Security News > 2021 > August > Adobe fixes critical preauth vulnerabilities in Magento
Adobe has released a large Patch Tuesday security update that fixes critical vulnerabilities in Magento and important bugs in Adobe Connect.
In total, Adobe fixed 29 vulnerabilities with today's updates.
Almost all Critical vulnerabilities could lead to arbitrary code execution, allowing threat actors to execute commands on vulnerable computers.
Out of the Adobe security updates released today, Magento has the most fixes, with 26 vulnerabilities.
Of particular concern are ten pre-authentication vulnerabilities in Magento that can be exploited without logging into the site.
Some of these preauth vulnerabilities are remote code execution and security bypasses, allowing a threat actor to control a site and it's server.
News URL
Related news
- Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit (source)
- Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks (source)
- Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited (source)
- HPE Issues Critical Security Patches for Aruba Access Point Vulnerabilities (source)
- Patch Tuesday: Four Critical Vulnerabilities Paved Over (source)
- Critical vulnerabilities persist in high-risk sectors (source)