A second critical patch: CVE-2022-24087

CVE-2022-24087 needs both MDVA-43395 and MDVA-43443 applied, across production, staging and development. Here is the deployment and test order.

Adobe has released a critical security patch addressing CVE-2022-24087. Two patches are required: MDVA-43395 and MDVA-43443. Both, not either.

What it is

CVE-2022-24087 affects core Adobe Commerce (Magento) functionality and Adobe's security team has classified it as critical. It opens a route to unauthorised access to sensitive systems and data. Security researchers are aware of the flaw and threat actors have begun probing production environments, so this is not one for the next quarterly maintenance window.

What to do

  • Apply MDVA-43395. This addresses the core vulnerability vector, and it needs to reach production, staging and development.

  • Apply MDVA-43443. This closes a related vulnerability that can be exploited in conjunction with CVE-2022-24087. You need both for complete protection.

  • Smoke test the critical paths afterwards: checkout, customer account operations, order management and payment processing.

  • Watch the logs for unusual activity and access patterns in the days immediately after deployment.

How to deploy it

Development first. Apply the patches, run your complete test suite, and confirm custom extensions and integrations still behave.

Then staging, mirroring production as closely as you can, with real customer workflows, load testing and the edge cases.

Then production, in a low-traffic window, with rollback procedures ready — although rolling forward to the patched version is the only secure option here.

Afterwards, keep an eye on error logs, performance metrics and transaction throughput, and report anything unexpected to Adobe's support team.

What this means for you

Security is not a project with an end date. The merchants who handle patch cycles well tend to have the same four things: a documented patch calendar with defined maintenance windows, automated smoke tests that validate a patch in minutes rather than days, extension vendors held to timely compatibility statements, and a habit of escalating critical Adobe advisories to business stakeholders rather than filing them under IT overhead.

If you have not applied MDVA-43395 and MDVA-43443, that is today's job. If you run several Adobe Commerce instances, write the schedule down and work through it methodically — the one you forget is the one that matters.