Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Adobe Commerce Improper Input Validation Vulnerability Leading to Session Takeover

Vulnerability

A vulnerability allowing improper input validation has been identified in Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier. This vulnerability can be exploited by an attacker to achieve session takeover, significantly increasing the risks to confidentiality and integrity. Notably, exploitation of this issue does not require any user interaction.

Impact

Successful exploitation of this vulnerability can lead to session takeover, allowing an attacker to impersonate a user and potentially access or modify sensitive information.

Remediation

Users are advised to update to the latest version of Adobe Commerce. A hotfix for this vulnerability is available and compatible with all Adobe Commerce versions between 2.4.4 and 2.4.7. For more details, refer to the Release Notes for the hotfix on CVE-2025-54236.

Added: Sep 9, 2025, 2:17 PM
Updated: Oct 24, 2025, 5:08 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
9.3
remediation
7.0
relevance
0.5
threat
9.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.