APSB26-138: Security update available for Adobe Commerce
Published Sep 8, 2026.
APSB26-138 (published 2026-09-08) discloses 8 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-sep.
Eight vulnerabilities, six of them exploitable without authentication, including two stored cross-site scripting flaws (CVE-2026-76200, CVE-2026-76201, CVSS 9.3) and several incorrect authorization flaws. Successful exploitation could result in security feature bypass and privilege escalation. Adobe ships the fix as the 2026-sep isolated patch level on top of the base release, not as a new -pN release; Adobe asks merchants to apply the APSB26-146 hotfix in addition.
- Published
- Sep 8, 2026
- Severity
- critical
- CVEs
- 8
- Isolated patch
- yes
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-76200 | 9.3 | cross-site-scripting-stored | privilege-escalation | no |
| CVE-2026-76201 | 9.3 | cross-site-scripting-stored | privilege-escalation | no |
| CVE-2026-77111 | 8.7 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-77109 | 8.6 | improper-authorization | privilege-escalation | no |
| CVE-2026-77774 | 8.6 | improper-authorization | security-feature-bypass | no |
| CVE-2026-76202 | 8.2 | improper-authorization | privilege-escalation | no |
| CVE-2026-77110 | 7.6 | improper-limitation-of-a-pathname-to-a-restricted-directory | security-feature-bypass | yes |
| CVE-2026-77108 | 7.5 | improper-authorization | privilege-escalation | no |
Fixed in
Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.
Isolated patches
- 2026-sep — applies to 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-138
