Drooid Logo
Back to today’s briefing

Story perspectives

Critical Adobe Security Flaw Exposes Magento Users to Attacks

9/11/2025

40 5

1 of 1

Story summary
  • Adobe revealed a severe security flaw, CVE-2025-54236, known as SessionReaper, impacting Adobe Commerce and Magento platforms.
  • Rated 9.1 on the CVSS scale, it enables attackers to hijack accounts and execute remote code.
  • Sansec researchers consider it one of the most serious Magento vulnerabilities, akin to the 2015 Shoplift incident.
  • An emergency patch was released on September 9 but was leaked, potentially aiding cybercriminals.
  • Merchants must apply the patch immediately or use a Web Application Firewall (WAF) within 24 hours to mitigate risks.