Vulnerability record · CVE-2022-24086 · published 16 February 2022
CVE-2022-24086: Adobe Commerce and Magento improper input validation in checkout enables RCE
Adobe · Commerce
Adobe Commerce (2.4.3-p1 and earlier, 2.3.7-p2 and earlier) and Magento Open Source fail to properly validate input during the checkout process. The flaw allows unauthenticated remote code execution, making it a severe risk for internet-facing storefronts. It was added to CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.
Description
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing and near-certain EPSS probability makes this an urgent patch-first issue.
What it is
Adobe Commerce (2.4.3-p1 and earlier, 2.3.7-p2 and earlier) and Magento Open Source fail to properly validate input during the checkout process. The flaw allows unauthenticated remote code execution, making it a severe risk for internet-facing storefronts. It was added to CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.
Impact
An attacker can execute arbitrary code on the server, leading to full compromise of the e-commerce platform and any data or payment flows it handles. No privileges or user interaction are required.
Attack surface
Reachable over the network via the checkout process; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. Any exposed Adobe Commerce or Magento storefront with the affected versions is a candidate target.
Exploitation
Listed in CISA KEV with a due date of 2022-03-01, and EPSS 30-day probability is 0.99199 (99.9th percentile), indicating active exploitation is expected and observed. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor patch from Adobe security bulletin APSB22-12 immediately for all affected Commerce and Magento Open Source versions.
- If patching cannot be done at once, restrict or block external access to the checkout endpoint and apply virtual patching or WAF rules for the known exploit pattern.
- Audit the server for signs of compromise and rotate credentials, API keys and payment integration secrets after patching.
- Confirm no unsupported or end-of-life Commerce/Magento versions remain in the environment and upgrade them to a supported release.
Detection
- Monitor web server and application logs for anomalous POST requests to checkout endpoints, especially those containing serialized or template-like payloads.
- Alert on unexpected child processes spawned by the web/PHP process (for example shells, curl, wget) which may indicate post-exploitation.
- Review file integrity monitoring for new or modified PHP files under the web root and for unexpected outbound connections from the Commerce host.
- Correlate with CISA KEV guidance and check for known exploitation indicators published by Adobe and CISA.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-24086 to the Known Exploited Vulnerabilities catalog on 15 February 2022 as "Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 1 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/magento/apsb22-12.html | PatchRelease NotesVendor Advisory |
| https://helpx.adobe.com/security/products/magento/apsb22-12.html | PatchRelease NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24086 | Third Party AdvisoryUS Government Resource |
Track CVE-2022-24086 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24086), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.