SessionReaper Strikes: Adobe Commerce Users Scramble to Patch Critical Vulnerability!
SessionReaper (CVE-2025-54236) is wreaking havoc on Adobe Commerce, with hackers exploiting it like it’s a cyber buffet. Six weeks post-patch, hundreds of attempts are recorded, yet 62% of online stores remain vulnerable. It’s a digital Wild West out there—time for website admins to patch up or face the code-slingers!

Hot Take:
Well, it seems like Adobe Commerce is having a bit of an identity crisis—it’s gone from being a shopping haven to a hacker’s playground faster than you can say “SessionReaper.” Someone should tell them this is not what they meant by “customer engagement.”
Key Points:
- Hackers are exploiting the SessionReaper vulnerability in Adobe Commerce.
- The flaw allows attackers to hijack account sessions without user interaction.
- Sansec has detected and blocked over 250 exploitation attempts in a single day.
- A technical analysis by Searchlight Cyber could fuel further exploitation.
- 62% of Magento stores are still vulnerable due to not applying the patch.
Already a member? Log in here
