Critical security patches for Magento 2.4.1, 2.3.6 and 2.4.0-p1

Adobe has patched 15+ vulnerabilities in Magento 2.4.1, 2.3.6 and 2.4.0-p1, including remote code execution and XSS.

Critical security patches for Magento 2.4.1, 2.3.6 and 2.4.0-p1

Adobe has released security patches covering 15+ vulnerabilities in Magento 2.4.1, 2.3.6 and 2.4.0-p1. Among them are remote code execution and cross-site scripting flaws. Patch now.

What the vulnerabilities allow

Remote code execution lets an attacker run arbitrary code on your server. Cross-site scripting lets them inject scripts that run in your customers' browsers. Neither needs much explaining beyond that.

Which versions are affected

Magento 2.4.1, 2.3.6 and 2.4.0-p1. If you are running any of them, the patches apply to you.

What to do

Check your version in the admin. Apply the patch in staging and run your checkout and admin flows against it. Then push to production and watch your logs for a few days afterwards.

Staying ahead of the next one

Patch promptly, harden the admin interface, put WAF rules in front of the store, audit periodically and actually read the logs. None of that is interesting work. It is the difference between a patch cycle and an incident.