Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Adobe patches ‘most severe’ flaw in Magento eCommerce platform

Tech Wavo by Tech Wavo
September 10, 2025
in Computers
0




  • Adobe patched a critical Web API flaw in Commerce and Magento
  • The bug, dubbed SessionReaper, scored 9.1/10 and affects multiple versions
  • Researchers warn the leaked hotfix may aid attackers

Adobe has patched a critical vulnerability in its Commerce and Magento Open Source platforms that could lead to full account takeover.

In a recently published security advisory, Adobe said it fixed an Improper Input Validation (CWE-20) vulnerability affecting the ServiceInputProcessor component of the Web API.

In other words, it allows malicious, improperly validated API requests to bypass security controls. Researchers dubbed it SessionReaper.


You may like

Most severe flaw ever

The bug is now tracked as CVE-2025-54236 and has been given a severity score of 9.1/10 (critical) on the National Vulnerability Database (NVD).

Vulnerable versions include 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier, the NVD page says.

“A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.” Adobe Commerce on Cloud customers are protected by a web application firewall (WAF), the company confirmed.

The company says it is not aware of any exploits in the wild but, according to BleepingComputer, describes it as “the most severe” flaw in the history of the platform.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

A patch was released on September 9, and customers are urged to apply it without delay. “Please apply the hotfix as soon as possible. If you fail to do so, you will be vulnerable to this security issue, and Adobe will have limited means to help remediate,” Adobe warned.

While there is no evidence of in-the-wild abuse, security outfit Sansec said the initial hotfix for SessionReaper was leaked a few days ago, which could allow malicious actors to reverse-engineer it and find additional holes to exploit, BleepingComputer reported.

At the same time, some researchers believe deploying the fix could break some external code breaking, since it disables certain Magento functionalities.

Via BleepingComputer

You might also like

Previous Post

How AI is rewriting the playbook for investing

Next Post

Meta adds new features to Community Notes fact checks, including alerts for corrected posts

Next Post
Report: Meta is hitting pause on AI hiring after its poaching spree

Meta adds new features to Community Notes fact checks, including alerts for corrected posts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Charlie Kirk Shot at Utah Valley University Event

by Tech Wavo
September 10, 2025
0
Charlie Kirk Shot at Utah Valley University Event
Computers

Charlie Kirk, the internet personality and cofounder of Turning Point USA, was shot on Wednesday afternoon at Utah Valley University...

Read more

While U.S. stalls, Australia and Anduril move to put XL undersea vehicle into service

by Tech Wavo
September 10, 2025
0
Tesla could have avoided that $242.5M Autopilot verdict, filings show
Computers

With Anduril’s help, Australia has done what the U.S. Navy has struggled to accomplish: transition an extra-large undersea drone from...

Read more

Creative Stage Pro review: an affordable soundbar that’s equally at home on a TV stand or desktop

by Tech Wavo
September 10, 2025
0
Creative Stage Pro review: an affordable soundbar that’s equally at home on a TV stand or desktop
Computers

Why you can trust TechRadar We spend hours testing every product or service we review, so you can be sure...

Read more

Lyft launches autonomous fleet with May Mobility in Atlanta

by Tech Wavo
September 10, 2025
0
Lyft launches autonomous fleet with May Mobility in Atlanta
Computers

Lyft and May Mobility have teamed up to launch a fleet of autonomous vehicles in Atlanta. It's a pilot program,...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock