Exploited Known exploited (KEV) CVE-2025-54236

Improper input validation in Adobe Commerce and Magento (CVE-2025-54236) — what the attacker takes is not the merchant account but the customer one

Adobe Commerce and Magento Added to KEV Oct 24, 2025 Federal remediation due 2025-11-14

Adobe Commerce and Magento Open Source contain an improper input validation flaw that could allow an attacker to take over customer accounts through the Commerce REST API. CISA added it to the KEV catalog on 2025-10-24 with a due date of 2025-11-14.

Key facts

  • CVE IDCVE-2025-54236
  • Affected (vendor / product)Adobe Commerce and Magento
  • CWECWE-20
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2025-11-14 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected products are Adobe Commerce and Magento Open Source; CWE-20, improper input validation.
  • An attacker could take over customer accounts through the Commerce REST API.
  • The harm falls on customers shopping at the site rather than on the merchant operating it, which runs opposite to most KEV records.
  • The scope includes the open source edition, where the update decision rests with the operator and remediation therefore spreads unevenly.
  • Added to KEV 2025-10-24 with a due date of 2025-11-14 — 21 days, the most standard setting at 1,025 of the 1,685 records this site holds as of 2026-08-28 (61 percent).
  • Across the 1,687 records held as of 2026-09-01, 1,025 carry a 21-day deadline, 86 carry three days and 238 carry 181.

1The harm lands outside the organization

Most vulnerabilities in KEV carry a storyline in which a server or a network device is breached and the inside of that organization is put at risk. This record runs the other way. What is taken is not the account of the merchant running the site but the account of a customer shopping on it: name, address, order history, saved payment method.

Where the takeover succeeds, it is the attacker rather than the merchant who can reach them. The duty to fix sits with the merchant while the harm sits with the customer, and that asymmetry is the shape of this entry.

2The REST API as the way in

What the catalog names is not the ordinary purchase screen but the Commerce REST API. An API is the entrance through which applications and external systems call the functions of a site, provided separately from the screens people use. However carefully input is checked on the screen side, a loose check on the API side becomes the route through.

The classification of improper input validation refers to processing values without confirming them adequately, and here that is said to lead to account takeover.

3The open source edition is in the same record

The scope covers not only the commercial Adobe Commerce but Magento Open Source. Open source editions are often built and operated in-house, leaving the update decision to the operator. Without a mechanism for the vendor to push a fix to everyone, the same vulnerability reaches different levels of remediation.

The due date is 21 days after listing, which across the 1,685 records this site holds as of 2026-08-28 is the most standard setting at 1,025 records, or 61 percent. How much account takeover was actually observed is not part of this catalog record.

4Remediation dates are not uniform

A KEV entry carries a date by which it must be fixed. That number of days differs by entry and is itself information about how heavily the entry is treated.

21 days1025 / 1687
14 days269 / 1687
181 days238 / 1687
3 days86 / 1687
7 days20 / 1687

The breakdown is across the 1,687 records held as of 2026-09-01. Twenty-one days is the most common and the standard setting. Alongside it, 86 entries carry a window as short as three days while 238 carry one as long as 181. The 21 days here is on the standard side.

The scope covers not only the commercial Adobe Commerce but Magento Open Source, which is more often built and run in-house, so the same vulnerability reaches its fix along a different path.

Why it matters

Setting priority purely by whether your own assets are protected tends to undervalue this class of flaw. What is breached belongs to the customer, and it returns to the merchant as a question of trust and accountability. Input validation on the API side has to be checked separately from the screen side, and anyone self-hosting the open source edition has to confirm for themselves that the fix arrived.

FAQ

What is a REST API?
The entrance through which applications and external systems call the functions of a site, provided separately from the screens people use. Even where the screen side checks input carefully, a loose check on the API side becomes the route through.
What happens when a customer account is taken over?
The catalog goes as far as stating that takeover becomes possible. Accounts generally carry a name, address, order history and saved payment method.
Is the open source edition affected?
Yes. The record covers both Adobe Commerce and Magento Open Source.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Adobe#E-commerce#API
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.