CRITICAL

APSB26-146: Security update available for Adobe Commerce

Published Sep 7, 2026.

APSB26-146 (published 2026-09-07) discloses 1 CVE in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch VULN-39341.

Template engine injection (CVE-2026-75650, CVSS 10.0) that lets an unauthenticated attacker execute arbitrary code. Adobe reports exploitation in the wild. Fixed by the hotfix for CVE-2026-75650 (VULN-39341), which Adobe's APSB26-138 bulletin asks merchants to apply in addition to the September 2026 security update; Adobe also tells merchants to rotate their encryption keys.

Published
Sep 7, 2026
Severity
critical
CVEs
1
Isolated patch
yes

CVEs

CVEs in APSB26-146
CVE CVSS Type Impact Auth required
CVE-2026-75650 10 improper-neutralization-of-special-elements-used-in-a-template-engine arbitrary-code-execution no

Fixed in

Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB26-146
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.