: Authorities, Industrial Servers Focused in China-Linked ‘PassiveNeuron’ Marketing campaign

Security Week News Tags:Adobe, Commerce, Critical, ECommerce, Exploitation, Flaw, Puts, Risk, Sites

Post navigation

Previous Post: Why Organizations Are Abandoning Static Secrets for Managed Identities
Next Post: Vibe Coding’s Real Problem Isn’t Bugs—It’s Judgment

Related Posts

Several Code Execution Flaws Patched in Veeam Backup & Replication Several Code Execution Flaws Patched in Veeam Backup & Replication Security Week News
‘ZombieAgent’ Attack Let Researchers Take Over ChatGPT ‘ZombieAgent’ Attack Let Researchers Take Over ChatGPT Security Week News
1.1 Million Unique Records Identified in Allianz Life Data Leak 1.1 Million Unique Records Identified in Allianz Life Data Leak Security Week News
Crunchbase Confirms Data Breach After Hacking Claims Crunchbase Confirms Data Breach After Hacking Claims Security Week News
Vulnerabilities Exposed Phone Number of Any Google User Vulnerabilities Exposed Phone Number of Any Google User Security Week News
HPE Patches Critical Flaw in IT Infrastructure Management Software HPE Patches Critical Flaw in IT Infrastructure Management Software Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News