EXPOSURES › CVE-2025-54236
CVE-2025-54236
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe's Magento suffered an unpatched input validation flaw exploited in the wild, allowing remote code execution and potential account takeover via the REST API.
Adobe's Magento Commerce and Open Source versions had an unpatched input validation vulnerability that was actively exploited, enabling attackers to compromise customer accounts via the REST API. This could lead to remote code execution and unauthorized access.
Shame score — Active exploitation of a known vulnerability with no indication of a fix, leading to potential unauthorized access and data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |