CVE-2022-24086

Adobe Magento Commerce

Published 16 Feb 2022 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, adobe.com

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 15 Feb 2022, with a remediation deadline of 1 Mar 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

References