By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
The Pixel PakistanThe Pixel PakistanThe Pixel Pakistan
Font ResizerAa
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films
Reading: NCERT Warns of Critical “SessionReaper” Flaw in Adobe Commerce & Magento Platforms
Font ResizerAa
The Pixel PakistanThe Pixel Pakistan
  • Home
  • Tech
  • Political
  • Sports
  • News
  • Fashion
  • Contact
  • Privacy Policy
  • Terms & Conditions
Search
  • Home
  • Exclusive
  • Tech
  • Political
  • News
  • Fashion
  • Business
  • Sports
  • Music
  • Films

Trending →

GTA 6 Pre-Order Date Revealed Alongside Official Cover Art as Rockstar Begins Final Marketing Push

By
Syed Mehmood
June 18, 2026

Sindh Police Blacklist 40,000 Vehicles in Karachi Ahead of July 1 Crackdown

By
Publisher
June 9, 2026

Sindh’s SECCAP Admissions Portal Restored After Upgrades, Education Department Confirms

By
Publisher
June 5, 2026

Binance and Telenor Pakistan Sign MoU to Explore Digital Innovation and Blockchain Education Initiatives in Pakistan

By
Publisher
June 3, 2026

Binance and Telenor Pakistan Sign MoU to Explore Digital Innovation and Blockchain Education Initiatives in Pakistan

By
Syed Mehmood
June 3, 2026
Follow US
© 2025 The Pixel Pakistan. All rights reserved.
WhatsApp Image 2025 10 28 at 3.44.45 PM
DefenceNewsTech

NCERT Warns of Critical “SessionReaper” Flaw in Adobe Commerce & Magento Platforms

Syed Mehmood
Last updated: October 28, 2025 12:26 pm
By
Syed Mehmood
Share
3 Min Read
SHARE
chrome

The National Computer Emergency Response Team (NCERT) has issued a high-priority advisory for organizations using Adobe Commerce and Magento Open Source, warning of a newly discovered critical vulnerability tracked as CVE-2025-54236 — dubbed “SessionReaper.”

Rated 9.1 (Critical) on the CVSS scale, the flaw allows unauthenticated attackers to hijack active customer sessions. Experts caution that this could lead to large-scale account takeovers, theft of sensitive data, and even remote code execution under certain conditions.


Technical Overview

According to NCERT, the SessionReaper vulnerability arises from improper input validation within the Commerce REST API, enabling attackers to manipulate session data remotely. The flaw affects multiple configurations, including:

  • Adobe Commerce
  • Magento Open Source
  • B2B Extensions
  • Custom Attributes Serializable Module

When exploited, attackers could intercept or impersonate user sessions, escalate privileges, execute arbitrary code, or gain full access to backend systems.


Affected Versions

  • Adobe Commerce: up to version 2.4.9-alpha2
  • Magento Open Source: up to version 2.4.9-alpha2

Both platforms and their corresponding modules are exposed if not updated to the latest security release.


Why It’s Dangerous

Cybersecurity analysts emphasize that SessionReaper is particularly alarming due to its low attack complexity and lack of authentication requirements. It can be executed remotely, making it easy for attackers to target unpatched systems.

Potential consequences include:

  • Mass account hijacking and unauthorized transactions
  • Service disruption and operational downtime
  • Financial and reputational losses for online businesses

The e-commerce sector, especially platforms handling customer and payment data, remains highly vulnerable if the flaw is left unaddressed.


Recommended Mitigation

NCERT has strongly urged all administrators and developers to implement immediate security measures. The team recommends applying the emergency hotfix (VULN-32437-2-4-X-patch) or upgrading to the latest Adobe release (APSB25-88).

For organizations unable to patch immediately, the following temporary safeguards are advised:

  • Restrict REST API access to trusted IP ranges and internal networks
  • Deploy Web Application Firewall (WAF) rules to detect and block suspicious payloads
  • Continuously monitor system logs for unusual login or session activity
  • Rotate credentials and enforce least-privilege permissions for administrative accounts
  • Strengthen intrusion detection and endpoint monitoring systems

With cyber threats against e-commerce platforms growing more frequent and sophisticated, the SessionReaper flaw underscores the urgent need for proactive defense measures. Adobe Commerce and Magento Open Source users are advised to prioritize patching and continuously monitor for signs of compromise.

Failure to address this vulnerability promptly could expose thousands of online stores to session hijacking, data theft, and full-scale system compromise. Immediate action is the only reliable safeguard.

Share This Article
Facebook Whatsapp Whatsapp Threads Copy Link
What do you think?
Love0
Sad0
Happy0
Angry0

Follow Us

- Advertisement -

The Pixel Pakistan

More

03c3e400 6b19 11f1 be36 65d2d6d55e70.jpg
GTA 6 Pre-Order Date Revealed Alongside Official Cover Art as Rockstar Begins Final Marketing Push
Gaming
banner3
Sindh Police Blacklist 40,000 Vehicles in Karachi Ahead of July 1 Crackdown
Exclusive
Banner
Sindh’s SECCAP Admissions Portal Restored After Upgrades, Education Department Confirms
News
WhatsApp Image 2026 06 02 at 2.54.48 PM 1
Binance and Telenor Pakistan Sign MoU to Explore Digital Innovation and Blockchain Education Initiatives in Pakistan
Business

Top 10 Coins

  • bitcoinBitcoin$62,678.00-2.04%
  • ethereumEthereum$1,665.70-3.57%
  • tetherTether$1.000.00%
  • binancecoinBNB$577.36-2.33%
  • usd-coinUSDC$1.000.00%
  • rippleXRP$1.10-2.03%
  • solanaSolana$69.50-3.30%
  • tronTRON$0.329022-1.25%
  • Figure HelocFigure Heloc$1.03-0.16%
  • HyperliquidHyperliquid$61.25-8.59%
Powered by CoinGecko API

You Might Also Like ↷

images 1 2

Hackers Threaten KP Govt and RAW with 500 Bitcoin Ransom, Warn of Data Leak

By
Syed Mehmood
September 28, 2025
shaheen

Pakistan and Saudi Arabia Sign Historic Mutual Defence Agreement

By
Syed Mehmood
September 17, 2025
ptcl telenor

 CCP grants approval for PTCL’s acquisition of Telenor Pakistan

By
Syed Mehmood
October 1, 2025
abirgulaalreview d

Fawad Khan’s Big Bollywood Return in Aabeer Gulaal Fails to Meet Expectations

By
Syed Mehmood
September 17, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles and deals instantly!
  • Write For Us
  • Careers
  • Advertise with us
  • Contact
Pixel Pakistan is the voice of today and the vision of tomorrow, a platform that frames the evolving picture of our nation with clarity and depth. More than just news, it is a space where truth, inquiry, and understanding come together to inspire fresh perspectives and progress.
The Pixel Pakistan
393.9KFollowersLike
34.3KFollowersFollow
InstagramFollow
4.4MSubscribersSubscribe
TiktokFollow
30.4KFollowersFollow
LinkedInFollow
RSS FeedFollow

© 2025 The Pixel Pakistan. All rights reserved.

  • Terms & Conditions
  • Privacy Policy
  • About Us