peter bassill · operator
$ cve CVE-2025-54236 JSON

CVE-2025-54236 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 94.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-11-14.

Description

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS94.53% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2025-11-14
Public exploitnone known
Published2025-09-09
Last modified2026-06-17

CISA KEV

NameAdobe Commerce and Magento Improper Input Validation Vulnerability
Added2025-10-24
Due2025-11-14
Vendor / productAdobe / Commerce and Magento
Ransomware usenone reported

Affected (3)

VendorProduct
adobecommerce
adobecommerce b2b
adobemagento

References

→ the Explorer  ·  watch your stack  ·  NVD