CRITICAL

APSB26-49: Security update available for Adobe Commerce

Published May 12, 2026.

APSB26-49 (published 2026-05-12) fixes 15 CVEs in Adobe Commerce and Magento Open Source 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier; fixed in 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15; Adobe Commerce also in 2.4.5-p17, 2.4.4-p18.

Fifteen vulnerabilities, including incorrect authorization, server-side request forgery, uncontrolled resource consumption, vulnerable third-party components and stored cross-site scripting; one path traversal allows arbitrary file system write. Successful exploitation could lead to arbitrary code execution, arbitrary file system write, application denial-of-service and security feature bypass. Fixed in the May 2026 patch releases, including the 2.4.9 GA release.

Published
May 12, 2026
Severity
critical
CVEs
15
Isolated patch
no

CVEs

CVEs in APSB26-49
CVE CVSS Type Impact Auth required
CVE-2026-34645 7.5 improper-authorization security-feature-bypass yes
CVE-2026-34646 7.5 improper-authorization security-feature-bypass yes
CVE-2026-34647 7.4 server-side-request-forgery security-feature-bypass yes
CVE-2026-34648 7.5 uncontrolled-resource-consumption application-denial-of-service yes
CVE-2026-34649 7.5 uncontrolled-resource-consumption application-denial-of-service yes
CVE-2026-34650 7.5 uncontrolled-resource-consumption application-denial-of-service yes
CVE-2026-34651 7.5 uncontrolled-resource-consumption application-denial-of-service yes
CVE-2026-34652 7.5 dependency-on-vulnerable-third-party-component application-denial-of-service yes
CVE-2026-34686 8.7 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-34653 8.7 improper-limitation-of-a-pathname-to-a-restricted-directory arbitrary-file-system-write yes
CVE-2026-34654 5.3 dependency-on-vulnerable-third-party-component application-denial-of-service yes
CVE-2026-34655 4.8 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-34656 4.3 improper-authorization security-feature-bypass yes
CVE-2026-34658 4.8 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-34685 3.4 improper-input-validation arbitrary-code-execution yes

Fixed in

Magento Open Source
2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
Adobe Commerce
2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
Mage-OS
—

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB26-49
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.