CVE-2022-24086
critical-risk
Published 2022-02-16
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
Do I need to act?
!
93.6% chance of exploitation in next 30 days
EPSS score — higher than 6% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
+
Fix available
Upgrade to: f4c1d7526f05bdfb1327b0701cc345f94aadcaed, f4c1d7526f05bdfb1327b0701cc345f94aadcaed
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (10)
Affected Vendors
75
/ 100
critical-risk
Severity
32/34 · Critical
Exploitability
27/34 · High
Exposure
16/34 · Moderate