CWE-CWE-20

Adobe Commerce/Magento "SessionReaper" RCE (CVE-2025-54236)

Severity:
Critical
Summary

A deserialization vulnerability in Adobe Commerce and Adobe Magento allows an attacker to send specially crafted requests that can bypass authentication. This flaw can be combined with file-upload functionality to achieve remote code execution (RCE).

Impact

An unauthenticated attacker can compromise the system.

Remediation

Upgrade to the latest version of Adobe Commerce/Magento

Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding