SessionReaper (CVE-2025-54236) is a critical deserialization vulnerability in Magento 2 and Adobe Commerce that enables unauthenticated customer-account takeover through the Commerce REST API and, in certain configurations, remote code execution. Researchers described an attack chain combining manipulated API inputs with an unauthenticated file-upload endpoint, with file-based session storage particularly exposed. Redis-backed sessions are not affected by that specific chain, but alternative exploitation paths may exist. CrowdSec recorded 1,376 exploitation signals across 20 tracked days between October 28 and November 23, 2025, with a daily peak of 388 signals and up to 89 distinct attacking sources. Its reference to more than 130,000 stores reflects the platforms’ global footprint, not a verified count of compromised stores.
Adobe released an emergency fix on September 9, 2025, under security bulletin APSB25-88, including hotfix VULN-32437-2-4-X-patch. Adobe’s statement that it had no evidence of exploitation was explicitly dated September 18, 2025, preceding CrowdSec’s later observations; CrowdSec also reported the vulnerability’s subsequent addition to CISA’s Known Exploited Vulnerabilities catalog. Adobe deployed protective web application firewall rules for Commerce on Cloud infrastructure but emphasized that customers must still complete remediation. Organizations should prioritize applying Adobe’s applicable fixes, review session-storage configurations, and investigate suspicious REST API activity, uploads, and customer-account access. Researchers found that the patch restricts deserializable types, while warning that future changes could reintroduce similar weaknesses.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
CrowdSec identified November 7 as the date it confirmed its first in-the-wild SessionReaper signals. Its report separately gives conflicting October 23 and October 28 dates for the beginning of exploitation activity.
CrowdSec released detection rules for exploitation attempts targeting CVE-2025-54236.
According to CrowdSec, CISA added CVE-2025-54236 to its Known Exploited Vulnerabilities catalog, requiring remediation under Binding Operational Directive 22-01.
Searchlight Cyber published a technical analysis showing how nested deserialization could be chained with an unauthenticated file-upload endpoint to achieve code execution on systems using file-based session storage. The analysis also described a response-code difference that could distinguish patched from unpatched systems.
In an updated security notice, Adobe stated that it had no evidence of CVE-2025-54236 being exploited in the wild and urged customers to apply the available hotfix.
Adobe publicly disclosed the vulnerability through security bulletin APSB25-88 and released an emergency patch. The hotfix restricts deserialization to simple types and specific API Data Objects.
CrowdSec reported 1,376 exploitation signals across 20 tracked days within October 28–November 23, 2025, with a daily peak of 388 signals and up to 89 distinct attacking sources. These figures describe observed activity, not a verified count of compromised stores.
Adobe deployed web application firewall rules to help protect Adobe Commerce on Cloud infrastructure against exploitation. It emphasized that merchants still needed to apply the hotfix and follow all remediation guidance.
Researcher Daniel “Blaklis” Le Gall discovered CVE-2025-54236 in Magento and Adobe Commerce. The flaw involves nested deserialization and can enable customer-account takeover and, in certain configurations, unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
pentest-tools.com
Open sourceexperienceleague.adobe.com
Open sourcecrowdsec.net
Open sourceslcyber.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.