The biggest web store security story of late: SessionReaper (CVE-2025-54236, CVSS 9.1) hits Magento / Adobe Commerce . The vulnerability allows account takeover and, in a bad scenario, unauthenticated remote code execution (RCE) — attackers through the upload endpoint plant PHP backdoors disguised as session files. Mass exploitation started on 10/22/2025. ; it is estimated that 16–18% of all Magento stores already have a planted backdoor .
Are you affected?
- Unknown files in
var/or suspicious "session" files with PHP code - Unknown admin logins, order changes, or skimmer JavaScript at checkout (card theft)
- Suspicious requests to
/customer/address_file/uploadin logs - The store is open, but customers are reporting misuse of their cards
What to do now
- Apply Adobe's hotfix for CVE-2025-54236 (Adobe Commerce / Magento Open Source).
- Check for backdoors and skimmer code; compare files with clean version.
- Rotate keys, admin passwords, and invalidate all sessions.
- If the store was vulnerable before the patch — assume a breach and perform forensics.
A webshop that steals customers' cards is both a reputational and legal risk — act quickly.
Do you have a Magento store and you're not sure if it's clean? Send us the link — the diagnosis is free, and we'll get back to you within 5 minutes. Urgent repair →
WMD — Super fast support.