#AdobeCommerce

Christian Münchcmuench@phpc.social
2026-01-28

🎙️ Premiere! Florian Sydekum und ich starten unseren neuen Podcast: Commerce Champions.

Wir sprechen über Adobe Commerce, Magento Open Source und alles drumherum.

RSS Feed URL:

anchor.fm/s/10cb1ffa0/podcast/

#Magento #AdobeCommerce #Podcast

Christian Münchcmuench@phpc.social
2026-01-05

I just released the first update of the year for n98-magerun2. Version 9.2.1 is out now!

This release includes: ✨ A handy new feature 🐛 Three bugfixes

Update your tools and check the release notes here: magerun.net/release-9-2-0/

#Magento #AdobeCommerce #PHP #OpenSource

Christian Münchcmuench@phpc.social
2025-12-23

Next generation ...
Stay tuned!

#Magento #MageOS #AdobeCommerce

GitHub Repo Screenshot
Joseph Leedy :magento:JosephLeedy@phpc.social
2025-11-28

Rather than buying useless junk today, how about sponsoring your favorite open source projects?

(Or me at github.com/sponsors/JosephLeedy.)

#OpenSource #PHP #AdobeCommerce #Magento

Christian Münchcmuench@phpc.social
2025-11-21

Der 53. Magento Stammtisch Rhein-Main liegt hinter uns. 👋

Persönliche Treffen sind durch nichts zu ersetzen – besonders wenn es um technische Deep-Dives und den Austausch über das Ökosystem geht. Danke an alle, die dabei waren!

Wer wissen möchte, was besprochen wurde und wie mein Fazit ausfällt, findet hier meinen aktuellen Blogpost dazu:

📝 muench.dev/post/2025-11-rueckb

#Magento #AdobeCommerce #OpenSource #RheinMain #Stammtisch

Joseph Leedy :magento:JosephLeedy@phpc.social
2025-10-24

Today’s fun project was figuring out how tax calculation in #Magento works. After spelunking in the core code all day, I think I put something together that might work. I’ll know tomorrow after I write some integration tests for my logic. 🤞🏽

#AdobeCommerce #MageOS

Offensive Sequenceoffseq@infosec.exchange
2025-10-24

🚨 CRITICAL: CVE-2025-54236 'SessionReaper' in Adobe Commerce lets remote attackers hijack user sessions without authentication. No active exploits, but EU e-commerce at risk. Enforce strict session controls, monitor activity, prep for patch. radar.offseq.com/threat/fear-t #OffSeq #AdobeCommerce #vuln

Critical threat: Fear the 'SessionReaper': Adobe Commerce Flaw Under Attack
Offensive Sequenceoffseq@infosec.exchange
2025-10-23

🔥 SessionReaper (CVE-2025-54236) exploited in wild! 250+ Magento stores hit via Adobe Commerce REST API flaw—unauth RCE, webshells, account takeover. 62% still unpatched. Patch ASAP, audit uploads, monitor logs. radar.offseq.com/threat/over-2 #OffSeq #Magento #AdobeCommerce #Infosec

Critical threat: Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw
2025-10-22

A dangerous flaw in Adobe Commerce lets hackers hijack customer sessions with zero effort—and 60% of Magento stores are still unpatched. Is your business vulnerable?

thedefendopsdiaries.com/unders

#sessionreaper
#adobecommerce
#magento
#cve202554236
#ecommercesecurity

Ziffityziffity
2025-10-17

Magento Managed Services for the world's No. 1 cookie brand

Empowering the world’s No.1 cookie brand with 24/7 Magento Managed Services to ensure peak performance, security, and seamless customer experiences.

Watch here: go.screenpal.com/watch/cT6b6Rn

Maxsdigitmaxsdigit
2025-10-17

Exploring SEO Friendliness: Is Adobe Commerce Magento CMS SEO Friendly? - maxsdigitindia.com/is-adobe-co

Adobe Commerce is SEO-friendly by design, but it’s not “plug-and-play perfect.” Success depends on technical configuration, hosting performance, and ongoing optimization. With proper setup and maintenance, it can support high-ranking, traffic-driving e-commerce sites.

Ziffityziffity
2025-10-16

Discover how we helped a leading cannabis brand migrate seamlessly to Adobe Commerce, boosting performance, scalability, and customer experience.

Learn more: go.screenpal.com/watch/cT6DlYn

Joseph Leedy :magento:JosephLeedy@phpc.social
2025-10-01

Version 1.3.0 of Custom Fees for Magento 2 is now available! 🎉

New features include:

✅ Invoiced fees are now tracked for reporting
✅ Support for full or partial fee refunds
✅ The Ordered Fees Report now includes the invoiced and refunded fee amounts
✅ Fees can now be disabled or enabled as needed

github.com/JosephLeedy/magento

Like what you see? Give the extension a star on GitHub and help support development by becoming a sponsor!

github.com/sponsors/JosephLeedy

#AdobeCommerce #Magento #MageOS #PHP

Hostvixstacksize
2025-09-11

🚨 Critical Magento & Adobe Commerce Flaw (CVE-2025-54236 – SessionReaper) 🚨

Impact: Customer account takeover + unauthenticated remote code execution (CVSS 9.1 Critical).

👉 Full details and action steps: hostvix.com/sessionreaper-crit

:mastodon: deciodecio@infosec.exchange
2025-09-10

⚠️ si tu administres (ou sais que) ton site e-commerce tourne sur Magento / Adobe Commerce : c’est LE moment de le mettre à jour

Une faille critique baptisée SessionReaper (CVE-2025-54236) a été rendue publique. Elle permet à un attaquant, sans aucune authentification, de prendre le contrôle d’une boutique en ligne, d’accéder aux comptes clients… et dans certains cas d’exécuter du code à distance sur le serveur.
👉 En clair : risque important de vol d’infos de paiement, compromission massive de boutiques, déploiement de malwares.

Adobe a publié un patch d’urgence hors calendrier
👇
helpx.adobe.com/security/produ
⬇️
experienceleague.adobe.com/en/

Selon la société spécialisée Sansec:
« Cela n’aide pas que le patch Adobe ait fuité accidentellement la semaine dernière, donc il est possible que des acteurs malveillants travaillent déjà sur un code d’exploitation. »

(sansec.io/research/sessionreap)

Qui est concerné ?

  • Adobe Commerce (tous déploiements) : 2.4.9-alpha2 et toutes les versions antérieures jusqu’à 2.4.4-p15 inclus

  • Magento Open Source : mêmes versions affectées

  • Adobe Commerce B2B : 1.5.3-alpha2 et antérieures jusqu’à 1.3.3-p15 inclus

  • Module Custom Attributes Serializable : 0.1.0 → 0.4.0

Que faire ?

Appliquer dès que possible le patch 👉 Adobe APSB25-88

Tester vos personnalisations : ce correctif désactive certaines fonctions internes, certains modules tiers risquent de casser

Si vous ne pouvez patcher dans les prochaines heures → activez un WAF (Fastly ou Sansec Shield). Adobe a déjà poussé de nouvelles règles WAF côté Cloud.

⚡ L’historique montre que les failles Magento de ce type (Shoplift 2015, TrojanOrder 2022, CosmicSting 2024…) sont exploitées (en masse) très rapidement et récursivement.

( vulnerability.circl.lu/vuln/CV )

#Magento #CyberVeille #AdobeCommerce #Cyberveille #CVE_2025_54236

2025-09-09

Adobe Commerce is under threat—a new flaw, SessionReaper, lets hackers hijack live sessions like an open front door. Learn why immediate patching is crucial to keep your eCommerce safe.

thedefendopsdiaries.com/unders

#sessionreaper
#adobecommerce
#magento
#cybersecurity
#vulnerability

Joseph Leedy :magento:JosephLeedy@phpc.social
2025-09-09
Joseph Leedy :magento:JosephLeedy@phpc.social
2025-09-09

Additional information from Sansec, who has nicknamed this vulnerability "SessionReaper":

sansec.io/research/sessionreap

#AdobeCommerce #Magento #MageOS #Infosec #Security #SessionReaper

Joseph Leedy :magento:JosephLeedy@phpc.social
2025-09-09

🚨 A critical security patch was just released by Adobe for all Magento Open Source and Adobe Commerce versions lower than 2.4.9-alpha2! This hotfix patches a hole in the Web API processor that could allow a malicious actor to compromise and take over customer accounts using a specially crafted REST API request.

Don't delay—apply this patch before it's too late!

experienceleague.adobe.com/en/

#AdobeCommerce #Magento #MageOS #Infosec #Security

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst