← Vulnerability feed

Vulnerability record · CVE-2022-24086 · published 16 February 2022

CVE-2022-24086: Adobe Commerce and Magento improper input validation in checkout enables RCE

Adobe · Commerce

Adobe Commerce (2.4.3-p1 and earlier, 2.3.7-p2 and earlier) and Magento Open Source fail to properly validate input during the checkout process. The flaw allows unauthenticated remote code execution, making it a severe risk for internet-facing storefronts. It was added to CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

9.8 CVSS 3.1 Critical CISA KEV since 15 Feb 2022 EPSS 99% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score, KEV listing and near-certain EPSS probability makes this an urgent patch-first issue.

What it is

Adobe Commerce (2.4.3-p1 and earlier, 2.3.7-p2 and earlier) and Magento Open Source fail to properly validate input during the checkout process. The flaw allows unauthenticated remote code execution, making it a severe risk for internet-facing storefronts. It was added to CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

Impact

An attacker can execute arbitrary code on the server, leading to full compromise of the e-commerce platform and any data or payment flows it handles. No privileges or user interaction are required.

Attack surface

Reachable over the network via the checkout process; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. Any exposed Adobe Commerce or Magento storefront with the affected versions is a candidate target.

Exploitation

Listed in CISA KEV with a due date of 2022-03-01, and EPSS 30-day probability is 0.99199 (99.9th percentile), indicating active exploitation is expected and observed. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor patch from Adobe security bulletin APSB22-12 immediately for all affected Commerce and Magento Open Source versions.
  • If patching cannot be done at once, restrict or block external access to the checkout endpoint and apply virtual patching or WAF rules for the known exploit pattern.
  • Audit the server for signs of compromise and rotate credentials, API keys and payment integration secrets after patching.
  • Confirm no unsupported or end-of-life Commerce/Magento versions remain in the environment and upgrade them to a supported release.

Detection

  • Monitor web server and application logs for anomalous POST requests to checkout endpoints, especially those containing serialized or template-like payloads.
  • Alert on unexpected child processes spawned by the web/PHP process (for example shells, curl, wget) which may indicate post-exploitation.
  • Review file integrity monitoring for new or modified PHP files under the web root and for unexpected outbound connections from the Commerce host.
  • Correlate with CISA KEV guidance and check for known exploitation indicators published by Adobe and CISA.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-24086 to the Known Exploited Vulnerabilities catalog on 15 February 2022 as "Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 1 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24086 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-75650Adobe Commerce template engine flaw allows unauthenticated remote code executionAdobe Commerce, Commerce B2B and Magento are affected by improper neutralization of special elements used in a template engine (CWE-1336), allowing a…KEVEPSS 3.9%analysed9.8CVE-2024-34102Adobe Commerce and Magento XXE flaw allows unauthenticated code executionAdobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML do…KEVEPSS 100%analysed9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%9.1CVE-2025-54236Adobe Commerce improper input validation enables session takeoverAdobe Commerce and Magento are affected by improper input validation (CWE-20) across multiple 2.4.x branches and earlier. A remote, unauthenticated a…KEVEPSS 95%analysed9.8CVE-2024-45115Adobe commerce improper authentication vulnerabilityAdobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul…EPSS 1.3%9.8CVE-2024-34107Adobe commerce improper access control vulnerabilityAdobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in…EPSS 1.1%9.8CVE-2022-34256Adobe commerce improper authorization vulnerabilityAdobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit…EPSS 2.1%9.3CVE-2026-76200Adobe magento cross-site scripting vulnerabilityAdobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into …EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2022-24086), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.