IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Adobe forced to patch its own failed security update

Company issues new fix for e-commerce vulnerability after researchers bypass the original update

An image of a building with the Adobe sign on the side, shot from below

Adobe has had to issue another software update after an out-of-band patch failed to fix a vulnerability in its e-commerce software.

Last weekend, the company released an out-of-band patch to fix a vulnerability in its Adobe Commerce and Magento Open Source e-commerce products.

The CVE-2022-24086 input validation bug allowed attackers to run their own code on e-commerce sites, making them vulnerable to cart skimmers. The company said that the attack had been exploited in the wild.

Adobe credited the new discovery to one of the bug researchers that found the original vulnerability. The researcher from security company Bugscale, who uses the Twitter handle @Blaklis, warned about Adobe's first patch on Twitter. "THIS IS NOT SUFFICIENT to be safe," they said, adding a comment that hinted at the cause of the problem: "take care of json/url encoded values".

Researchers at security company Positive Technologies also warned that they had bypassed the initial patch to exploit the vulnerability again. "We weren't the first," they added.

The additional research created a new vulnerability ID, CVE-2022-24087. It mirrors the first bug's 9.8 (critical) rating. Adobe released a fix for the bug, which customers must apply on top of the first patch.

This isn't the first critical vulnerability that Adobe has had to patch lately. Earlier this month it issued a patch for a critical bug, CVE-2022-23202, that enabled attackers to execute their own code in its Creative Cloud Desktop application.

It also patched an arbitrary code execution bug in Adobe After Effects, and another in Photoshop.

Featured Resources

Activation playbook: Deliver data that powers impactful, game-changing campaigns

Bringing together data and technology to drive better business outcomes

Free Download

In unpredictable times, a data strategy is key

Data processes are crucial to guide decisions and drive business growth

Free Download

Achieving resiliency with Everything-as-a-Service (XAAS)

Transforming the enterprise IT landscape

Free Download

What is contextual analytics?

Creating more customer value in HR software applications

Free Download

Recommended

Adobe rolls out new PayPal payment options through Adobe Commerce
e commerce

Adobe rolls out new PayPal payment options through Adobe Commerce

16 Sep 2021
Signs it’s time to upgrade your CMS
Whitepaper

Signs it’s time to upgrade your CMS

23 Aug 2021
Engaging the new digital workforce blueprint
Whitepaper

Engaging the new digital workforce blueprint

23 Aug 2021
Delivering personalised content for dummies
Whitepaper

Delivering personalised content for dummies

23 Aug 2021

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers
ransomware

Linux-based Cheerscrypt ransomware found targeting VMware ESXi servers

26 May 2022
Open source packages with millions of installs hacked to harvest AWS credentials
hacking

Open source packages with millions of installs hacked to harvest AWS credentials

24 May 2022