CVE-2025-54236: critical vulnerability in Adobe Commerce
Adobe Commerce | Improper Input Validation (CWE-20)
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Commerce has a flaw that fails to properly check user input, allowing attackers to take over customer or admin sessions without any user action. This gives attackers full access to accounts and sensitive data.
Improper input validation in affected Adobe Commerce versions (2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier) enables unauthenticated session hijacking. The vulnerability allows attackers to craft malicious input that bypasses validation controls, leading to unauthorized session establishment without requiring user interaction, resulting in high confidentiality and integrity impact.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.