logo

CosmicSting flaw impacts 75% of Adobe Commerce, Magento sites

ID: 62e5a9cc-2bda-566d-b830-39c08f1dc5a1

STIX ID: report--62e5a9cc-2bda-566d-b830-39c08f1dc5a1

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-06-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical vulnerability dubbed "CosmicSting" (CVE-2024-34102, CVSS 9.8) in Adobe Commerce and Magento enables XXE and potentially remote code execution when chained with a glibc/iconv bug; Sansec warns that roughly three out of four affected e-commerce sites remain unpatched, placing millions of stores at severe risk. Adobe has published fixes for multiple product lines and plugin versions, and Sansec and BleepingComputer publish mitigations and guidance (including a temporary PHP input filter and a glibc test) for administrators who cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.