TrojanOrder
CVE-2022-24086 APSB22-12 Adobe Commerce / Magento 2.x CISA KEV 2022-02-15
If it is 2.4.3-p1 or earlier without the APSB22-12 patch, an unauthenticated template-injection leads to remote code execution. Verify the exact patch level.
Is my store affected?
A free passive scan tells you whether your store is on an affected line, along with everything else we can see from outside. It takes under a minute and needs no account.
How we detect this
We infer the platform and version line from signals the storefront serves publicly — the version endpoint when it is reachable, markup and cookie markers when it is not, and the fingerprints of static assets that changed between releases. If that line is one CVE-2022-24086 affects, we say so.
We do not attempt to exploit it, and we never claim a store is vulnerable from a version string alone. A patched store and an unpatched one on the same release look identical from outside, so the finding is marked inferred and phrased as something to verify. It does not affect your grade.
How to fix it
Apply Adobe's APSB22-12 patch, then rebuild. The fix is the patch; a full upgrade is optional on top of it.
-
1
See which patches the Quality Patches Tool offers for your exact version.
vendor/bin/magento-patches status
-
2
Apply the APSB22-12 patch, which covers CVE-2022-24086 and the follow-up CVE-2022-24087.
vendor/bin/magento-patches apply <patch-id> # or: patch -p1 < APSB22-12_2.4.x.patch
-
3
Rebuild so the patched code is compiled and served.
bin/magento setup:upgrade && bin/magento setup:di:compile && bin/magento setup:static-content:deploy -f && bin/magento cache:flush
-
4
This one was exploited at scale within days of disclosure. If the store was unpatched during that window, check for injected admin users, unexpected files under pub/ and var/, and modified .htaccess or index.php before assuming you were missed.
-
5
Optional, and separate from the fix: move to a patched release on your line. Use your edition's metapackage and the exact fixed version from the advisory.
composer require magento/product-<your-edition>-edition:<fixed-version> --no-update && composer update
vendor/bin/magento-patches status | grep -i 24086
References
We have a longer write-up on this one: TrojanOrder (CVE-2022-24086): how a checkout email became remote code execution.
From intelligence vault 2026.09.6, released 2026-09-25. What changed