A flaw called “CosmicSting” affecting Adobe Commerce and Magento websites remains largely unpatched nine days after the security update was released, leaving millions of websites open to devastating attacks.
See also: LockBit: The top ransomware for May – 176 attacks

According to Sansec statistics , about three out of four websites using the affected e-commerce platforms have not been patched against the CosmicSting flaw, which puts them at risk of XML external entity injection (XXE) and remote code execution (RCE).
"CosmicSting (also known as CVE-2024-34102) is the worst bug to hit Magento and Adobe Commerce stores in the last two years," says Sansec.
“On its own, it allows anyone to read private files (such as those with passwords). However, combined with the recent iconv bug in Linux, it becomes a security nightmare, allowing remote code execution..”
See also: Maui health center reportedly hit by ransomware attack
The CosmicSting flaw, rated critical ( CVSS score: 9.8), affects the following product versions:
Adobe Commerce 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Adobe Commerce Extended Support 2.4.3-ext-7 and earlier, 2.4.2-ext-7 and earlier, 2.4.1-ext-7 and earlier, 2.4.0-ext-7 and earlier, 2.3.7-p4-ext-7 and earlier.
Magento Open Source 2.4.7 and earlier, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
Adobe Commerce Webhooks Plugin versions 1.2.0 to 1.4.0
Sansec says that despite Adobe omitting technical details in its bulletin to avoid feeding the active exploit, effective attack methods can be easily deduced from the update code, which its analysts used to replicate the attack.

Based on the severity and low complexity of the attack, Sansec estimates that the CosmicSting flaw has all the makings to become one of the most damaging attacks in the history of e-commerce, along with “Shoplift”, “Ambionics” and “Trojan Order”.
The vendor has released patches for CVE-2024-34102, which e-commerce platform administrators are advised to implement as soon as possible.
See also: NoName carries out DDoS attack in Romania
A security flaw, like the one from CosmicSting, is a weakness or vulnerability in a system that can be exploited by hackers to gain unauthorized access to an asset. This can lead to data breaches, loss of sensitive information, and significant financial damage. Common types of vulnerabilities include software bugs, improper configurations, and weak passwords. Identifying and mitigating these vulnerabilities is crucial to maintaining the security and integrity of systems and protecting against potential attacks. Regular updates, patches, and strong security practices are essential to protecting against the ever-evolving landscape of cybersecurity threats.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
