Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

Posted on September 10, 2025September 10, 2025 By CWS

Sep 10, 2025Ravie LakshmananVulnerability / Software program Safety
Adobe has warned of a important safety flaw in its Commerce and Magento Open Supply platforms that, if efficiently exploited, may permit attackers to take management of buyer accounts.
The vulnerability, tracked as CVE-2025-54236 (aka SessionReaper), carries a CVSS rating of 9.1 out of a most of 10.0. It has been described as an improper enter validation flaw. Adobe stated it isn’t conscious of any exploits within the wild.
“A possible attacker may take over buyer accounts in Adobe Commerce by means of the Commerce REST API,” Adobe stated in an advisory issued immediately.
The difficulty impacts the next merchandise and variations –

Adobe Commerce (all deployment strategies):

2.4.9-alpha2 and earlier
2.4.8-p2 and earlier
2.4.7-p7 and earlier
2.4.6-p12 and earlier
2.4.5-p14 and earlier
2.4.4-p15 and earlier

Adobe Commerce B2B:

1.5.3-alpha2 and earlier
1.5.2-p2 and earlier
1.4.2-p7 and earlier
1.3.4-p14 and earlier
1.3.3-p15 and earlier

Magento Open Supply:

2.4.9-alpha2 and earlier
2.4.8-p2 and earlier
2.4.7-p7 and earlier
2.4.6-p12 and earlier
2.4.5-p14 and earlier

Customized Attributes Serializable module:

Adobe, along with releasing a hotfix for the vulnerability, stated it has deployed internet utility firewall (WAF) guidelines to guard environments towards exploitation makes an attempt which will goal retailers utilizing Adobe Commerce on Cloud infrastructure.

“SessionReaper is among the extra extreme Magento vulnerabilities in its historical past, akin to Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022), and CosmicSting (2024),” e-commerce safety firm Sansec stated.

The Netherlands-based agency stated it efficiently reproduced one attainable option to exploit CVE-2025-54236, however famous that there are different attainable avenues to weaponize the vulnerability.
“The vulnerability follows a well-recognized sample from final yr’s CosmicSting assault,” it added. “The assault combines a malicious session with a nested deserialization bug in Magento’s REST API.”
“The precise distant code execution vector seems to require file-based session storage. Nevertheless, we suggest retailers utilizing Redis or database periods to take quick motion as nicely, as there are a number of methods to abuse this vulnerability.”
Adobe has additionally shipped fixes to comprise a important path traversal vulnerability in ColdFusion (CVE-2025-54261, CVSS rating: 9.0) that might result in an arbitrary file system write. It impacts ColdFusion 2021 (Replace 21 and earlier), 2023 (Replace 15 and earlier), and 2025 (Replace 3 and earlier) on all platforms.

The Hacker News Tags:Accounts, Adobe, Commerce, Customer, CVE202554236, Flaw, Hackers, Lets

Post navigation

Previous Post: SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws
Next Post: Chrome Security Update Patches Critical Remote Code Execution Vulnerability

Related Posts

WhatsApp Issues Emergency Update for Zero-Click Exploit Targeting iOS and macOS Devices The Hacker News
CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign The Hacker News
Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages The Hacker News
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown The Hacker News
New ‘Curly COMrades’ APT Using NGEN COM Hijacking in Georgia, Moldova Attacks The Hacker News
Open Source Web Application Firewall with Zero-Day Detection and Bot Protection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments
  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control
  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials
  • Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments
  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control
  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials
  • Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News