Skip to content
COOEY

EXPOSURES › CVE-2022-24086

CVE-2022-24086

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-24086 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

Improper input validation in Adobe Commerce and Magento Open Source allowed arbitrary code execution.

The vulnerability in Adobe Commerce and Magento Open Source stemmed from improper input validation, enabling attackers to execute arbitrary code on affected systems. For DIB organizations, this represents a severe compliance impact as it directly violates CMMC/NIST 800-171 requirements for preventing unauthorized access and ensuring system integrity. Organizations must immediately patch this vulnerability and assess their exposure to similar unpatched flaws in their supply chain.

Shame score — A critical unpatched vulnerability allowing arbitrary code execution in a widely used e-commerce platform demonstrates severe negligence and exposes countless organizations to data breaches and ransomware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized