APSB25-94: Security update available for Adobe Commerce
Published Oct 14, 2025.
APSB25-94 (published 2025-10-14) fixes 5 CVEs in Adobe Commerce and Magento Open Source 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier; fixed in 2.4.8-p3, 2.4.7-p8, 2.4.6-p13; Adobe Commerce also in 2.4.5-p15, 2.4.4-p16.
Incorrect authorization (CVE-2025-54263, CVE-2025-54265, CVE-2025-54267) and stored cross-site scripting in the admin (CVE-2025-54264, CVE-2025-54266) that allow security feature bypass, privilege escalation and arbitrary code execution. Four of the five issues require authentication. Fixed in the October 2025 patch releases.
- Published
- Oct 14, 2025
- Severity
- critical
- CVEs
- 5
- Isolated patch
- no
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-54263 | 8.1 | improper-authorization | security-feature-bypass | yes |
| CVE-2025-54264 | 8.1 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2025-54265 | 5.9 | improper-authorization | security-feature-bypass | no |
| CVE-2025-54266 | 4.8 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2025-54267 | 6.5 | improper-authorization | privilege-escalation | yes |
Fixed in
- Mage-OS
- —
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-94
