CVE-2022-24086
Adobe Magento Commerce
Published 16 Feb 2022 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, adobe.com
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 15 Feb 2022, with a remediation deadline of 1 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
References
- helpx.adobe.com/security/products/magento/apsb22-12.html · Patch, Release Notes, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24086 · Third Party Advisory, US Government Resource