SECURITY BULLETINS

Magento and Adobe Commerce security bulletins

Every tracked Adobe security bulletin with its CVEs and the exact patch version that fixes each one.

This is machine-readable Adobe/Magento CVE data mapped to the fixed-in patch version, kept in sync with the version-lifecycle data on this site — built for CI pipelines, monitoring and coding agents, not just for reading in a browser.

curl -s https://magento.watch/api/v1/magento-community/versions/2.4.7/security

MCP clients get the same answer from the check_version_security tool.

Security bulletins
Bulletin Published Severity CVEs Magento Open Source Adobe Commerce Mage-OS
APSB25-88 2025-09-09 critical CVE-2025-54236 Open Source2.4.8-p2Commerce2.4.8-p2Mage-OS
Improper input validation in the Web API's service input processor (CVE-2025-54236), publicly known as SessionReaper. An unauthenticated attacker can hijack customer sessions through the REST API and, depending on configuration, reach remote code execution. Adobe shipped the out-of-band hotfix VULN-32437 before the regular patch release; it was the first emergency patch since CosmicSting.
APSB25-71 2025-08-12 critical CVE-2025-49557 Open Source2.4.8-p2Commerce2.4.8-p2Mage-OS
Improper access control (CVE-2025-49557) and related flaws that let an attacker bypass security features and reach functionality that should require authorization. Shipped with the regular August 2025 patch set for the 2.4.4 to 2.4.8 lines.
APSB25-50 2025-06-10 critical CVE-2025-47110 Open Source2.4.8-p1Commerce2.4.8-p1Mage-OS
Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.
APSB25-26 2025-04-08 critical CVE-2025-27189 Open Source2.4.8Commerce2.4.8Mage-OS
Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.
APSB25-08 2025-02-11 critical CVE-2025-24434 Open Source2.4.7-p4Commerce2.4.7-p4Mage-OS
Improper authorization (CVE-2025-24434) that lets a low-privileged actor escalate privileges; Adobe rated it critical because exploitation does not require user interaction. Fixed in the February 2025 patch set.
APSB24-73 2024-10-08 critical CVE-2024-45115 Open Source2.4.7-p3Commerce2.4.7-p3Mage-OS
Improper authentication (CVE-2024-45115) that allows privilege escalation without prior authentication. Part of the October 2024 patch set that followed the CosmicSting exploitation wave.
APSB24-61 2024-08-13 critical CVE-2024-39397 Open Source2.4.7-p2Commerce2.4.7-p2Mage-OS
Unrestricted upload of a file with a dangerous type (CVE-2024-39397) allowing arbitrary code execution by an unauthenticated attacker; Adobe notes the exploit requires the Apache web server. Fixed in the August 2024 patch set.
APSB24-40 2024-06-11 critical CVE-2024-34102 Open Source2.4.7-p1Commerce2.4.7-p1Mage-OS
XML external entity injection in the REST API (CVE-2024-34102), publicly known as CosmicSting. An unauthenticated attacker can read arbitrary files such as env.php and, chained with the glibc iconv bug CVE-2024-2961, execute code. Mass exploitation followed within weeks; Adobe also released an isolated patch for stores that could not upgrade.
APSB24-18 2024-04-09 critical CVE-2024-20758, CVE-2024-20759 Open Source2.4.7Commerce2.4.7Mage-OS
Improper input validation (CVE-2024-20758) enabling arbitrary code execution by an authenticated administrator, plus stored cross-site scripting (CVE-2024-20759). Published with the 2.4.7 general availability release and the April 2024 patch set.