CRITICAL

APSB26-138: Security update available for Adobe Commerce

Published Sep 8, 2026.

APSB26-138 (published 2026-09-08) discloses 8 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-sep.

Eight vulnerabilities, six of them exploitable without authentication, including two stored cross-site scripting flaws (CVE-2026-76200, CVE-2026-76201, CVSS 9.3) and several incorrect authorization flaws. Successful exploitation could result in security feature bypass and privilege escalation. Adobe ships the fix as the 2026-sep isolated patch level on top of the base release, not as a new -pN release; Adobe asks merchants to apply the APSB26-146 hotfix in addition.

Published
Sep 8, 2026
Severity
critical
CVEs
8
Isolated patch
yes

CVEs

CVEs in APSB26-138
CVE CVSS Type Impact Auth required
CVE-2026-76200 9.3 cross-site-scripting-stored privilege-escalation no
CVE-2026-76201 9.3 cross-site-scripting-stored privilege-escalation no
CVE-2026-77111 8.7 improper-authorization security-feature-bypass yes
CVE-2026-77109 8.6 improper-authorization privilege-escalation no
CVE-2026-77774 8.6 improper-authorization security-feature-bypass no
CVE-2026-76202 8.2 improper-authorization privilege-escalation no
CVE-2026-77110 7.6 improper-limitation-of-a-pathname-to-a-restricted-directory security-feature-bypass yes
CVE-2026-77108 7.5 improper-authorization privilege-escalation no

Fixed in

Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB26-138
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.