ZeroHour
Sansec (Magento / e-commerce security)published ()ingested Sansec Forensics Team

Magento 2 critical vulnerability (CVE-2022-24086 & CVE-2022

criticalVulnerability exploited in the wildimportance 60CVE-2022-24086CVE-2026-75650CVE-2025-54236

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-24086
Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento

Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks.

Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise.

9.899% KEV
  • Adobe Commerce 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
  • Adobe Magento Open Source 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms)
CVE-2025-54236
Unauthenticated Session Takeover in Adobe Commerce and Magento (SessionReaper)

Adobe Commerce and Magento Open Source contain an improper input validation flaw (CWE-20), widely tracked as 'SessionReaper', that lets a remote, unauthenticated attacker take over user sessions. The flaw is exploitable over the network with no privileges and no user interaction (CVSS 3.1 9.1, critical). A successful attacker hijacks legitimate customer or admin sessions, yielding high confidentiality and integrity impact; a public writeup additionally describes unauthenticated exploitation potentially reaching code execution. Anyone running Adobe Commerce (including Commerce B2B) or Magento Open Source on the affected 2.4.x releases is exposed. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2025-10-24, reporting headlines cite over 250 observed attacks, EPSS is 94.5%, and roughly 3 in 5 stores were reported as still unpatched.

Do: Immediately upgrade every affected 2.4.x line to a release newer than 2.4.9-alpha2/2.4.8-p2/2.4.7-p7/2.4.6-p12/2.4.5-p14/2.4.4-p15 per Adobe's security advisory. Because the flaw is on CISA's KEV list, federal agencies must apply the vendor's mitigations (or BOD 22-01 cloud guidance) or discontinue use; other defenders should prioritize patching given 250+ observed attacks and 94.5% EPSS. Until patched, watch for indicators of session takeover — unexpected customer or admin sessions, unfamiliar admin accounts, and anomalous session activity — and review Adobe's advisory for interim mitigations.

9.195% KEV PoC
  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier (all listed 2.4.x lines and older releases)
  • Adobe Commerce B2B Listed via CPE as affected alongside Adobe Commerce; no separate version range given in the source data — treat B2B deployments on the affected Commerce 2.4.x l
  • Adobe Magento Open Source (Magento) 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
mass≈100,000+ internet-facing Adobe Commerce/Magento storefronts (order of magnitude 10^5)
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts
Full article425 words · extracted from sansec.io · click to collapse

Update Feb 21st, 2022: Sansec has observed the first actual attacks in the wild. Patch now! Unfortunately, this validates our previous prediction that abuse would start within days. Attacks are coming from 45.134.20.11 and target a variety of URL endpoints, making it harder to add protection via a WAF/firewall. Magento 2 merchants should really patch now.

Update Feb 17th, 2022: Adobe has released another emergency patch. Merchants running Magento 2.3.3 and above need to urgently apply both patches:

  • MDVA-43395 (Feb 13th)
  • MDVA-43443 (Feb 17th)

The text below has been updated.

How to fix Trojanorder?

If you are running Magento 2.3 or 2.4, install both patches from Adobe asap, ideally within the next few hours.

If you are running a version of Magento 2 between 2.3.3 and 2.3.7, you should be able to manually apply the patches as it only concerns a few lines.

If you are running Magento 2.3.3 or below, you are not directly vulnerable. However, Sansec still recommends to manually implement the patches (at the very least the code changes that affect vendor/magento/module-email/Model/Template/Filter.php).

For anyone using vaimo/composer-patches, you can apply the patch file across magento/framework and magento/module-email like this (credits Luke Rodgers), it will apply both patches in the correct order.

        "patches": {
            "*": {
                "Apply MDVA-43395": {
                    "source": "patches/magento/MDVA-43395_EE_2.4.3-p1_COMPOSER_v1.patch",
                    "targets": [
                        "magento/framework",
                        "magento/module-email"
                    ]
                },
                "Apply MDVA-43443": {
                    "source": "patches/magento/MDVA-43443_EE_2.4.2-p2_COMPOSER_v1.patch",
                    "targets": [
                        "magento/framework",
                        "magento/module-email"
                     ],
                     "after": "MDVA-43395_EE_2.4.3-p1_COMPOSER_v1.patch"
                }
            },

More detailed guides on how to implement these patches using composer:

Hot fix measures for ISPs

Due to the dynamic nature of the vulnerability, there is currently no method to filter on this attack pattern via a proxy or webserver. In order to identify attack probes, you could log HTTP POST requests with the following in the body. It may produce false positives so should be manually examined.

{{ .... }}

Implications

These vulnerabilities have a similar severity as the Magento Shoplift vulnerability from 2015. At that time, nearly all unpatched Magento stores globally were compromised in the days after the exploit publication.

We strongly recommend merchants to implement counter measures today. Our eComscan security monitor will alert you about any unpatched or incorrectly patched installations.

References

Read more

Text extracted automatically; images, tables and formatting may be missing. Original: https://sansec.io/research/magento-2-cve-2022-24086