Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-facing-service-vulnerabilitywidely-deployed-product-advisory

Critical Adobe Commerce Session Hijack Flaw Added to KEV After Active Exploitation

Updated 1mo agoFirst seen Apr 23, 20265 sources

Adobe released an out-of-band fix for CVE-2025-54236, a critical improper input validation flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows unauthenticated attackers to take over user sessions through vulnerable session-handling and Web API components. The bug, dubbed "SessionReaper" by Sansec, carries a reported CVSS 9.1 rating and can lead to account hijacking, exposure of customer data, fraudulent orders, administrative access, and in some scenarios potentially remote code execution. Affected releases span multiple 2.4.x branches, including versions from 2.4.4 through 2.4.7 and other listed builds and earlier releases.

Security guidance escalated after reports said the flaw was being actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog. Adobe published remediation details in APSB25-88 and shipped patched versions, while defenders were urged to apply the vendor fix immediately, verify patch status, review logs for anomalous session activity, tighten administrative access, and increase WAF, API, and SIEM monitoring. Advisories also warned that leaked hotfix details and unofficial fixes could accelerate attacker weaponization or create additional risk.

Share:
Critical Adobe Commerce Session Hijack Flaw Added to KEV After Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Mar 11, 20263mo ago

CVE-2025-54236 added to CISA KEV amid active exploitation

By March 2026, the vulnerability was reported as actively exploited in the wild and had been added to CISA’s Known Exploited Vulnerabilities catalog. This marked an escalation from earlier reporting that had not yet observed exploitation.

Jan 1, 20266mo ago

Adobe issues out-of-band patch for CVE-2025-54236

Adobe released Security Advisory APSB25-88 and patched affected Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions for the critical auth bypass/session takeover flaw CVE-2025-54236. Early reporting described the issue as severe and urged customers to apply the emergency hotfix immediately.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Affected products
3 linked
Adobe CommerceAdobe Commerce B2bMagento Open Source
Organizations
3 linked
AdobeSentinelOneSansec
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Adobe Commerce Session Hijack Flaw Added to KEV After Active Exploitation | Mallory