Ecommerce Apocalypse: Adobe Commerce & Magento Users Ignore Critical Patch!

“CosmicSting, a critical vulnerability in Adobe Commerce and Magento, leaves millions of ecommerce sites exposed. Despite the high risk, about 75% of users haven’t patched. For a safer tomorrow, don’t delay—patch today!”

Hot Take:

Breaking news: Adobe Commerce and Magento users are like that one guy at a party who refuses to leave even after the lights come on. Despite a glaring ‘CosmicSting’ vulnerability, millions of sites are practically rolling out the red carpet for cybercriminals. Patch, people, patch!

Key Points:

  • A catastrophic vulnerability named “CosmicSting” (CVE-2024-34102) was found in Adobe Commerce and Magento.
  • The vulnerability allows unauthorized access to private files and remote code execution when combined with another Linux bug.
  • Despite being public for over a week, 75% of users have yet to apply the available patch.
  • Affected versions include Adobe Commerce 2.4.7 and earlier, Magento Open Source 2.4.7 and earlier, and specific Adobe Commerce Webhooks Plugin versions.
  • Mitigations are available for those unable to patch immediately, but prompt action is strongly recommended.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here