Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Active Exploits Target Magento and Adobe Commerce RCE, Attackers Inject Webshells

Unauthenticated attackers are actively exploiting a critical vulnerability affecting Adobe Commerce and Magento platforms worldwide. The flaw, tracked as CVE-2025-54236 and known as SessionReaper , allows remote code execution and customer account…

Unauthenticated attackers are actively exploiting a critical vulnerability affecting Adobe Commerce and Magento platforms worldwide. The flaw, tracked as CVE-2025-54236 and known as SessionReaper , allows remote code execution and customer account takeover on numerous online stores.

CVE ID Vulnerability Name Affected Products Type CVSS 3.1

CVE-2025-54236 SessionReaper Adobe Commerce & Magento (all versions) Unauthenticated RCE, Account Takeover 9.1 Critical

Security researchers at Sansec detected the first mass attacks on October 22, 2025, nearly two months after Adobe released an emergency patch. At the time of discovery, less than 40 percent of affected stores had deployed protective fixes.

SessionReaper combines a malicious session with a nested deserialization bug in Magento’s REST API to grant attackers complete control over vulnerable storefronts. Exploits arrive via the /customer/address_file/upload endpoint, where attackers upload PHP backdoors disguised as fake session files.

Unauthenticated attackers are actively exploiting a critical vulnerability affecting Adobe Commerce and Magento platforms worldwide.
Aiden Sinclair · Thehackingpost

This method bypasses authentication requirements entirely, allowing any internet-connected attacker to compromise unpatched systems without valid credentials. Magento administrators using file-based session storage face the highest risk, although organizations relying on Redis or database-backed sessions should not assume they are safe.

Adobe released the SessionReaper patch on September 9 as an out-of-band emergency update, breaking its normal release schedule. However, adoption remained low, with fewer than one in three Magento stores installing the fix by mid-September.

This lag created a critical window for attackers to develop and deploy exploits. The situation worsened when Adobe accidentally leaked the patch code on GitHub, potentially accelerating attacker preparations.

Adobe's official vulnerability advisory initially downplayed the threat, describing the impact only as account takeover and omitting any mention of remote code execution, a detail security researchers later confirmed.

Advertisement

SessionReaper ranks among the most severe Magento vulnerabilities ever discovered. Organizations running unpatched Magento or Adobe Commerce instances face imminent compromise.

Immediate actions include deploying the official patch from Adobe’s repository and testing thoroughly, as the fix disables internal Magento functionality that may impact custom extensions. Administrators unable to patch within 24 hours should activate a Web Application Firewall (WAF) for temporary protection; only Adobe Fastly and Sansec Shield currently block this specific attack.

For stores already patched, security researchers recommend running malware scanners to detect compromises and rotating cryptographic keys to prevent attackers from modifying CMS blocks indefinitely. With 62 percent of stores remaining unpatched, the threat landscape continues to evolve as more organizations fall victim to automated exploitation campaigns.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories