EXPOSURES › CVE-2022-24086
CVE-2022-24086
HIGH ⌖ ON CISA KEV · EXPLOITEDImproper input validation in Adobe Commerce and Magento Open Source allowed arbitrary code execution.
The vulnerability in Adobe Commerce and Magento Open Source stemmed from improper input validation, enabling attackers to execute arbitrary code on affected systems. For DIB organizations, this represents a severe compliance impact as it directly violates CMMC/NIST 800-171 requirements for preventing unauthorized access and ensuring system integrity. Organizations must immediately patch this vulnerability and assess their exposure to similar unpatched flaws in their supply chain.
Shame score — A critical unpatched vulnerability allowing arbitrary code execution in a widely used e-commerce platform demonstrates severe negligence and exposes countless organizations to data breaches and ransomware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |