
More improvements to Attack Surface Custom Policies
Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Detectify Admin
![[Alert] New Magento Vulnerability – Unauthenticated Remote Code Execution](/_next/image/?url=https%3A%2F%2Fblog-detectify-api.stage.io-ext.se%2Fapp%2Fuploads%2F2022%2F11%2Finspect-report-small-1.png&w=3840&q=75)
Are you running Magento version before 2.0.6.? Time to upgrade!
It was recently discovered that all Magento versions before 2.0.6. (both Community and Enterprise Edition) are vulnerable against an unauthenticated Remote Code Execution. The vulnerability (CVE-2016-4010) could allow an attacker to take over the vulnerable process, consequently even take complete control over the machine, putting your customer data, transaction history and revenues at risk.
[Solution] Upgrade to the 2.0.6 patch as soon as possible
As always, we recommend you to run regular security tests on your website and keep up with all the latest vulnerabilities on our blog.
Stay safe!

Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …