Adobe has released a security update, APSB26-138, for Adobe Commerce and Magento Open Source to address multiple security vulnerabilities affecting supported platform versions. The vulnerabilities could potentially allow attackers to bypass security features or gain elevated privileges on affected installations.
Adobe has assigned this update a Priority 2 rating and recommends that merchants and store administrators update their installations to the newest available versions. At the time of publication, Adobe stated that it was not aware of any exploits in the wild for the vulnerabilities addressed in this update.
Affected Versions
The following versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected:
- Adobe Commerce: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, and 2.4.4-2026-aug and earlier.
- Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, and 1.3.3-2026-aug and earlier.
- Magento Open Source: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, and 2.4.6-2026-aug and earlier.
The vulnerabilities affect installations across all supported platforms. Merchants and development teams should review their current platform version and security update level to determine whether their environment is affected.
Solution
Adobe has released updated versions for both Adobe Commerce and Magento Open Source to address these vulnerabilities. Merchants using affected versions should take the following steps:
- Update affected Adobe Commerce installations to the appropriate September 2026 security release: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, or 2.4.4-2026-sep.
- Update affected Adobe Commerce B2B installations to the appropriate September 2026 release: 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, or 1.3.3-2026-sep.
- Update affected Magento Open Source installations to 2.4.9-2026-sep, 2.4.8-2026-sep, or 2.4.7-2026-sep, as applicable.
- Review extension, customization, and integration compatibility and test the security update in a staging environment before deploying it to production.
- Adobe also instructs users to apply the hotfix for CVE-2026-75650, released under APSB26-146 on September 7, 2026, in addition to the security updates included in APSB26-138.
- Refer to Adobe’s September 2026 security update release notes and installation instructions for implementation guidance.
Why This Matters
The vulnerabilities addressed in APSB26-138 include critical security issues that could result in privilege escalation or allow attackers to bypass security features. Several of the critical vulnerabilities can be exploited without authentication, increasing the potential risk for affected Adobe Commerce and Magento Open Source environments.
- The highest-severity vulnerabilities in APSB26-138 have a CVSS base score of 9.3 and are classified as critical.
- Multiple vulnerabilities do not require authentication, meaning exploitation may be possible without valid user credentials.
- Successful exploitation could result in privilege escalation or security feature bypass, potentially compromising application security and sensitive information.
- The bulletin includes vulnerabilities affecting Adobe Commerce B2B, making it important for B2B merchants to verify that their installations are properly updated.
- Adobe has stated that it is not aware of any exploits in the wild for the vulnerabilities addressed in APSB26-138 at the time of publication.
- Applying the September security updates promptly can help reduce exposure and protect store data, application functionality, and overall eCommerce security.
Vulnerability Details
The Adobe Security Bulletin APSB26-138 addresses multiple critical vulnerabilities involving Stored Cross-site Scripting (XSS), Incorrect Authorization, and Path Traversal.
Two of the highest-severity vulnerabilities, CVE-2026-76200 and CVE-2026-76201, are Stored XSS vulnerabilities with CVSS base scores of 9.3. Both are classified as critical, do not require authentication, and could result in privilege escalation.
The bulletin also addresses several incorrect authorization vulnerabilities. CVE-2026-77109 has a CVSS score of 8.6, does not require authentication, could result in privilege escalation, and specifically affects Adobe Commerce B2B. CVE-2026-77774, also rated 8.6, could allow security feature bypass without authentication.
Additional critical vulnerabilities include CVE-2026-76202, which could result in privilege escalation without authentication, and CVE-2026-77108, another Adobe Commerce B2B vulnerability that could lead to privilege escalation without requiring credentials. CVE-2026-77111 and the Path Traversal vulnerability CVE-2026-77110 could result in security feature bypass but require authentication for exploitation.
Although Adobe has not reported active exploitation of the vulnerabilities addressed specifically in APSB26-138, organizations running affected Adobe Commerce or Magento Open Source versions should update their environments promptly. Adobe also advises users to apply the separate CVE-2026-75650 hotfix associated with APSB26-146 in addition to these September security updates.