Adobe disclosed in a security advisory yesterday that its e-commerce storefront solutions, Adobe Commerce and Magento, has a critical vulnerability that can be exploited to achieve arbitrary remote code execution. The vulnerability is being tracked as CVE-2022-24086. The company announced in its security advisory that “CVE-2022-24086 has been exploited in the wild in very limited attacks targeting Adobe Commerce merchants.” The vulnerability was assigned a CVSS score of 9.8/10.
Affected versions are currently listed as all versions above 2.3.3 as per the security advisory:
