CVE-2022-24086Patch(adobe / commerce)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch adobe commerce systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

2.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-01. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commerce
  • magento

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
commercemagento

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Vulnerability Research Labs@vulnresearchlab
    Patch

    The checkout process is where an e-commerce platform must be most careful. An input validation flaw in Magento's, CVE-2022-24086, allowed for arbitrary code execution. We reproduced the public vulnerability and verified the fix.

    Post summary

    The text confirms Magento CVE-2022-24086, demonstrates the flaw, and verifies the vendor’s patch.

    0000033
    8 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecommerce---
Appadobecommerce2.3.7--
Appadobecommerce2.3.7--
Appadobecommerce2.4.3--
Appadobecommerce2.4.3--
Appadobemagento---
Appadobemagento2.3.7--
Appadobemagento2.3.7--
Appadobemagento2.4.3--
Appadobemagento2.4.3--

Explore more