CVE-2025-54236

critical KEV
Published 2025-09-09 · Modified 2025-10-24
CVSS v3
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
10.0

Description

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

CISA KEV

Vendor
Adobe
Product
Commerce and Magento
Due date
2025-11-14

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236

vendor Authored 2026-05-27

Vendor advisory: 134c704f-9b21-4f2e-91b3-4a467353bcc0 — https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397

vendor Authored 2026-05-27

Vendor advisory: psirt@adobe.com — https://helpx.adobe.com/security/products/magento/apsb25-88.html

Exploits

Package impact

EcosystemPackageVulnerableFixed
php Packagistmagento/community-edition<=2.4.5-p14
php Packagistmagento/community-edition
php Packagistmagento/community-edition>=2.4.6-p1,<=2.4.6-p12
php Packagistmagento/community-edition>=2.4.9-alpha1,<=2.4.9-alpha2
php Packagistmagento/community-edition>=2.4.7-beta1,<=2.4.7-p7
php Packagistmagento/community-edition>=2.4.8-beta1,<=2.4.8-p2
php Packagistmagento/project-community-edition<=2.0.2

Application impact

VendorProductVersionsFixed
adobecommerce2.4.4
adobecommerce2.4.5
adobecommerce2.4.6
adobecommerce2.4.7
adobecommerce2.4.8
adobecommerce2.4.9
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.4
adobecommerce_b2b1.4.2
adobecommerce_b2b1.5.2
adobecommerce_b2b1.5.3
adobemagento2.4.5
adobemagento2.4.6
adobemagento2.4.7
adobemagento2.4.8
adobemagento2.4.9

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.