<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Magento Updates &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/magento-updates/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 24 Oct 2025 04:46:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Magento Updates &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Critical Adobe Commerce &#038; Magento Vulnerability CVE-2025-54236 Under Active Attack – Apply Security Patch Now</title>
		<link>https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/</link>
					<comments>https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 23 Oct 2025 09:02:23 +0000</pubDate>
				<category><![CDATA[Magento Updates]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Reports]]></category>
		<category><![CDATA[#AdobeCommerce]]></category>
		<category><![CDATA[#CVE202554236]]></category>
		<category><![CDATA[#DataProtection]]></category>
		<category><![CDATA[#MagentoSecurity]]></category>
		<category><![CDATA[#WebSecurity]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=10546</guid>

					<description><![CDATA[<p>E-commerce security experts at Sansec have issued a warning about active exploitation targeting a newly disclosed Adobe Commerce</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/">Critical Adobe Commerce &amp; Magento Vulnerability CVE-2025-54236 Under Active Attack – Apply Security Patch Now</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>E-commerce security experts at <strong>Sansec</strong> have issued a warning about active exploitation targeting a newly disclosed <strong>Adobe Commerce</strong> and <strong>Magento Open Source</strong> vulnerability. Known as <strong>CVE-2025-54236</strong> and nicknamed <strong>SessionReaper</strong>, this critical security flaw (CVSS score: 9.1) allows attackers to compromise customer accounts through the <strong>Commerce REST API</strong>.</p>



<p>Over the past 24 hours, Sansec has recorded more than <strong>250 attack attempts</strong> against multiple online stores. Alarmingly, research indicates that <strong>62% of Magento stores remain vulnerable</strong> six weeks after the public disclosure. Website administrators and e-commerce businesses are urged to <strong>apply security patches immediately</strong> to prevent customer account takeovers and potential data breaches.</p>



<p>The vulnerability was discovered and responsibly disclosed by security researcher <strong>Blaklis</strong> and was patched by Adobe last month. Threat actors have been leveraging this flaw to upload <strong>PHP webshells</strong> or probe <code>phpinfo</code> files to extract PHP configuration information. Attack traffic has originated from IP addresses including:</p>



<ul class="wp-block-list">
<li>34.227.25[.]4</li>



<li>44.212.43[.]34</li>



<li>54.205.171[.]35</li>



<li>155.117.84[.]134</li>



<li>159.89.12[.]166</li>
</ul>



<p>Sansec confirmed that attackers exploit the vulnerability by uploading <strong>PHP backdoors</strong> via the <code>/customer/address_file/upload</code> endpoint, masquerading as fake session files.</p>



<p>A detailed technical analysis by <strong>Searchlight Cyber</strong> describes CVE-2025-54236 as a <strong>nested deserialization flaw</strong> that allows <strong>remote code execution (RCE)</strong>. This makes it the <strong>second major deserialization vulnerability</strong> affecting Adobe Commerce and Magento in just two years, following the <strong>CosmicSting flaw (CVE-2024-34102)</strong>, which saw widespread exploitation in July 2024.</p>



<p>With <strong>proof-of-concept exploits</strong> now publicly available, online retailers, developers, and e-commerce administrators must <strong>prioritize patching vulnerable Magento and Adobe Commerce installations</strong> to safeguard sensitive customer data and prevent cyberattacks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/">Critical Adobe Commerce &amp; Magento Vulnerability CVE-2025-54236 Under Active Attack – Apply Security Patch Now</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
