← Vulnerability feed

Vulnerability record · CVE-2016-4010 · published 23 January 2017

CVE-2016-4010: Magento PHP object injection in shopping cart data enables RCE

MMagento · Magento

Magento CE and EE before 2.0.6 unserialize crafted shopping cart data without adequate validation, allowing PHP object injection. An attacker can chain that injection into arbitrary PHP code execution on the server. The flaw is remotely reachable and needs no credentials, so any exposed storefront is a candidate target.

9.8 CVSS 3.0 Critical EPSS 93% · top 0.2% CWE-74 · Injection
9.8CVSS 3.0 base score, v2 7.5
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, very high EPSS and public exploit code makes this an urgent patch target.

What it is

Magento CE and EE before 2.0.6 unserialize crafted shopping cart data without adequate validation, allowing PHP object injection. An attacker can chain that injection into arbitrary PHP code execution on the server. The flaw is remotely reachable and needs no credentials, so any exposed storefront is a candidate target.

Impact

An attacker gains remote code execution on the Magento host, which typically means full control of the application, its data and the underlying server. That can expose customer records, payment data and administrative access.

Attack surface

Reached over the network through crafted serialized shopping cart data submitted to the storefront; the CVSS vector shows no privileges and no user interaction required. No authentication is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.92869 (99.8th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, indicating public exploit code exists.

What to do

  • Upgrade Magento CE/EE to 2.0.6 or later, or apply the vendor security patch referenced in the Magento advisory.
  • If immediate patching is not possible, restrict or block untrusted serialized input reaching cart handling code and tighten WAF rules around cart endpoints.
  • Remove or harden any unused cart, API or admin endpoints exposed to the internet.
  • Rotate credentials and secrets stored on the Magento host if compromise is suspected, and review file integrity on the web root.

Detection

  • Monitor web logs for POST requests to cart endpoints carrying serialized PHP object payloads (O: or a: patterns) or unusually long encoded parameters.
  • Alert on unexpected PHP file creation or modification under the Magento web root, which is consistent with the arbitrary file write described in public exploit write-ups.
  • Watch for outbound connections or child processes spawned by the web server user that are not normal for Magento.
  • Correlate requests from a single source hitting cart endpoints repeatedly with malformed or oversized payloads.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34256Adobe commerce improper authorization vulnerabilityAdobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit…EPSS 2.1%9.8CVE-2020-9664Magento deserialization of untrusted data vulnerabilityMagento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbit…EPSS 8.4%9.8CVE-2020-9583Magento command injection vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…EPSS 5.7%9.8CVE-2020-9585Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a defense-in-depth security mit…EPSS 4.9%9.8CVE-2020-9630Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerab…EPSS 4.0%9.8CVE-2020-9631Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…EPSS 7.4%9.8CVE-2020-9632Magento vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vu…EPSS 7.4%9.8CVE-2020-9576Magento command injection vulnerabilityMagento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerabili…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2016-4010), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.