APSB26-49: Security update available for Adobe Commerce
Published May 12, 2026.
APSB26-49 (published 2026-05-12) fixes 15 CVEs in Adobe Commerce and Magento Open Source 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier; fixed in 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15; Adobe Commerce also in 2.4.5-p17, 2.4.4-p18.
Fifteen vulnerabilities, including incorrect authorization, server-side request forgery, uncontrolled resource consumption, vulnerable third-party components and stored cross-site scripting; one path traversal allows arbitrary file system write. Successful exploitation could lead to arbitrary code execution, arbitrary file system write, application denial-of-service and security feature bypass. Fixed in the May 2026 patch releases, including the 2.4.9 GA release.
- Published
- May 12, 2026
- Severity
- critical
- CVEs
- 15
- Isolated patch
- no
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-34645 | 7.5 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-34646 | 7.5 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-34647 | 7.4 | server-side-request-forgery | security-feature-bypass | yes |
| CVE-2026-34648 | 7.5 | uncontrolled-resource-consumption | application-denial-of-service | yes |
| CVE-2026-34649 | 7.5 | uncontrolled-resource-consumption | application-denial-of-service | yes |
| CVE-2026-34650 | 7.5 | uncontrolled-resource-consumption | application-denial-of-service | yes |
| CVE-2026-34651 | 7.5 | uncontrolled-resource-consumption | application-denial-of-service | yes |
| CVE-2026-34652 | 7.5 | dependency-on-vulnerable-third-party-component | application-denial-of-service | yes |
| CVE-2026-34686 | 8.7 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-34653 | 8.7 | improper-limitation-of-a-pathname-to-a-restricted-directory | arbitrary-file-system-write | yes |
| CVE-2026-34654 | 5.3 | dependency-on-vulnerable-third-party-component | application-denial-of-service | yes |
| CVE-2026-34655 | 4.8 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-34656 | 4.3 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-34658 | 4.8 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-34685 | 3.4 | improper-input-validation | arbitrary-code-execution | yes |
Fixed in
- Mage-OS
- —
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-49
