Junglewise Threat Intelligence

CVE-2025-54236: Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Vali

CVE-2025-54236 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2025-09-09

Technologies: Adobe Commerce, Adobe Magento Open Source, Adobe Magento. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a critical security flaw. An attacker can exploit this vulnerability to take over customer accounts without needing any user interaction or login credentials. This could lead to the theft of sensitive customer data and unauthorized access to shopping accounts, potentially damaging business reputation and customer trust.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe Commerce and Magento Open Source within the Commerce REST API. The flaw allows a remote, unauthenticated attacker to bypass security checks and achieve session takeover. Exploitation does not require user interaction and has a high impact on confidentiality and integrity. This vulnerability is confirmed to be exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available in updated versions including 2.4.8-p2, 2.4.7-p7, and other listed maintenance releases.

Affected products

  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
  • Adobe Magento Open Source 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier

Timeline

  • 2025-10-24: advisory: Adobe published security advisory APSB25-88
  • 2025-10-24: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
  • 2025-10-24: exploited: Vulnerability reported as being exploited in the wild

Related threats