CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-54236

CVSS 9.1v3.1pub. 2025-09-09upd. 2026-05-12

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

🤖 AI Analysis
How it works

The error results from improper input validation in Adobe Commerce. An attacker, without possessing an account or requiring any user interaction, can supply crafted input data to the vulnerable application mechanism. This results in hijacking an active session of another user — potentially including store administrators — giving the attacker high-level access to sensitive data and the ability to modify resources.

Impact

An attacker can gain full control over a hijacked session, resulting in high impact on confidentiality (access to customer data, orders, configuration) and system integrity (ability to introduce unauthorized changes). The vulnerability does not directly affect system availability.

Mitigation & patch

Adobe Commerce and Magento must be immediately updated to versions containing the patch described in the vendor security bulletin APSB25-88 (https://helpx.adobe.com/security/products/magento/apsb25-88.html). Due to active exploitation in production environments, the update should be an immediate priority. Until the patch is deployed, enhanced session monitoring is recommended and restricting access to the administrative panel should be considered.

Who is affected

Adobe Commerce and Adobe Magento in versions: 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier. Also affects Adobe Commerce B2B.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Adobe Commerce

    APP
    Adobe
    2.4.42.4.52.4.62.4.72.4.82.4.9
  • Adobe Commerce B2b

    APP
    Adobe
    1.3.31.3.41.4.21.5.21.5.3
  • Adobe Magento

    APP
    Adobe
    2.4.52.4.62.4.72.4.82.4.9

CISA KEV — detailsi

Vendori
Adobe
Producti
Commerce and Magento
Added to KEVi
October 24, 2025
Remediation deadline (US Federal)i
November 14, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 14 listopada 2025
CWE
References

Related vulnerabilities

CVE-2024-34102CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE

CVE-2022-24086CRITICAL9.8⚠ KEVPL ✓same product

Adobe Commerce — RCE przez błędną walidację danych podczas checkout

CVE-2026-48356CRITICAL9.3PL ✓same product

Adobe Commerce — nieograniczony upload pliku umożliwiający RCE

CVE-2026-48358CRITICAL9.1PL ✓same product

RCE w Adobe Commerce — błąd kodowania wyjścia (CVE-2026-48358)

CVE-2025-24434CRITICAL9.1PL ✓same product

Adobe Commerce — Incorrect Authorization umożliwiające privilege escalation