APSB26-05: Security update available for Adobe Commerce
Published Mar 10, 2026.
APSB26-05 (published 2026-03-10) fixes 19 CVEs in Adobe Commerce and Magento Open Source 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier; fixed in 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16; Adobe Commerce also in 2.4.4-p17.
Nineteen vulnerabilities, mainly stored cross-site scripting and incorrect authorization, plus server-side request forgery, path traversal, improper input validation and an open redirect. Successful exploitation could lead to security feature bypass, privilege escalation, arbitrary code execution, arbitrary file system read and application denial-of-service. Fixed in the March 2026 patch releases.
- Published
- Mar 10, 2026
- Severity
- critical
- CVEs
- 19
- Isolated patch
- no
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-21361 | 8.1 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-21284 | 8.1 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-21289 | 7.5 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21290 | 8.7 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-21311 | 8 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-21309 | 7.5 | improper-authorization | privilege-escalation | yes |
| CVE-2026-21285 | 4.3 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21286 | 5.3 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21291 | 4.8 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-21292 | 5.4 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-21293 | 5.5 | server-side-request-forgery | security-feature-bypass | yes |
| CVE-2026-21294 | 5.5 | server-side-request-forgery | security-feature-bypass | yes |
| CVE-2026-21359 | 4.7 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21360 | 6.8 | improper-limitation-of-a-pathname-to-a-restricted-directory | security-feature-bypass | yes |
| CVE-2026-21282 | 5.3 | improper-input-validation | security-feature-bypass | yes |
| CVE-2026-21310 | 5.3 | improper-input-validation | security-feature-bypass | yes |
| CVE-2026-21296 | 4.3 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21297 | 4.3 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-21295 | 3.1 | url-redirection-to-untrusted-site | security-feature-bypass | yes |
Fixed in
- Mage-OS
- —
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-05
