Skip to content
CISA Known Exploited Vulnerability

CVE-2025-54236 — Magento Actively Exploited CVE

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.

⚠ Actively exploited (CISA KEV) Magento 2025
CISA catalog entry
Product
Commerce and Magento
Vendor
Adobe
Added to KEV
2025-10-24
Remediation due
2025-11-14

CVE-2025-54236 is tracked in the CISA Known Exploited Vulnerabilities catalog. WebPulse monitors it as part of its framework security intelligence.

View CVE-2025-54236 on the NIST National Vulnerability Database →