Adobe has released a series of out-of-band security to updates fix important issues in the Magento platform.

The updates were released on October 15 and are not part of Adobe's regular monthly patch schedule. The updates fix nine vulnerabilities, eight of which are rated critical or serious. The last bug is rated moderate.
The vulnerabilities affect Magento Commerce and Magento Open Source, versions 2.3.5-p1, 2.4.0 and earlier.
The most critical vulnerabilities in the Adobe Magento platform, which have now been resolved with the new updates, are known as CVE-2020-24407 and CVE-2020-24400. The vulnerabilities allow code execution or database access bothcases, an attacker would first need to gain administrator privileges to be able to exploit the vulnerabilities.
Additionally, Adobe addressed another vulnerability (CVE-2020-24402), which allows attackers to manipulate and modify customer lists.
According to ZDNet, other vulnerabilities that were fixed include: a cross-site scripting (XSS) bug (CVE-2020-24408), a session invalidation bug (CVE-2020-24401), a security vulnerability that allows Magento CMS pages to be modified without user permission ( CVE-2020-24404), and two bugs that prevent access to resources (CVE-2020-24405 and CVE-2020-24403).

According to Adobe, the least dangerous flaw (CVE-2020-24406) is the accidental disclosure of a document's root path, which could lead to the exposure of sensitive information.
In its monthly patch, Adobe has fixed a critical vulnerability in Flash for Windows, macOS, Linux, and Chrome OS. This vulnerability (CVE-2020-9746) could be exploited to cause software crashes or execute malicious code.
This week, Microsoft its own security updates (Patch Tuesday October 2020) to fix vulnerabilities in many of its products. In total, the company is fixing 87 vulnerabilities. 21 of them allow code execution and affect Outlook, Excel , and Windows TCP/IP stack.
