Adobe has warned of a critical flaw in its Commerce and Magento Open Source, which, if successfully exploited, could allow attackers to take control of customer accounts.
See also: Adobe brings Premiere video editing to iPhone

The vulnerability, tracked as CVE-2025-54236 (also known as SessionReaper), has a CVSS score of 9.1 out of a maximum of 10.0. It is described as an improper input validation error. Adobe said it is not aware of any exploits in the wild.
“A potential attacker could compromise customer accounts in Adobe Commerce via the Commerce REST API,” Adobe said in an advisory issued today.
The issue affects the following products and versions:
– 2.4.9-alpha2 and earlier
– 2.4.8-p2 and earlier
– 2.4.7-p7 and earlier
– 2.4.6-p12 and earlier
– 2.4.5-p14 and earlier
– 2.4.4-p15 and earlier
– 1.5.3-alpha2 and earlier
– 1.5.2-p2 and earlier
– 1.4.2-p7 and earlier
– 1.3.4-p14 and earlier
– 1.3.3-p15 and earlier
– Versions 0.1.0 to 0.4.0
See also: Adobe: Releases Firefly apps for iOS and Android

Adobe, in addition to releasing a hotfix for the vulnerability, said it has deployed rules for its web application firewall (WAF) to protect environments from exploit attempts that may target merchants using Adobe Commerce on Cloud.
“SessionReaper is one of the most serious Magento vulnerabilities in its history, comparable to Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022) and CosmicSting (2024),” e-commerce security firm Sansec.
The company based in the Netherlands reported that it successfully reproduced a possible exploitation method for CVE-2025-54236, but noted that there are also other possible ways to exploit the vulnerability.
“The vulnerability follows a familiar pattern from last year’s CosmicSting attack,” he added. “The attack combines a malicious session with a built-in unsubscription bug in Magento’s REST API.”
“The specific method of remote code execution appears to require file‑based session storage. However, we recommend that merchants using Redis or database sessions take immediate action, as there are many ways to exploit this vulnerability.“
See also: Adobe: Brings Photoshop (beta) to Android users

Adobe has also released fixes to mitigate a critical path vulnerability in ColdFusion (CVE-2025-54261, CVSS score: 9.0) that could lead to arbitrary file system writes. It affects ColdFusion 2021 (Update 21 and earlier), 2023 (Update 15 and earlier), and 2025 (Update 3 and earlier) across all platforms.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
