Ecommerce sites across the world could be at risk from this dangerous security flaw, so patch now
A catastrophic vulnerability was recently discovered in Adobe Commerce and Magento, but ecommerce websites operating these platforms seem largely uninterested in applying a patch.
As a result, “millions” of sites are open to attacks that could have devastating consequences, experts have warned.
As reported by BleepingComputer, cybersecurity researchers from Sansec discovered an improper restriction of XML external entity reference (‘XXE’) vulnerability, and dubbed it “CosmicSting”. It is now being tracked as CVE-2024-34102, and carries a severity score of 9.8 (critical).
Patch and mitigations
“CosmicSting (aka CVE-2024-34102) is the worst bug to hit Magento and Adobe Commerce stores in two years,” Sansec said in a security advisory. “In itself, it allows anyone to read private files (such as those with passwords). However, combined with the recent iconv bug in Linux, it turns into the security nightmare of remote code execution.”
Here are the product versions affected by CosmicSting:
- Adobe Commerce 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
- Adobe Commerce Extended Support 2.4.3-ext-7 and earlier, 2.4.2-ext-7 and earlier, 2.4.1-ext-7 and earlier, 2.4.0-ext-7 and earlier, 2.3.7-p4-ext-7 and earlier.
- Magento Open Source 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
- Adobe Commerce Webhooks Plugin versions 1.2.0 to 1.4.0
If your business is running any of the above, make sure to apply the patch – which was already made available – as soon as possible.
Sansec says that despite the vulnerability being made public more than a week ago, some 75% of Adobe Commerce and Magento users are yet to patch up. There is currently no evidence of in-the-wild abuse, and Adobe did not publish technical details so at to not give hackers any hints. However, Sansec says that the patch can be reverse-engineered and used to learn more about the bug.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Those who are unable to apply the patch immediately are advised to apply the mitigations found on this link.
More from TechRadar Pro
A catastrophic vulnerability was recently discovered in Adobe Commerce and Magento, but ecommerce websites operating these platforms seem largely uninterested in applying a patch. As a result, “millions” of sites are open to attacks that could have devastating consequences, experts have warned. As reported by BleepingComputer, cybersecurity researchers from Sansec…
Recent Posts
- ‘A masterclass in sensor-to-shooter kill chain management’: Blackhawk Company commander explains what he learned from controversial US-Ukraine ‘drone-first’ wargame
- ‘It’s not unlike what they’re using at their own house for video games’: US Army budgets $465 million for Group 3 Killer anti-drone laser which uses Xbox controller
- What are the major changes coming to Apple HomeKit in iOS 27?
- 69% of Americans oppose local AI data centers in 2026 poll — Trump blasts blocking communities on Truth Social for choosing poverty over server farms, throwing off ‘tremendous amounts of money’
- Is there any benefit to restarting your PC regularly?
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023