Security News > 2022 > February > Emergency Magento update fixes zero-day bug exploited in attacks

Adobe rolled out emergency updates for Adobe?Commerce and?Magento Open Source to fix a critical vulnerability tracked as CVE-2022-24086 that's being exploited in the wild.
Administrators of online stores running Adobe Commerce or Magento Open Source versions 2.4.3-p1/2.3.7-p2 and below are strongly advised to prioritize addressing CVE-2022-24086 and apply the update as soon as possible.
On Sunday, Adobe published an out-of-band security bulletin warning that threat actors are exploiting CVE-2022-24086 "In the wild in very limited attacks targeting Adobe Commerce merchants."
Sansec, a company offering eCommerce malware and vulnerability detection services, stresses that stores running Magento 2.3 or 2.4 should install the custom patch from Adobe immediately, "Ideally within the next few hours."
"If you are running Magento 2.3.3 or below, you are not directly vulnerable. However, Sansec still recommends to manually implement the given patch" - Sansec.
The company warns that failing to apply the patch can have severe consequences, similar to the 2015 critical bug Magento Shoplift, discovered by security researchers at cybersecurity company Check Point.
News URL
Related news
- Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks (source)
- Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks (source)
- EncryptHub linked to MMC zero-day attacks on Windows systems (source)
- Zero-Day Alert: Google Releases Chrome Patch for Exploit Used in Russian Espionage Attacks (source)
- Google fixes Android zero-days exploited in attacks, 60 other flaws (source)
- Apple fixes two zero-days exploited in targeted iPhone attacks (source)
- Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201) (source)
- Apple Patches Two Zero-Days Used in ‘Extremely Sophisticated’ Attacks (source)
- Phishing detection is broken: Why most attacks feel like a zero day (source)
- DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-16 | CVE-2022-24086 | Improper Input Validation vulnerability in multiple products Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. | 0.0 |