Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CVE-2022-24086
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2022-02-15), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EPSS
- 99.9%
- KEV
- ⚠ Exploited
Published
February 16, 2022
Last Modified
October 23, 2025
Advisory Details (1)
Auto-updated Jun 1, 2026Known Exploited Vulnerabilities Catalog | CISA
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24086Affected Packages
(1 across 1 ecosystem)
Packagist(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| magento/community-edition | 2.4.0 ... 2.4.3-p1 (9 versions) | 2.4.3-p2 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 7× in last 7d / 23× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-21 17:56 UTCEG score recompute
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-17 08:26 UTCEG score recompute
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-09 19:07 UTCEPSS rescore
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-01 19:16 UTCCISA KEV update
- 2026-06-29 19:12 UTCCISA KEV update
- 2026-06-25 19:15 UTCCISA KEV update
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-24 14:03 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 17:44 UTCCISA KEV update
- 2026-06-18 16:13 UTCCISA KEV update
- 2026-06-17 17:51 UTCEPSS rescore
Show 32 moreShow fewer
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-16 19:33 UTCCISA KEV update
- 2026-06-15 19:33 UTCCISA KEV update
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-12 17:35 UTCCISA KEV update
- 2026-06-11 19:10 UTCCISA KEV update
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-09 18:42 UTCCISA KEV update
- 2026-06-09 17:12 UTCCISA KEV update
- 2026-06-08 19:16 UTCCISA KEV update
- 2026-06-08 17:26 UTCCISA KEV update
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-05 22:43 UTCCISA KEV update
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-03 19:09 UTCCISA KEV update
- 2026-06-02 18:32 UTCCISA KEV update
- 2026-06-01 20:42 UTCCISA KEV update
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-29 22:20 UTCCISA KEV update
- 2026-05-29 13:42 UTCEPSS rescore
- 2026-05-27 20:35 UTCCISA KEV update
- 2026-05-26 19:13 UTCCISA KEV update
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 02:56 UTCEG score recompute
Publicly available exploits
(6 references)Working exploit code is in the public domain (5 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCpescepilota/CVE-2022-24086First seen Dec 20, 2022
Proof of concept of CVE-2022-24086
Open source ↗ - GitHub PoCakr3ch/CVE-2022-24086First seen Oct 1, 2022
PoC of CVE-2022-24086
Open source ↗ - Open source ↗GitHub PoCseymanurmutlu/CVE-2022-24086-CVE-2022-24087First seen Jun 12, 2022
- GitHub PoCoK0mo/CVE-2022-24086-RCE-PoCFirst seen May 19, 2022
Verifed Proof of Concept on CVE-2022-24086
Open source ↗ - GitHub PoCMr-xn/CVE-2022-24086First seen Feb 20, 2022
CVE-2022-24086 about Magento RCE
Open source ↗ - Nucleihttp/cves/2022/CVE-2022-24086.yamlFirst seen Jan 1, 2022
Adobe Commerce (Magento) - Remote Code Execution
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-20
- CVE-2002-2444EG 9.8CRITICAL
- CVE-2005-0116NVD 0.0EG 9.0EPSS 99%NONE
- CVE-2002-1359NVD 0.0EG 9.0EPSS 100%NONE
- CVE-2000-0380NVD 0.0EG 9.0EPSS 98%NONE
- CVE-2000-0258EG 7.5EPSS 97%HIGH
- CVE-2004-2771EG 0.0EPSS 93%NONE
- CVE-2002-2443EG 0.0EPSS 93%NONE
- CVE-2002-2433EG 0.0NONE
- CVE-2003-1569EG 0.0NONE
- CVE-2003-1568EG 0.0NONE
Frequently asked(6)
What is CVE-2022-24086?
When was CVE-2022-24086 disclosed?
Is CVE-2022-24086 actively exploited?
What is the CVSS score of CVE-2022-24086?
Which products are affected by CVE-2022-24086?
How do I remediate CVE-2022-24086?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-24086
Is Your Infrastructure Affected by CVE-2022-24086?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.