Listen to this Post

Adobe Commerce (formerly Magento) platforms are under siege as hackers actively exploit the critical SessionReaper vulnerability (CVE-2025-54236). Security researchers warn that this flaw represents one of the most severe security risks in Adobe Commerce history, allowing attackers to hijack account sessions without any user interaction. The surge in attacks highlights the urgency for e-commerce businesses to apply security patches immediately, as thousands of online stores remain exposed.
Active Exploitation and Vulnerability Details
The vulnerability, officially disclosed by Adobe on September 8, stems from improper input validation affecting multiple Commerce versions, including 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15, and earlier. Exploiting SessionReaper allows attackers to take control of customer accounts through the Commerce REST API, with session takeover possible even without user interaction.
Sansec, an e-commerce security firm, has been closely monitoring the threat and confirmed real-world exploitation just six weeks after the emergency patch was released. Researchers noted that most successful attacks leverage the default configuration where session data is stored on the file system. A leaked hotfix further raised concerns that attackers could reverse-engineer the vulnerability for exploitation.
In a single day, Sansec blocked over 250 attempts targeting multiple stores, with most attacks traced to five IP addresses: 34.227.25.4, 44.212.43.34, 54.205.171.35, 155.117.84.134, and 159.89.12.166. The attacks often involved PHP webshells or phpinfo probes designed to collect configuration data, exposing sensitive server information.
Research from Searchlight Cyber adds technical depth to the threat, offering a step-by-step analysis of CVE-2025-54236 that could inadvertently fuel more exploitation attempts. Alarmingly, Sansec reports that 62% of Magento stores are yet to install the patch, leaving a significant portion of the e-commerce ecosystem vulnerable. Only a third of websites had applied the fix ten days after its release, and current estimates suggest three in five stores remain exposed. Adobe strongly recommends that administrators apply patches or follow mitigation guidance immediately to prevent compromise.
What Undercode Say: Assessing the Risk and Implications
The SessionReaper vulnerability highlights both systemic and operational weaknesses in e-commerce platforms. From a technical perspective, the flaw exploits session handling through the REST API—a critical component that many stores rely on for customer management and checkout processes. Attackers targeting session files directly can bypass multi-factor authentication and other access controls, which makes the vulnerability particularly dangerous.
Operationally, the slow adoption of patches points to deeper challenges. Many small to mid-sized e-commerce stores lack dedicated security teams or automated patching workflows. This delay transforms an already critical flaw into a systemic risk across the entire Adobe Commerce ecosystem. The fact that the vulnerability was publicized through a hotfix leak adds another layer of complexity, as attackers gain advanced knowledge of potential attack vectors before full mitigation can occur.
The active exploitation trend also raises questions about monitoring and incident response. Organizations that rely solely on generic intrusion detection systems may fail to detect subtle session hijacking attempts. Customized defenses, such as file-system monitoring for unexpected session activity or anomalous REST API behavior, become essential.
Furthermore, the attack patterns observed—PHP webshells and phpinfo probes—suggest that initial compromise may be followed by more extensive campaigns, including data exfiltration or ransomware deployment. Adobe Commerce powers thousands of stores globally, which makes this vulnerability attractive not just to lone hackers but also to organized cybercriminal groups seeking financial gain.
Another critical factor is the user impact. Compromised customer accounts can lead to fraudulent orders, stolen payment information, and reputational damage. E-commerce platforms face the dual challenge of protecting both their infrastructure and their customers’ sensitive data. For many organizations, this vulnerability underscores the importance of proactive vulnerability management, timely patching, and continuous security auditing.
In the long term, SessionReaper demonstrates the need for architectural resilience. Relying on default session storage on the file system exposes critical operations to unnecessary risk. Migrating to more secure session management solutions, implementing encryption, and employing anomaly detection could drastically reduce the likelihood of successful exploitation in the future.
Finally, the incident also serves as a warning to the broader e-commerce community: vulnerabilities of this scale require both immediate technical remediation and strategic policy changes. Companies that delay patching or fail to monitor session activity are not just risking individual breaches—they are contributing to an ecosystem-wide threat landscape that is increasingly exploitable by automated attacks.
🔍 Fact Checker Results
✅ CVE-2025-54236 impacts multiple Adobe Commerce versions, confirmed by Adobe.
✅ Over 250 exploitation attempts were blocked by Sansec in recent monitoring.
❌ Claims that all stores are safe without patching are false; 62% remain vulnerable.
📊 Prediction
🚨 Exploitation attempts are likely to increase as more attackers study leaked patches and technical analyses.
💳 High-risk stores may see a rise in account takeovers, fraudulent transactions, and data theft.
🛡️ Widespread adoption of Adobe’s emergency patch and proactive monitoring will be crucial in containing the threat.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




