CVE 2025-54236 for Magento

Incident Report for Server Status | Nexcess

Update

Our team is actively involved in applying the necessary security patches across all affected Magento environments as part of the ongoing remediation for CVE-2025-54236.

Patch deployment is continuing in a phased and controlled manner to ensure a smooth rollout and maintain platform stability. We are closely monitoring all systems during this process to confirm successful application and verify that no customer impact occurs.

Further updates will be provided as progress continues.
Posted Oct 25, 2025 - 11:42 EDT

Identified

We are currently deploying a security patch across our Magento environments to remediate CVE-2025-54236, a critical vulnerability disclosed by Adobe affecting Magento Open Source and Adobe Commerce installations.

This proactive maintenance is being conducted to safeguard customer data, prevent potential exploitation, and ensure the continued integrity and stability of our eCommerce infrastructure. Patch deployment is progressing in phases across our fleet to minimize any potential service impact.

No customer downtime is expected during this process

For additional details regarding this vulnerability, please refer to Adobe’s official security advisory: https://helpx.adobe.com/security/products/magento/apsb25-88.html
Posted Oct 24, 2025 - 16:18 EDT
This incident affects: Platform Operations (Platform Updates / Other).