CRITICAL

APSB25-71: Security update available for Adobe Commerce

Published Aug 12, 2025.

Improper access control (CVE-2025-49557) and related flaws that let an attacker bypass security features and reach functionality that should require authorization. Shipped with the regular August 2025 patch set for the 2.4.4 to 2.4.8 lines.

Published
Aug 12, 2025
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB25-71
CVE CVSS Type Impact Auth required
CVE-2025-49557 improper-access-control security-feature-bypass no

Fixed in

Magento Open Source
2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
Adobe Commerce
2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-71