CWE-CWE-20

Adobe Commerce/Magento "SessionReaper" RCE (CVE-2025-54236)

Severity:
Critical
Summary
Adobe Commerce and Magento Open Source contain a critical deserialization vulnerability (CVE-2025-54236) that allows unauthenticated attackers to bypass authentication mechanisms by sending maliciously crafted requests. When chained with the platform's file upload capabilities, this vulnerability enables attackers to achieve remote code execution on affected systems without requiring valid credentials.
Impact
An unauthenticated remote attacker can exploit this vulnerability to completely compromise affected Adobe Commerce and Magento systems. Successful exploitation allows attackers to bypass authentication controls, upload malicious files, execute arbitrary code with web server privileges, and potentially gain full control of the application and underlying server. This can lead to data theft, unauthorized access to customer information, manipulation of e-commerce transactions, installation of backdoors, and complete system takeover.
Remediation
Apply security patches immediately by upgrading to the latest patched versions as specified in Adobe Security Bulletin APSB25-88. For Adobe Commerce: upgrade to version 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, or 2.4.4-p11 and later. For Magento Open Source: upgrade to version 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, or 2.4.4-p11 and later. If immediate patching is not possible, implement the following temporary mitigations: (1) restrict access to administrative interfaces using IP allowlisting, (2) implement web application firewall (WAF) rules to detect and block deserialization attack patterns, and (3) monitor system logs for suspicious authentication bypass attempts and unexpected file uploads. Verify the integrity of your installation after patching and review access logs for any signs of prior exploitation.
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding