ºÚÁÏÉç

Security Bulletin text on the screen with a wolf in the background
Security Bulletin text on the screen with a wolf in the background

CVE?2025?54236: Critical Adobe Commerce and Magento Open Source Flaw Allows Customer Account Takeover and RCE

On 9 September 2025, Adobe released an out-of-band security update to address a critical vulnerability in Adobe Commerce and Magento Open Source. The vulnerability is tracked as CVE-2025-54236.
Security Bulletin text on the screen with a wolf in the background
6 min read

On 9 September 2025, Adobe an out-of-band security update to address a critical vulnerability in Adobe Commerce and Magento Open Source. The vulnerability, tracked as CVE-2025-54236 and referred to in open-source reporting as ¡°SessionReaper,¡± allows a remote unauthenticated threat actor to take over customer accounts through the Commerce REST API. The security researcher who discovered the vulnerability has that this flaw could also potentially lead to Remote Code Execution (RCE) under certain conditions.?

Arctic Wolf has not observed exploitation of CVE?2025?54236 or any public proof-of-concept exploit. has reproduced an exploit avenue, and multiple attack vectors may exist. Based on historical targeting of these platforms (as noted in CISA¡¯s Known Exploited Vulnerabilities catalog) and the potential for RCE, this vulnerability could be targeted by threat actors in the near future.?

Recommendation for CVE?2025?54236

Apply Hotfix

Arctic Wolf strongly recommends that customers upgrade to the latest hotfix for CVE-2025-54236.?

Product? Affected Version? Fixed Version?
Adobe Commerce?
  • 2.4.9-alpha2 and earlier?
  • 2.4.8-p2 and earlier?
  • 2.4.7-p7 and earlier?
  • 2.4.6-p12 and earlier?
  • 2.4.5-p14 and earlier?
  • 2.4.4-p15 and earlier?
for CVE-2025-54236 (Compatible with all Adobe Commerce and Magento Open Source versions between 2.4.4 – 2.4.7)?
Adobe Commerce B2B?
  • 1.5.3-alpha2 and earlier?
  • 1.5.2-p2 and earlier?
  • 1.4.2-p7 and earlier?
  • 1.3.4-p14 and earlier?
  • 1.3.3-p15 and earlier?
Magento Open Source?
  • 2.4.9-alpha2 and earlier?
  • 2.4.8-p2 and earlier?
  • 2.4.7-p7 and earlier?
  • 2.4.6-p12 and earlier?
  • 2.4.5-p14 and earlier?

 

Note: For organisations using Adobe Commerce on Cloud infrastructure, Adobe has stated they have deployed web application firewall (WAF) rules to protect environments against exploitation of CVE-2025-54236.?

Please follow your organisation’s patching and testing guidelines to minimise potential operational impact.?

References?

Share this post: