Critical Security Update for Magento Open Source & Adobe Commerce

Last week on August 8th, 2023, Adobe released a critical security patch for Adobe Commerce and the Magento Open Source CMS. The patch provides fixes for three vulnerabilities which affect the popular ecommerce platforms. Successful exploitation could lead to arbitrary code execution, privilege escalation and arbitrary file system read.

Affected versions of Magento Open Source are as follows:

  • 2.4.6-p1 and earlier
  • 2.4.5-p3 and earlier
  • 2.4.4-p4 and earlier

Website administrators are advised to update their software immediately to mitigate risk to their Magento and Adobe Commerce environments.

Continue reading Critical Security Update for Magento Open Source & Adobe Commerce at Sucuri Blog.

More great articles

Widespread Attacks Continue Targeting Vulnerabilities in The Plus Addons for Elementor Pro

Over the past 10 days, Wordfence has blocked over 14 million attacks targeting Privilege Escalation Vulnerabilities in The Plus Addons…

Read Story

Cross Site Scripting in YITH WooCommerce Ajax Product Filter

During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+…

Read Story

Over 8,000 Exploit Attempts Already Blocked For Recently Patched Unauthenticated Arbitrary File Upload Vulnerability in 简数采集器 (Keydatas) WordPress Plugin

On June 18th, 2024, during the 0-day Threat Hunt Promo of our Bug Bounty Program, we received a submission for…

Read Story

Emergency WordPress Help

One of our techs will get back to you within minutes.