We would like to bring your attention to the following 0-day exploit we have recently become aware of.
A zero day remote code-execution (RCE) bug in the Magento 2 and Adobe Commerce platforms has been discovered. This vulnerability has been seen to be actively exploited in the wild.
Affected Versions (Both eCommerce Platforms)
-
2.3.7-p2 and earlier
-
2.4.3-p1 and earlier
This vulnerability has been rated as 9.8 out of 10 on the CVSS vulnerability scale. The vulnerability is triggered by improper input validation during the checkout process.
To exploit the vulnerability in its present form, an attacker would need to have administrative privileges in order to be successful.
Remediation
Patches have been made available from Adobe Directly.
-
If you are running Magento 2.3 or 2.4, install the custom patch from Adobe.
-
If you are running a version of Magento 2 between 2.3.3 and 2.3.7, you should be able to manually apply the patch.
Versions of Magento 2.3.3 or below, are not directly vulnerable. However, it is advisable to apply this patch to ensure any future weaknesses identified are mitigated.
References:
Constant Cyber Attack: What People Keep Getting Wrong
There are a lot of terms floating around offensive security right now. COST. CTEM. Exposure validation. Some of it is useful. Most of it is new…
When “Just Logging In” Isn’t Just Logging In: A Lookat xrdp and CVE-2026-33145
A quiet finding with real-world impact. CVE-2026-33145 shows how xrdp’s AlternateShell feature, enabled by default, passes client-supplied input directly into a shell, turning an RDP login…
Mythos found a $20,000 bug. It won’t tell you who’s already inside.
Anthropic’s Mythos has dominated the security conversation this week. But the debate about whether it’s overhyped is the wrong argument. The real question is simpler and…