SessionReaper is considered one of the most serious Magento security issues to date, and has been compared to high-profile vulnerabilities such as Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022) and CosmicSting (2024). In past incidents, thousands of stores were compromised, in some cases within mere hours of the vulnerability being disclosed.
We first learned of the patch through Sansec’s report of its pending release on Sep 8th. Adobe had privately notified selected Commerce customers, however Open Source clients were left uninformed. While we knew an emergency update was on the horizon, Adobe does not share full details in advance, so the severity wasn’t clear until the official announcement.
Timeline
Aug 22nd: Adobe internally discusses emergency fix
Sep 4th: Adobe privately announces emergency fix to selected Commerce customers
Sep 9th: Adobe releases emergency patch for SessionReaper - CVE-2025-54236 in APSB25-88
(Source: Sansec)
To ensure our customers were prepared, we proactively raised support tickets ahead of time. This allowed us to respond immediately once details became available, prioritising customer protection.
Once the severity became clear, our team acted immediately. Within minutes of the release, we informed customers of the risk and scheduled the patch implementation.
We began by coordinating with our development team and applying the update to development environments. From there, our developers and account managers collaborated to thoroughly test and validate the patch, confirming it was safe for production.
We're proud to report another 100% success rate – within 24 hours all clients were patched, with no issues following deployment to live environments.
If your agency hasn't been in touch about this patch, we strongly recommend reaching out to them. It's also worth asking why a more proactive approach wasn't taken. This is a critical update, your Magento site and customer data could be at serious risk without it.
Keep up to date with everything eCommerce.