logo

Active Exploitation Against Adobe Commerce and Magento Through CVE-2022-24086/CVE-2022-24087

ID: 97e327ec-9f35-57de-a141-9a6765803691

STIX ID: report--97e327ec-9f35-57de-a141-9a6765803691

Feed Name: FortiGuard Threat Signals

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-07-28

...
...

**Adobe/Magento critical RCE advisory:** FortiGuard Labs reports two critical improper-input-validation vulnerabilities (CVE-2022-24086 and CVE-2022-24087) in Adobe Commerce and Magento Open Source that allow remote code execution (CVSS 9.8). Adobe released patches (including an out-of-band fix for CVE-2022-24087) and FortiGuard notes active exploitation of CVE-2022-24086 in the wild; affected versions include 2.3.3-p1 through 2.3.7-p2 and 2.4.0 through 2.4.3-p1, and administrators must apply MDVA-43395 then MDVA-43443 to fully remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.