Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityidentity-authentication-vulnerabilityrapid-weaponizationinternet-facing-service-vulnerability

Mass Exploitation of Magento SessionReaper (CVE-2025-54236) to Hijack Admin Sessions and Gain Root Access

Updated 3mo agoFirst seen Jan 30, 20262 sources

Threat actors conducted a mass exploitation campaign against Magento e-commerce deployments by abusing CVE-2025-54236 (aka SessionReaper), an authentication/session management flaw that allows attackers to bypass login controls by reusing improperly invalidated session tokens. Reporting based on an Oasis Security investigation described large-scale scanning that identified 1,000+ exposed/vulnerable Magento Commerce APIs and confirmed compromises of 200+ websites (with one count citing 216 victim sites), indicating broad weaponization by multiple actors across regions.

After hijacking valid admin sessions via replayed “zombie” tokens, intruders escalated privileges to achieve root-level control of affected Linux servers, enabling follow-on actions such as deploying web shells for persistent remote command execution and full administrative takeover of storefront infrastructure. Separately, research on eSkimming/Magecart activity highlighted that browser-based JavaScript payment-card theft remains persistent across e-commerce sites—often via third-party script/supply-chain compromise—and a longitudinal study of 550 previously compromised sites found 18% still infected a year later, underscoring that e-commerce compromises frequently involve durable footholds and re-compromise even after initial cleanup.

Share:
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 30, 20265mo ago

Oasis Security disclosed active exploitation and urged immediate patching

By January 30, 2026, Oasis Security publicly reported the ongoing mass exploitation of SessionReaper and warned administrators to patch immediately and audit logs for suspicious session token activity. The disclosure highlighted the risk to customer and payment data from continued attacks.

Researchers linked campaign infrastructure to servers in Finland and Hong Kong

Oasis Security identified active command-and-control infrastructure associated with the exploitation activity, including an IP address in Finland and additional infrastructure in Hong Kong. The findings provided infrastructure indicators connected to the ongoing campaign.

Attackers deployed web shells on Magento sites in Canada and Japan

In separate incidents tied to the campaign, attackers installed web shells on compromised Magento sites in Canada and Japan to maintain persistence and execute remote commands. Investigators also observed attackers searching systems for sensitive files, including user accounts and credentials.

One attack wave compromised more than 200 Magento websites

A documented wave of the campaign resulted in root-level compromise of more than 200 websites worldwide. Attackers used the authentication bypass to take over Magento environments at scale.

SessionReaper flaw left Magento session tokens reusable after logout

The vulnerability CVE-2025-54236, dubbed "SessionReaper," affected Magento session handling by allowing improperly invalidated session tokens to be reused for authentication bypass. Successful exploitation enabled session hijacking, administrative access without passwords, and potential full system compromise.

Jan 1, 20266mo ago

Mass exploitation campaign targeted Magento sites worldwide in January 2026

During January 2026, multiple intrusion sets actively exploited CVE-2025-54236 against Magento e-commerce sites across several regions. Oasis Security reported hundreds of compromised stores and identified 1,460 vulnerable Magento Commerce APIs exposed to attack.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
2 linked
Oasis SecurityAdobe
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.