Adobe has released a security update, APSB26-92, for Adobe Commerce and Magento Open Source to address multiple security vulnerabilities affecting supported platform versions. The update includes fixes for critical, important, and moderate vulnerabilities that could potentially allow attackers to bypass security controls, execute arbitrary code, or gain elevated privileges.
Adobe has assigned the update a Priority 2 rating and recommends that merchants and store administrators update their installations to the latest available versions. Adobe has not reported any known exploits in the wild for the vulnerabilities addressed by this update.
Affected Versions
The affected versions include various iterations of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Users running the following versions or earlier should take action:
- Adobe Commerce: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier, 2.4.5-2026-jul and earlier, 2.4.4-2026-jul and earlier
- Adobe Commerce B2B: 1.5.3-2026-jul and earlier, 1.5.2-2026-jul and earlier, 1.4.2-2026-jul and earlier, 1.3.4-2026-jul and earlier, 1.3.3-2026-jul and earlier
- Magento Open Source: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier
Solution
Adobe has released updated versions for both Adobe Commerce and Magento Open Source to address these vulnerabilities. Merchants using affected versions should take the following steps:
- Identify whether the current Adobe Commerce or Magento Open Source version is affected.
- Review patch and extension compatibility before applying the security update.
- Apply the latest security update in a staging environment first.
- Test key areas, including checkout, admin functionality, third-party integrations, custom modules, and Adobe Commerce B2B features where applicable.
- Adobe Commerce B2B users should update to the latest compatible B2B security release.
- Once testing is complete, deploy the security update to the production environment.
- Refer to Adobe’s official August 2026 security update release notes for detailed implementation guidance.
The updated versions include:
- Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
- Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
- Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
Why This Matters
Magento and Adobe Commerce stores frequently handle sensitive customer information, account data, payment-related transactions, and business-critical operations, making timely security updates essential for reducing exposure to potential attacks.
- Several vulnerabilities addressed in APSB26-92 are classified as critical and could result in serious security consequences if successfully exploited.
- Incorrect authorization vulnerabilities could allow attackers to escalate privileges or bypass security features.
- Stored cross-site scripting (XSS) vulnerabilities could potentially result in arbitrary code execution.
- Some of the critical vulnerabilities do not require authentication or administrative privileges, increasing the potential exposure of unpatched environments.
- Although Adobe has reported no known active exploitation at the time of publication, delaying security updates may leave stores exposed if exploitation techniques emerge.
- Applying the latest Adobe Commerce and Magento Open Source security updates helps strengthen store security, protect sensitive information, and maintain customer trust.
Vulnerability Details
The Adobe Security Bulletin APSB26-92 addresses multiple vulnerabilities affecting Adobe Commerce and Magento Open Source installations. The identified vulnerabilities primarily involve incorrect authorization and stored cross-site scripting (XSS) weaknesses.
Several incorrect authorization vulnerabilities could allow attackers to bypass security mechanisms or escalate privileges. One critical vulnerability, identified as CVE-2026-71362, carries a CVSS base score of 9.1 and could enable privilege escalation without requiring authentication or administrative privileges.
The update also addresses stored XSS vulnerabilities, including CVE-2026-48413 and CVE-2026-48414, which Adobe classifies as critical and which could potentially result in arbitrary code execution.
Another critical vulnerability, CVE-2026-48415, specifically affects Adobe Commerce B2B and could lead to a security feature bypass. Additional vulnerabilities addressed by the bulletin include CVE-2026-48416, CVE-2026-48411, and CVE-2026-48412, with impacts ranging from security feature bypass to privilege escalation.
Depending on the vulnerability, successful exploitation may or may not require authentication or administrative privileges. Adobe has released the August 2026 security updates to remediate these vulnerabilities and recommends that users update their installations to the newest applicable versions.
At the time the bulletin was published, Adobe stated that it was not aware of any exploits in the wild for the vulnerabilities addressed in APSB26-92. Nevertheless, merchants should prioritize applying the security update to reduce exposure to potential future exploitation.