CVE-2024-20720Active Exploitation(adobe / commerce)

LOWCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for adobe commerce systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commerce

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
commerce

3 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-01: 1Active Exploitation · 2026-04-01: 104-01
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Magecart attackers exploited CVE-2024-20720 to inject e-skimmers into checkout pages, capturing payment data from 23M+ transactions. The malicious JavaScript operated with legitimate script privileges, enabling lateral movement across multiple e-commerce platforms. Runtime segmentation helps contain such cross-platform pivoting. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/magecart-e-skimmer-infections-2025

    Post summary

    The report confirms CVE‑2024‑20720 is actively exploited in the wild, with Magecart attackers injecting e‑skimmers that harvested over 23 million transactions.

    0000064
    1.9K followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.4--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.5--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--
Appadobecommerce2.4.6--

Explore more