Hundreds of Adobe Magento stores hit after critical security flaw found – here’s what we know


  • CVE-2025-54236 is actively exploited to hijack accounts via Magento’s REST API
  • Over 250 attacks in 24 hours; most stores remain unpatched six weeks after patching
  • Attackers upload PHP backdoors using fake sessions; Sansec encourages immediate patching and scans

A critical severity vulnerability recently found in Adobe Commerce and Magento Open Source platforms is being actively exploited in the wild to attack e-commerce websites and take over accounts, experts have warned.

Researchers at Sansec said in less than 24 hours they observed more than 250 attacks exploiting CVE-2025-54236, a Critical Severity (9.1/10) bug described as an “improper input validation” vulnerability.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top