Story perspectives
Critical Adobe Security Flaw Exposes Magento Users to Attacks
9/11/2025
40 5
1 of 1
Story summary
- Adobe revealed a severe security flaw, CVE-2025-54236, known as SessionReaper, impacting Adobe Commerce and Magento platforms.
- Rated 9.1 on the CVSS scale, it enables attackers to hijack accounts and execute remote code.
- Sansec researchers consider it one of the most serious Magento vulnerabilities, akin to the 2015 Shoplift incident.
- An emergency patch was released on September 9 but was leaked, potentially aiding cybercriminals.
- Merchants must apply the patch immediately or use a Web Application Firewall (WAF) within 24 hours to mitigate risks.
