BR100 Increased By (0.11%)
BR30 Decreased By (-0.26%)
KSE100 Increased By (0.12%)
KSE30 Increased By (0.09%)
AGHA 7.79 Increased By ▲ 0.04 (0.52%)
BECO 5.23 Increased By ▲ 0.04 (0.77%)
BML 57.26 Decreased By ▼ -1.40 (-2.39%)
BOP 34.10 Increased By ▲ 0.41 (1.22%)
CNERGY 9.92 Decreased By ▼ -0.69 (-6.5%)
CSIL 5.35 Increased By ▲ 0.05 (0.94%)
FCCL 54.61 Increased By ▲ 0.87 (1.62%)
FFL 16.70 Increased By ▲ 0.24 (1.46%)
FNEL 1.24 Increased By ▲ 0.02 (1.64%)
KEL 7.42 Increased By ▲ 0.14 (1.92%)
KOSM 5.75 Increased By ▲ 0.11 (1.95%)
LOTCHEM 29.35 Decreased By ▼ -0.30 (-1.01%)
MLCF 94.35 Decreased By ▼ -2.01 (-2.09%)
NBP 202.70 Decreased By ▼ -0.83 (-0.41%)
NCPL 57.00 Increased By ▲ 0.15 (0.26%)
NPL 67.78 Increased By ▲ 0.47 (0.7%)
OGDC 316.40 Decreased By ▼ -1.82 (-0.57%)
PACE 10.64 Increased By ▲ 0.01 (0.09%)
PAEL 43.15 Increased By ▲ 1.38 (3.3%)
PIBTL 16.72 Decreased By ▼ -0.09 (-0.54%)
PPL 220.50 Increased By ▲ 0.33 (0.15%)
PRL 49.05 No Change ▼ 0.00 (0%)
PTC 70.98 Increased By ▲ 0.97 (1.39%)
SSGC 28.17 Decreased By ▼ -0.97 (-3.33%)
TBL 9.90 Increased By ▲ 0.13 (1.33%)
TELE 8.80 Decreased By ▼ -0.02 (-0.23%)
TPL 18.14 Increased By ▲ 0.97 (5.65%)
TPLP 13.40 Increased By ▲ 0.89 (7.11%)
TREET 22.75 Increased By ▲ 0.16 (0.71%)
TRG 60.30 Increased By ▲ 0.08 (0.13%)

ISLAMABAD: The National Computer Emergency Response Team (NCERT) has issued a high-priority advisory warning to businesses of a critical vulnerability in Adobe Commerce and Magento Open Source platforms, dubbed SessionReaper.

The flaw, tracked as CVE-2025-54236, has been rated at CVSS 9.1 (Critical) and arises from improper input validation in the Commerce REST API. Successful exploitation could allow attackers to hijack customer sessions, gain unauthorized access to accounts, and, under certain conditions, execute remote code on affected servers.

According to NCERT, the vulnerability impacts multiple deployment methods of Adobe Commerce, Magento Open Source, B2B extensions, and the Custom Attributes Serializable Module. It poses a high risk of customer data theft, hijacked transactions, and potential full system compromise.

National CERT issues urgent data protection alert

If exploited, attackers could achieve: Account takeover and theft of sensitive customer information, remote code execution (RCE) in environments with file-based session storage enabled, privilege escalation through stolen tokens or API keys, and service disruption, potentially leading to widespread downtime of eCommerce operations.

NCERT has urged organizations to apply emergency hotfix VULN-32437-2-4-X-patch or upgrade to the latest Adobe release (APSB25-88) without delay. It also recommended rotating administrator and API credentials immediately, restricting REST API exposure to trusted networks, enforcing strict WAF/IDS/IPS rules to detect and block malicious traffic, the monitoring logs for abnormal login attempts, session manipulation, and privilege escalations.

The advisory warned that large-scale exploitation campaigns could emerge quickly, given the low complexity of attacks and the absence of authentication requirements.

“Timely patching is essential to prevent mass compromise of eCommerce platforms,” NCERT said, urging businesses to strengthen monitoring and apply defense-in-depth measures.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.