CRITICAL

APSB25-88: Security update available for Adobe Commerce

Published Sep 9, 2025.

Improper input validation in the Web API's service input processor (CVE-2025-54236), publicly known as SessionReaper. An unauthenticated attacker can hijack customer sessions through the REST API and, depending on configuration, reach remote code execution. Adobe shipped the out-of-band hotfix VULN-32437 before the regular patch release; it was the first emergency patch since CosmicSting.

Published
Sep 9, 2025
Severity
critical
CVEs
1
Isolated patch
yes

CVEs

CVEs in APSB25-88
CVE CVSS Type Impact Auth required
CVE-2025-54236 9.1 improper-input-validation security-feature-bypass no

Fixed in

Magento Open Source
2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
Adobe Commerce
2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
Mage-OS

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-88