BR100 Decreased By (-0.91%)
BR30 Decreased By (-1.47%)
KSE100 Decreased By (-0.78%)
KSE30 Decreased By (-0.75%)
AGHA 6.67 Decreased By ▼ -0.01 (-0.15%)
BECO 4.35 Decreased By ▼ -0.02 (-0.46%)
BML 56.17 Decreased By ▼ -1.15 (-2.01%)
BOP 30.12 Decreased By ▼ -0.23 (-0.76%)
CNERGY 12.98 Decreased By ▼ -0.14 (-1.07%)
CSIL 5.31 Decreased By ▼ -0.10 (-1.85%)
FCCL 51.65 Decreased By ▼ -1.14 (-2.16%)
FFL 14.49 Decreased By ▼ -0.23 (-1.56%)
FNEL 1.21 Increased By ▲ 0.09 (8.04%)
KEL 6.06 Decreased By ▼ -0.03 (-0.49%)
KOSM 5.84 Increased By ▲ 0.11 (1.92%)
LOTCHEM 26.17 Decreased By ▼ -0.29 (-1.1%)
MLCF 91.23 Decreased By ▼ -1.93 (-2.07%)
NBP 164.19 Decreased By ▼ -0.47 (-0.29%)
NCPL 53.18 Decreased By ▼ -2.48 (-4.46%)
NPL 59.12 Decreased By ▼ -2.04 (-3.34%)
OGDC 313.39 Decreased By ▼ -3.34 (-1.05%)
PACE 9.77 Decreased By ▼ -0.10 (-1.01%)
PAEL 35.24 Decreased By ▼ -0.39 (-1.09%)
PIBTL 14.71 Increased By ▲ 0.03 (0.2%)
PPL 221.36 Decreased By ▼ -5.55 (-2.45%)
PRL 91.22 Decreased By ▼ -1.80 (-1.94%)
PTC 59.19 Decreased By ▼ -1.07 (-1.78%)
SSGC 23.30 Decreased By ▼ -0.51 (-2.14%)
TBL 8.75 No Change ▼ 0.00 (0%)
TELE 7.61 Decreased By ▼ -0.19 (-2.44%)
TPL 22.03 Decreased By ▼ -0.32 (-1.43%)
TPLP 12.56 Decreased By ▼ -0.41 (-3.16%)
TREET 21.73 Decreased By ▼ -0.43 (-1.94%)
TRG 55.79 Decreased By ▼ -0.77 (-1.36%)

ISLAMABAD: The National Computer Emergency Response Team (NCERT) has issued a high-priority advisory warning to businesses of a critical vulnerability in Adobe Commerce and Magento Open Source platforms, dubbed SessionReaper.

The flaw, tracked as CVE-2025-54236, has been rated at CVSS 9.1 (Critical) and arises from improper input validation in the Commerce REST API. Successful exploitation could allow attackers to hijack customer sessions, gain unauthorized access to accounts, and, under certain conditions, execute remote code on affected servers.

According to NCERT, the vulnerability impacts multiple deployment methods of Adobe Commerce, Magento Open Source, B2B extensions, and the Custom Attributes Serializable Module. It poses a high risk of customer data theft, hijacked transactions, and potential full system compromise.

National CERT issues urgent data protection alert

If exploited, attackers could achieve: Account takeover and theft of sensitive customer information, remote code execution (RCE) in environments with file-based session storage enabled, privilege escalation through stolen tokens or API keys, and service disruption, potentially leading to widespread downtime of eCommerce operations.

NCERT has urged organizations to apply emergency hotfix VULN-32437-2-4-X-patch or upgrade to the latest Adobe release (APSB25-88) without delay. It also recommended rotating administrator and API credentials immediately, restricting REST API exposure to trusted networks, enforcing strict WAF/IDS/IPS rules to detect and block malicious traffic, the monitoring logs for abnormal login attempts, session manipulation, and privilege escalations.

The advisory warned that large-scale exploitation campaigns could emerge quickly, given the low complexity of attacks and the absence of authentication requirements.

“Timely patching is essential to prevent mass compromise of eCommerce platforms,” NCERT said, urging businesses to strengthen monitoring and apply defense-in-depth measures.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.