Input validation error in Adobe products - CVE-2025-54236
Published: September 9, 2025 / Updated: April 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote non-authenticated attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Affected software
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
How to mitigate CVE-2025-54236
Install a hotfix from vendor's website:
https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397
Links to Public Exploits and PoC-codes
- Exploit #12539 - SessionReaper-CVE-2025-54236 (PHP object deserialization in Magento 2's ServiceInputProcessor, with PoC and three exploitation vectors.) (April 1, 2026)
- Exploit #12186 - Magento SessionReaper (December 10, 2025)
- Exploit #12099 - CVE-2025-54236 (CVE-2025-54236 - Magento Remote Code Execution Exploit) (November 7, 2025)