Adobe Commerce and Magento Improper Input Validation Vulnerability

cve CVE-2025-54236 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Adobe Commerce and Magento Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236 the claim

What each source says

PropertySourceSaidMeans here
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-20
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-20
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-11-14
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-11-14
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Platform
platform
Metasploit exploit modulesLinux,PHP,Unix,Windows
receipt
Source
Metasploit exploit modules
Its words
Linux,PHP,Unix,Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php, cmd",
  "author": [
    "Blaklis",
    "Tomais Williamson",
    "Valentin Lobstein <chocapikk@leakix.net>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits CVE-2025-54236 (SessionReaper), a critical vulnerability in\n          Magento/Adobe Commerce that allows unauthenticated remote code execution.\n\n          The vulnerability stems from improper handling of nested deserialization in the\n          payment method context, combined with an unauthenticated file upload endpoint.\n\n          The exploit chain consists of three steps:\n          1. Upload a malicious PHP session file containing a Guzzle/FW1 deserialization\n          payload via the unauthenticated /customer/address_file/upload endpoint\n          2. Trigger deserialization by sending a crafted JSON payload to the REST API\n          endpoint /rest/default/V1/guest-carts/{cart_id}/order that modifies the\n          session savePath to point to the uploaded file\n          3. Execute the uploaded PHP code to gain remote code execution\n\n          This vulnerability affects Magento 2.x instances configured to use file-based\n          session storage. Patched versions will return a 400 Bad Request response instead\n          of processing the malicious payload.",
  "disclosure_date": "2025-10-22",
  "fullname": "exploit/multi/http/magento_sessionreaper",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Magento SessionReaper",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/magento_sessionreaper.rb",
  "platform": "Linux,PHP,Unix,Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/magento_sessionreaper",
  "references": [
    "CVE-2025-54236",
    "URL-https://slcyber.io/research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/",
    "URL-https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP In-Memory",
    "Unix/Linux Command Shell",
    "Windows Command Shell"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesCommerce and Magento
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Commerce and Magento
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "php, cmd",
  "author": [
    "Blaklis",
    "Tomais Williamson",
    "Valentin Lobstein <chocapikk@leakix.net>"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits CVE-2025-54236 (SessionReaper), a critical vulnerability in\n          Magento/Adobe Commerce that allows unauthenticated remote code execution.\n\n          The vulnerability stems from improper handling of nested deserialization in the\n          payment method context, combined with an unauthenticated file upload endpoint.\n\n          The exploit chain consists of three steps:\n          1. Upload a malicious PHP session file containing a Guzzle/FW1 deserialization\n          payload via the unauthenticated /customer/address_file/upload endpoint\n          2. Trigger deserialization by sending a crafted JSON payload to the REST API\n          endpoint /rest/default/V1/guest-carts/{cart_id}/order that modifies the\n          session savePath to point to the uploaded file\n          3. Execute the uploaded PHP code to gain remote code execution\n\n          This vulnerability affects Magento 2.x instances configured to use file-based\n          session storage. Patched versions will return a 400 Bad Request response instead\n          of processing the malicious payload.",
  "disclosure_date": "2025-10-22",
  "fullname": "exploit/multi/http/magento_sessionreaper",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "Magento SessionReaper",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/magento_sessionreaper.rb",
  "platform": "Linux,PHP,Unix,Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/magento_sessionreaper",
  "references": [
    "CVE-2025-54236",
    "URL-https://slcyber.io/research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/",
    "URL-https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "PHP In-Memory",
    "Unix/Linux Command Shell",
    "Windows Command Shell"
  ],
  "type": "exploit"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesAdobe
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Adobe
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-54236",
  "cwes": "CWE-20",
  "dateAdded": "2025-10-24",
  "dueDate": "2025-11-14",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
  "product": "Commerce and Magento",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
  "vendorProject": "Adobe",
  "vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
}
—

vulnerability

Adobe Commerce and Magento Improper Input Validation Vulnerability
zetlyn/cve-kev · 2025-10-24
cwes CWE-20 due_date 2025-11-14 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Commerce and Magento vendor_project Adobe

exploit

Magento SessionReaper
zetlyn/cve-metasploit · 2025-10-22
platform Linux,PHP,Unix,Windows rank 600 source