Adobe has released a patch for a critical Remote Code Execution vulnerability that affects the Magento and Adobe Commerce eCommerce platforms.
The CVSS 9.8 critical rated vulnerability (CVE-2022-24086) has, according to Adobe, been observed to be exploited in the wild and threat actors can use it to achieve arbitrary code execution on the target e-commerce web server.
To exploit this Improper Input Validation vulnerability the threat actor does not need a valid login – neither authentication or admin privileges are needed to be able to run arbitrary code on the target system.
The affected versions of Magento are: 2.4.3-p1 and earlier and 2.3.7-p2 and earlier of both the Adobe Commerce and Magento Open Source products.
CISA has added this vulnerability to their Known Exploited Vulnerabilities list and has mandated that federal organisations in the USA must apply the patch no later than 1st March 2022.
“We were very impressed with the service, I will say, the vulnerability found was one our previous organisation had not picked up, which does make you wonder if anything else was missed.”
Aim Ltd Chief Technology Officer (CTO)