Security News > 2022 > February > New Critical RCE Bug Found in Adobe Commerce, Magento
Another zero-day bug has been discovered in the Magento Open Source and Adobe Commerce platforms, while researchers have created a working proof-of-concept exploit for the recently patched CVE-2022-24086 vulnerability that came under active attack and forced Adobe to push out an emergency patch last weekend.
The new flaw, detailed on Thursday, has the same level of severity assigned to its predecessor, which Adobe patched on Feb. 13.
While the company is aware of "Very limited attacks" on Adobe Commerce merchants that have targeted the CVE-2022-24086 flaw, the company said that it's unaware of any exploits in the wild for CVE-2022-24087.
We have reproduced the fresh CVE-2022-24086 Improper Input Validation vulnerability in Magento Open Source and Adobe Commerce.
Blaklis said in a tweet that the first patch to resolve CVE-2022-24086 is "NOT SUFFICIENT" to be safe, urging Magento & Commerce users to update again.
A new patch have been published for Magento 2, to mitigate the pre-authenticated remote code execution.
News URL
https://threatpost.com/new-critical-rce-bug-found-in-adobe-commerce-magento/178554/
Related news
- SolarWinds fixes critical RCE bug affecting all Web Help Desk versions (source)
- Critical RCE bug in SolarWinds Web Help Desk fixed (CVE-2024-28986) (source)
- CISA warns critical SolarWinds RCE bug is exploited in attacks (source)
- Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE (source)
- Veeam warns of critical RCE flaw in Backup & Replication software (source)
- Apache OFBiz team patches critical RCE vulnerability (CVE-2024-45195) (source)
- D-Link fixes critical RCE, hardcoded password flaws in WiFi 6 routers (source)
- Exploit code released for critical Ivanti RCE flaw, patch now (source)
- SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks (source)
- Broadcom fixes critical RCE bug in VMware vCenter Server (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-16 | CVE-2022-24086 | Improper Input Validation vulnerability in multiple products Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. | 10.0 |