📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 26m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 26m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 26m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h
Vulnerabilities

CVE-2026-34651

High
CWE-400 — Weakness Type
Published: May 12, 2026  ·  Modified: May 19, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

🤖 AI Executive Summary

Adobe Commerce versions 2.4.9-beta1 through 2.4.4-p17 and earlier contain an uncontrolled resource consumption vulnerability (CWE-400) that enables unauthenticated denial-of-service attacks. With a CVSS score of 7.5, this vulnerability allows attackers to exhaust system resources without user interaction, potentially disrupting e-commerce operations. No patch is currently available, requiring immediate implementation of compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 20, 2026 11:49
🇸🇦 Saudi Arabia Impact Assessment
Saudi e-commerce and retail organizations using Adobe Commerce are at critical risk, particularly those operating payment processing systems regulated by SAMA. Financial institutions offering digital commerce services, telecommunications companies with online platforms (STC, Mobily), and government e-services portals are most vulnerable. The DoS vulnerability could disrupt critical business operations, impact customer transactions, and violate SAMA's cybersecurity requirements for financial service availability. Healthcare and energy sector online portals may also be affected if running vulnerable Adobe Commerce instances.
🏢 Affected Saudi Sectors
E-commerce and Retail Banking and Financial Services Telecommunications Government and Public Services Healthcare Energy and Utilities
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all Adobe Commerce deployments and identify affected versions (2.4.4-p17 and earlier)
2. Implement rate limiting and request throttling at WAF/load balancer level to mitigate resource exhaustion
3. Enable connection limits and timeout configurations to prevent resource depletion
4. Monitor system resource utilization (CPU, memory, database connections) for anomalous patterns

COMPENSATING CONTROLS:
5. Deploy Web Application Firewall (WAF) rules to detect and block malicious request patterns
6. Implement DDoS mitigation services and traffic filtering
7. Configure auto-scaling infrastructure to handle traffic spikes
8. Establish request validation and input sanitization at application layer
9. Implement API rate limiting per IP/session
10. Enable detailed logging of resource consumption and failed requests

DETECTION:
11. Monitor for unusual spike in HTTP requests from single sources
12. Alert on sustained high CPU/memory usage without legitimate traffic increase
13. Track database connection pool exhaustion events
14. Monitor application error logs for resource allocation failures

PATCHING:
15. Subscribe to Adobe security advisories for patch availability
16. Plan immediate patching upon release of security updates
17. Test patches in non-production environment before deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع نشرات Adobe Commerce وتحديد الإصدارات المتأثرة (2.4.4-p17 والإصدارات الأقدم)
2. تطبيق تحديد معدل الطلبات والتحكم في الازدحام على مستوى WAF/موازن الحمل
3. تفعيل حدود الاتصال وإعدادات المهلة الزمنية لمنع استنزاف الموارد
4. مراقبة استخدام موارد النظام (CPU، الذاكرة، اتصالات قاعدة البيانات) للأنماط الشاذة

الضوابط البديلة:
5. نشر قواعد جدار حماية تطبيقات الويب (WAF) للكشف عن أنماط الطلبات الضارة وحجبها
6. تطبيق خدمات تخفيف هجمات DDoS وتصفية حركة المرور
7. تكوين البنية الأساسية ذات التوسع التلقائي للتعامل مع ارتفاعات حركة المرور
8. إنشاء التحقق من صحة الطلبات وتنظيف المدخلات على مستوى التطبيق
9. تطبيق تحديد معدل API لكل عنوان IP/جلسة
10. تفعيل السجلات التفصيلية لاستهلاك الموارد والطلبات الفاشلة

الكشف:
11. مراقبة الارتفاع غير المعتاد في طلبات HTTP من مصادر واحدة
12. تنبيهات على استخدام CPU/الذاكرة المرتفع المستمر بدون زيادة حركة مرور شرعية
13. تتبع أحداث استنزاف مجموعة اتصالات قاعدة البيانات
14. مراقبة سجلات أخطاء التطبيق لفشل تخصيص الموارد

التصحيح:
15. الاشتراك في تنبيهات أمان Adobe للحصول على توفر التصحيحات
16. التخطيط للتصحيح الفوري عند إصدار التحديثات الأمنية
17. اختبار التصحيحات في بيئة غير الإنتاج قبل النشر
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.12.3.1 - Segregation of networks ECC 2024 A.12.4.1 - Event logging ECC 2024 A.12.4.3 - Administrator and operator logs
🔵 SAMA CSF
SAMA CSF ID.BE-5 - Organizational resilience objectives SAMA CSF PR.DS-6 - Integrity checking mechanisms SAMA CSF DE.AE-1 - A baseline of network operations and expected data flows SAMA CSF DE.CM-1 - The network is monitored to detect potential cybersecurity events
🟡 ISO 27001:2022
ISO 27001:2022 A.12.2.1 - Implementation of technical and organizational measures ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.8.1.3 - Segregation of duties ISO 27001:2022 A.12.4.1 - Event logging
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Ensure all system components and software are protected from known vulnerabilities PCI DSS 10.2 - Implement automated audit trails for all access to cardholder data PCI DSS 11.2 - Run automated vulnerability scans regularly
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-400
EPSS0.06%
Exploit No
Patch ✗ No
Published 2026-05-12
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-400
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.