Adobe has released security patches covering 15+ vulnerabilities in Magento 2.4.1, 2.3.6 and 2.4.0-p1. Among them are remote code execution and cross-site scripting flaws. Patch now.
What the vulnerabilities allow
Remote code execution lets an attacker run arbitrary code on your server. Cross-site scripting lets them inject scripts that run in your customers' browsers. Neither needs much explaining beyond that.
Which versions are affected
Magento 2.4.1, 2.3.6 and 2.4.0-p1. If you are running any of them, the patches apply to you.
What to do
Check your version in the admin. Apply the patch in staging and run your checkout and admin flows against it. Then push to production and watch your logs for a few days afterwards.
Staying ahead of the next one
Patch promptly, harden the admin interface, put WAF rules in front of the store, audit periodically and actually read the logs. None of that is interesting work. It is the difference between a patch cycle and an incident.
:quality(75))