Adobe Releases Additional Security Updates for Commerce and Magento Open Source
Exploitation in the wild found for existing vulnerability and another Critical RCE vulnerability has been added to the Adobe security advisory.
Summary
Exploitation in the wild found for existing vulnerability and another Critical RCE vulnerability has been added to the Adobe security advisory.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Adobe has released security updates to address vulnerabilities in multiple Adobe products. Both CVE-2022-24086 and CVE-2022-24087 are rated Critical by Adobe, each rating 9.8 on CVSSv3 scoring system. A remote, unauthenticated attacker could exploit these vulnerabilities to take control of an affected system.
Exploitation
Adobe has reported that there has been exploitation in the wild for the vulnerability known as CVE-2022-24086.
Remediation advice
Affected organisations are encouraged to review the following Adobe security bulletin and apply relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Adobe Commerce | APSB22-12 https://helpx.adobe.com/security/products/magento/apsb22-12.html |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 February 2022 1:23 pm