- Bulletin ID: APSB25-88
- Product: APSB25-88: Security update available for Adobe Commerce
- Published: September 09, 2025
- Priority: 1
- Severity: Critical
- CVE Count: 1
Affected Versions
- Adobe Commerce: 2.4.9-alpha2 and earlier2.4.8-p2 and earlier2.4.7-p7 and earlier2.4.6-p12 and earlier2.4.5-p14 and earlier2.4.4-p15 and earlier
- Adobe Commerce B2B: 1.5.3-alpha2 and earlier1.5.2-p2 and earlier1.4.2-p7 and earlier1.3.4-p14 and earlier1.3.3-p15 and earlier
- Magento Open Source: 2.4.9-alpha2 and earlier2.4.8-p2 and earlier2.4.7-p7 and earlier2.4.6-p12 and earlier2.4.5-p14 and earlier
Vulnerability Details
Total Vulnerabilities: 1
Severity Breakdown:
Key Vulnerabilities:
1. CVE-2025-54236
- Category: Improper Input Validation (CWE-20)
- Impact: Security feature bypass
- Severity: Critical
- CVSS Score: 9.1
- Authentication Required: No
CVE Identifiers
CVE-2025-54236
Read Full Bulletin on Adobe Security Portal →