Adobe will release fix for the critical SessionReaper attack tomorrow Sept 9th. All Magento and Adobe Commerce versions are vulnerable. Sansec Shield users are already protected, all others should standby and implement patch once it is published (likely 14h UTC). sansec.io/research/ses...
SessionReaper, a critical bug in Magento & Adobe Commerce (CVE-2025-54236)
Adobe breaks their regular patch schedule and will release an emergency fix for CVE-2025-54236 within the next 24 hours. Automated abuse is expected and merc...
sansec.io