Magento 2.4.0 and 2.3.5-p2 security updates released

Adobe has patched over 30 vulnerabilities in Magento 2.4.0 and 2.3.5-p2, including RCE, XSS and SQL injection. Schedule this one quickly.

Magento 2.4.0 and 2.3.5-p2 security updates released

Adobe has released security updates for Magento 2.4.0 and Magento 2.3.5-p2, addressing over 30 vulnerabilities across the two version lines.

What is in the release

Several of the issues need to go straight to the top of the queue:

  • Remote Code Execution (RCE) vulnerabilities that could let an attacker run arbitrary code

  • Cross-Site Scripting (XSS), affecting both stored and reflected attack vectors

  • SQL Injection risks against sensitive customer data

  • further vulnerabilities affecting order processing and customer account management

Why it needs scheduling now, not soon

RCE is a threat to the whole platform, not just the storefront. XSS and SQL injection put customer personal and payment data in scope. PCI DSS requires you to keep current with security patches, so an unpatched store is a compliance problem as well as a security one. And a compromised store costs revenue and customer trust in the same week.

What to do

  1. Read the advisory for your specific version.

  2. Test the patches in staging before production โ€” custom extensions are where patching usually snags.

  3. Schedule the deployment quickly. These are critical-level vulnerabilities, so this is not a next-quarter item.

  4. Check your logs for suspicious activity that might indicate somebody got there first.

What this means for you

Staying current with security patches is the cornerstone of running Adobe Commerce responsibly, and patching is not a project you finish. It is a rhythm you keep, and the stores that keep it spend far less time on releases like this one than the stores that treat every patch as an event. If you are not certain which version you are running, that is the first thing to find out โ€” and we are happy to help you find out quickly.