ID:12539 - Exploit for Input validation error in Adobe products - CVE-2025-54236
Published: April 1, 2026
Adobe Commerce (formerly Magento Commerce)
Adobe Commerce B2B
Magento Open Source
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote non-authenticated attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Remediation
Install a hotfix from vendor's website:
https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397