APSB26-146: Security update available for Adobe Commerce
Published Sep 7, 2026.
APSB26-146 (published 2026-09-07) discloses 1 CVE in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch VULN-39341.
Template engine injection (CVE-2026-75650, CVSS 10.0) that lets an unauthenticated attacker execute arbitrary code. Adobe reports exploitation in the wild. Fixed by the hotfix for CVE-2026-75650 (VULN-39341), which Adobe's APSB26-138 bulletin asks merchants to apply in addition to the September 2026 security update; Adobe also tells merchants to rotate their encryption keys.
- Published
- Sep 7, 2026
- Severity
- critical
- CVEs
- 1
- Isolated patch
- yes
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-75650 | 10 | improper-neutralization-of-special-elements-used-in-a-template-engine | arbitrary-code-execution | no |
Fixed in
Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.
Isolated patches
- VULN-39341 — applies to 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
References
- https://www.adobe.com/trust/security/products/commerce/apsb26-146.html
- https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-146
