CRITICAL

APSB25-94: Security update available for Adobe Commerce

Published Oct 14, 2025.

APSB25-94 (published 2025-10-14) fixes 5 CVEs in Adobe Commerce and Magento Open Source 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier; fixed in 2.4.8-p3, 2.4.7-p8, 2.4.6-p13; Adobe Commerce also in 2.4.5-p15, 2.4.4-p16.

Incorrect authorization (CVE-2025-54263, CVE-2025-54265, CVE-2025-54267) and stored cross-site scripting in the admin (CVE-2025-54264, CVE-2025-54266) that allow security feature bypass, privilege escalation and arbitrary code execution. Four of the five issues require authentication. Fixed in the October 2025 patch releases.

Published
Oct 14, 2025
Severity
critical
CVEs
5
Isolated patch
no

CVEs

CVEs in APSB25-94
CVE CVSS Type Impact Auth required
CVE-2025-54263 8.1 improper-authorization security-feature-bypass yes
CVE-2025-54264 8.1 cross-site-scripting-stored privilege-escalation yes
CVE-2025-54265 5.9 improper-authorization security-feature-bypass no
CVE-2025-54266 4.8 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2025-54267 6.5 improper-authorization privilege-escalation yes

Fixed in

Magento Open Source
2.4.8-p3, 2.4.7-p8, 2.4.6-p13
Adobe Commerce
2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16
Mage-OS
—

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-94
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.