Listen to this Post

Introduction
A storm is brewing in the world of e-commerce security. Over the past 24 hours, cybercriminals have launched more than 250 attack attempts targeting online stores powered by Adobe Commerce and Magento Open Source. The attacks exploit a dangerous vulnerability—recently patched but still largely unaddressed by many businesses—that allows hackers to hijack customer accounts and implant malicious backdoors. As the digital marketplace continues to grow, this new wave of attacks raises urgent questions about the fragility of online retail ecosystems and the slow response to critical security patches.
The Rise of SessionReaper and the Race Against Time
Cybersecurity firm Sansec has issued an alarming warning: a newly disclosed vulnerability in Adobe Commerce and Magento Open Source—tracked as CVE-2025-54236—is now being actively exploited. This flaw, rated 9.1 on the CVSS severity scale, stems from improper input validation that allows attackers to seize control of customer accounts via the Commerce REST API.
Nicknamed SessionReaper, the vulnerability was discovered and responsibly disclosed by a researcher known as Blaklis. Adobe addressed the issue last month, but the patch rollout remains worryingly incomplete. Sansec’s latest data shows that over 62% of Magento-based stores are still unpatched six weeks after the public disclosure—leaving them open to compromise.
The scale of exploitation is rapidly expanding. In the past day alone, over 250 attack attempts were recorded from multiple global IP addresses. These attacks were traced back to servers hosted at:
34.227.25[.]4
44.212.43[.]34
54.205.171[.]35
155.117.84[.]134
159.89.12[.]166
Threat actors have used these IPs to upload PHP webshells—malicious backdoors that grant full remote control over compromised servers—through the file upload endpoint /customer/address_file/upload. The hackers disguise their uploads as legitimate session files, allowing them to evade detection and quietly infiltrate store infrastructure.
Once the attackers gain access, they often probe the system using phpinfo() to gather details about the environment—an early reconnaissance step that helps them adapt their payloads to specific configurations.
According to Searchlight Cyber, which recently published a technical deep dive into CVE-2025-54236, the flaw arises from a nested deserialization issue that enables remote code execution (RCE). In simpler terms, it allows malicious actors to inject and execute arbitrary code on affected servers—effectively giving them the keys to the kingdom.
This marks the second major deserialization exploit to hit Adobe Commerce and Magento within a year. In July 2024, the now-infamous CosmicSting vulnerability (CVE-2024-34102, CVSS 9.8) swept through the e-commerce world, resulting in mass exploitation campaigns and data breaches across thousands of online stores.
With proof-of-concept exploits for SessionReaper now circulating in public domains and on dark web forums, experts fear a repeat of last year’s chaos unless swift action is taken. Sansec urges all administrators to immediately apply the official patches released by Adobe to close this dangerous loophole before attackers scale up their operations.
What Undercode Say:
The SessionReaper incident is more than just another technical vulnerability—it’s a wake-up call for the e-commerce industry’s complacency toward patch management and digital hygiene.
For years, online merchants have relied heavily on Magento and Adobe Commerce to power their stores, often without realizing how dependent they are on the platform’s underlying security. The issue isn’t just the existence of a bug—it’s the lag in response time. Six weeks after the fix, over 60% of merchants remain exposed. That statistic alone paints a grim picture of operational inertia in the digital retail world.
When critical patches are released, many store owners hesitate to implement them due to fear of downtime, compatibility issues, or loss of functionality. But this delay gives hackers a golden window of opportunity—a predictable gap that sophisticated threat actors exploit ruthlessly.
The fact that SessionReaper leverages deserialization to achieve remote code execution also signals an unsettling trend: attackers are moving deeper into application logic vulnerabilities rather than just brute-forcing credentials or exploiting misconfigurations. This shows growing technical maturity among cybercriminals targeting commerce systems.
Moreover, the reuse of old techniques—like uploading PHP webshells under the guise of session files—highlights that attackers don’t always need new tricks. They just need known doors left unlocked. Once a store is compromised, the attacker can silently implant persistent scripts, skim credit card data, or even redirect transactions without triggering alerts.
This vulnerability, like CosmicSting before it, also exposes a broader issue with the open-source nature of e-commerce frameworks. While openness drives innovation and flexibility, it also creates an uneven playing field where not all store owners have the technical capacity to stay secure. Without proper patch management, the open-source advantage quickly turns into a liability.
What’s more concerning is that these attacks often target small to medium-sized businesses—the very backbone of online commerce. Large enterprises typically patch faster due to dedicated IT teams, while smaller shops often run outdated versions for months. Attackers know this and tailor their campaigns accordingly.
The ripple effects could be devastating: compromised stores lead to customer trust erosion, brand damage, and financial losses. And since many Magento stores handle sensitive payment data, a single breach can have cascading consequences across thousands of customers.
To prevent a large-scale disaster, companies need to rethink their security posture:
Implement automated patching systems to reduce human delays.
Use Web Application Firewalls (WAFs) that can block malicious payloads targeting known endpoints.
Regularly audit system configurations and monitor logs for suspicious upload activities.
In essence, this is a battle not just against hackers—but against neglect. SessionReaper is proof that in cybersecurity, procrastination is a vulnerability of its own.
Fact Checker Results:
✅ CVE-2025-54236 has been confirmed and patched by Adobe in official advisories.
✅ Sansec verified over 250 attack attempts in the past 24 hours targeting unpatched stores.
❌ Over 60% of Magento stores remain vulnerable, despite the patch being available for weeks.
Prediction:
🔮 Expect a surge of automated bot attacks exploiting CVE-2025-54236 within the next month as PoC exploits spread. E-commerce platforms that delay patching will likely face mass credential takeovers and data exfiltration attempts. Security researchers anticipate that this exploit could become the most widespread Magento breach vector since CosmicSting (2024), unless rapid mitigation occurs.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




