CVE-2025-24423Active Exploitation(adobe / commerce_b2b)

MEDIUMCVSS 4.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch adobe commerce_b2b systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issue does not require user interaction.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • commerce_b2b

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
commerce_b2b

5 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Active Exploitation · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • 󠇯lucy@catboy1629
    Active Exploitation

    CISA added CVE-2025-24423 (SmarterMail RCE) to the KEV catalog this week. Federal agencies have until end of February to fix it. Quite a few on-prem mail servers are still exposed.

    Post summary

    CISA has listed CVE-2025-24423, a SmarterMail remote code execution flaw, in its KEV catalog, indicating active exploitation. Federal agencies have until the end of February to patch the exposed on‑prem mail servers.

    0000084
    215 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
Appadobecommerce_b2b---
Appadobecommerce_b2b1.3.3--
Appadobecommerce_b2b1.3.3--
Appadobecommerce_b2b1.3.3--
Appadobecommerce_b2b1.3.4--
Appadobecommerce_b2b1.3.4--
Appadobecommerce_b2b1.3.4--
Appadobecommerce_b2b1.3.5--
Appadobecommerce_b2b1.3.5--
Appadobecommerce_b2b1.3.5--
Appadobecommerce_b2b1.4.2--
Appadobecommerce_b2b1.4.2--
Appadobecommerce_b2b1.4.2--
Appadobecommerce_b2b1.4.2--
Appadobecommerce_b2b1.5.0--

Explore more