Adobe Digest
Home / Newsletters / CVE-2025-54236 (CRITICAL) CVSS 9.1

CVE-2025-54236 (CRITICAL) CVSS 9.1

November 15, 2025


CVE-2025-54236 (CRITICAL) CVSS 9.1

🔴 Severity: CRITICAL (CVSS 9.1)

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Published: 2025-09-09
Last Modified: 2025-11-15 ⚠️

References:

  • helpx.adobe.com/security/…
  • experienceleague.adobe.com/en/docs/e…
  • nullsecurityx.codes/cve-2025-…
  • www.cisa.gov/known-exp…

View Full CVE Details on NIST NVD →

2025-11-15


All Newsletters Home

Stay Ahead of Security Threats

Get bulletins and research updates delivered to your inbox

✓ Official security bulletins ✓ Industry research ✓ Zero spam

Follow on Social

● Micro.blog ● Mastodon ● Bluesky

Independent community resource, not affiliated with Adobe