Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

Posted on September 10, 2025September 10, 2025 By CWS

Sep 10, 2025Ravie LakshmananVulnerability / Software program Safety
Adobe has warned of a important safety flaw in its Commerce and Magento Open Supply platforms that, if efficiently exploited, may permit attackers to take management of buyer accounts.
The vulnerability, tracked as CVE-2025-54236 (aka SessionReaper), carries a CVSS rating of 9.1 out of a most of 10.0. It has been described as an improper enter validation flaw. Adobe stated it isn’t conscious of any exploits within the wild.
“A possible attacker may take over buyer accounts in Adobe Commerce by means of the Commerce REST API,” Adobe stated in an advisory issued immediately.
The difficulty impacts the next merchandise and variations –

Adobe Commerce (all deployment strategies):

2.4.9-alpha2 and earlier
2.4.8-p2 and earlier
2.4.7-p7 and earlier
2.4.6-p12 and earlier
2.4.5-p14 and earlier
2.4.4-p15 and earlier

Adobe Commerce B2B:

1.5.3-alpha2 and earlier
1.5.2-p2 and earlier
1.4.2-p7 and earlier
1.3.4-p14 and earlier
1.3.3-p15 and earlier

Magento Open Supply:

2.4.9-alpha2 and earlier
2.4.8-p2 and earlier
2.4.7-p7 and earlier
2.4.6-p12 and earlier
2.4.5-p14 and earlier

Customized Attributes Serializable module:

Adobe, along with releasing a hotfix for the vulnerability, stated it has deployed internet utility firewall (WAF) guidelines to guard environments towards exploitation makes an attempt which will goal retailers utilizing Adobe Commerce on Cloud infrastructure.

“SessionReaper is among the extra extreme Magento vulnerabilities in its historical past, akin to Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022), and CosmicSting (2024),” e-commerce safety firm Sansec stated.

The Netherlands-based agency stated it efficiently reproduced one attainable option to exploit CVE-2025-54236, however famous that there are different attainable avenues to weaponize the vulnerability.
“The vulnerability follows a well-recognized sample from final yr’s CosmicSting assault,” it added. “The assault combines a malicious session with a nested deserialization bug in Magento’s REST API.”
“The precise distant code execution vector seems to require file-based session storage. Nevertheless, we suggest retailers utilizing Redis or database periods to take quick motion as nicely, as there are a number of methods to abuse this vulnerability.”
Adobe has additionally shipped fixes to comprise a important path traversal vulnerability in ColdFusion (CVE-2025-54261, CVSS rating: 9.0) that might result in an arbitrary file system write. It impacts ColdFusion 2021 (Replace 21 and earlier), 2023 (Replace 15 and earlier), and 2025 (Replace 3 and earlier) on all platforms.

The Hacker News Tags:Accounts, Adobe, Commerce, Customer, CVE202554236, Flaw, Hackers, Lets

Post navigation

Previous Post: SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws
Next Post: Chrome Security Update Patches Critical Remote Code Execution Vulnerability

Related Posts

Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775 The Hacker News
Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods The Hacker News
EvilAI Malware Masquerades as AI Tools to Infiltrate Global Organizations The Hacker News
How to Stop Python Supply Chain Attacks—and the Expert Tools You Need The Hacker News
Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns The Hacker News
The ROI Problem in Attack Surface Management The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks
  • Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
  • Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network
  • Nike Probing Potential Security Incident as Hackers Threaten to Leak Data
  • Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks
  • Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware
  • Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network
  • Nike Probing Potential Security Incident as Hackers Threaten to Leak Data
  • Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark