Fear the 'SessionReaper': Adobe Commerce Flaw Under Attack
CVE-2025-54236 is a critical flaw in Adobe Commerce (formerly Magento) that allows attackers to remotely take over sessions on the e-commerce platform.
Stay secure with the latest e-commerce cybersecurity trends, news, and tips to protect your online business from cyber threats.
Search across headline titles and summaries.
Background for this topic.
E-commerce is the activity of buying and selling goods and services online. It involves transactions made on the internet, ranging from retail shopping and auctions to banking services and online ticket bookings. In the context of information security, E-commerce encompasses the protection of sensitive data, such as customer credit card numbers, personal information, and transaction records.
Information security measures in E-commerce aim to safeguard against threats like hacking, identity theft, and phishing. This includes the implementation of security protocols like SSL/TLS for secure communications, employing encryption to protect data in transit, deploying robust authentication mechanisms to verify user identities, and adhering to compliance standards like PCI-DSS that are designed to protect customer data within payment systems.
E-commerce security also involves regular security audits, monitoring for suspicious activities, and having incident response plans in place to address potential breaches swiftly. The integrity, confidentiality, and availability of E-commerce platforms are critical for maintaining consumer trust and ensuring the smooth operation of online marketplaces.
Weekly headline count for the current query.
CVE-2025-54236 is a critical flaw in Adobe Commerce (formerly Magento) that allows attackers to remotely take over sessions on the e-commerce platform.
Adobe is warning of a critical vulnerability (CVE-2025-54236) in its Commerce and Magento Open Source platforms that researchers call SessionReaper and describe as one of " the most severe" flaws in the history of the product. [...]
The infamous payment-skimmer cybercrime organization is exploiting CVE-2024-20720 in Magento for a novel approach to stealing card data.