ZeroHour

CVE-2026-34648

mass

Unauthenticated Resource-Exhaustion DoS in Adobe Commerce and Magento

CVSS 3.1
7.5 high
EPSS
23%p98
Published
()
Modified
AI analysis

Adobe Commerce and Magento Open Source are affected by an uncontrolled resource consumption flaw (CWE-400) that allows an unauthenticated remote attacker to exhaust system resources and cause an application denial-of-service. The flaw is reachable over the network with no privileges and no user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and yields high availability impact with no confidentiality or integrity impact. Attackers can trigger it directly against internet-facing storefronts, degrading or taking the shop offline. It affects Adobe Commerce, Adobe Commerce B2B, and Magento across the 2.4.4 through 2.4.9 release lines up to the patch levels listed in the advisory (2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, 2.4.9-beta1 and earlier). No exploitation is confirmed in the wild and no public proof-of-concept is known, but the 22.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

What to do: Upgrade every affected 2.4.x line to the first patched release beyond the listed patch levels (i.e., past 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, and 2.4.8-p4, and move off 2.4.9-beta1) per Adobe's security bulletin, and verify installed versions via composer/composer.lock. Until patched, apply rate limiting or WAF throttling on unauthenticated storefront endpoints and monitor CPU/memory for resource-exhaustion patterns. Given the 98th-percentile EPSS, prioritize this patch in the next maintenance window.

Affected
Adobe Commerce2.4.9-beta1 and earlier (2.4.9 line); 2.4.8 through 2.4.8-p4; 2.4.7 through 2.4.7-p9; 2.4.6 through 2.4.6-p14; 2.4.5 through 2.4.5-p16; 2.4.4 through 2.4.4-p17
Adobe Commerce B2B2.4.x lines listed for Adobe Commerce per the Adobe CPE (2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, 2.4.9-beta1 and earlier)
Adobe Magento (Open Source)2.4.9-beta1 and earlier (2.4.9 line); 2.4.8 through 2.4.8-p4; 2.4.7 through 2.4.7-p9; 2.4.6 through 2.4.6-p14; 2.4.5 through 2.4.5-p16; 2.4.4 through 2.4.4-p17
Estimated exposure
mass≈100,000–300,000 online storefronts (Magento 2/Adobe Commerce install base per public web-technology surveys) — Public web-technology surveys (e.g., BuiltWith) place Magento 2/Adobe Commerce on the order of 10^5 live e-commerce sites, and these storefronts are by definition internet-exposed, so plausibly more than 100,000 affected installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.