CRITICAL

APSB26-73: Security update available for Adobe Commerce

Published Jul 14, 2026.

APSB26-73 (published 2026-07-14) discloses 14 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-jul.

Fourteen vulnerabilities, led by an unauthenticated unrestricted file upload (CVE-2026-48356, CVSS 9.6) and several incorrect authorization and stored cross-site scripting flaws. Successful exploitation could lead to arbitrary code execution, privilege escalation and security feature bypass. Adobe ships the fix as the 2026-jul isolated patch level on top of the base release, not as a new -pN release.

Published
Jul 14, 2026
Severity
critical
CVEs
14
Isolated patch
yes

CVEs

CVEs in APSB26-73
CVE CVSS Type Impact Auth required
CVE-2026-48356 9.6 unrestricted-upload-of-file-with-dangerous-type privilege-escalation no
CVE-2026-48358 9.1 improper-encoding-or-escaping-of-output arbitrary-code-execution yes
CVE-2026-47994 8.7 cross-site-scripting-stored privilege-escalation yes
CVE-2026-47988 8.6 improper-authorization security-feature-bypass no
CVE-2026-47984 8.2 improper-authorization security-feature-bypass no
CVE-2026-47995 8.1 cross-site-scripting-stored privilege-escalation yes
CVE-2026-47996 7.6 improper-authorization security-feature-bypass yes
CVE-2026-47992 7.2 improper-input-validation privilege-escalation yes
CVE-2026-47997 5.9 improper-authorization security-feature-bypass no
CVE-2026-47998 5.9 improper-authorization security-feature-bypass no
CVE-2026-48371 5.4 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-47999 4.8 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-48000 4.3 url-redirection-to-untrusted-site security-feature-bypass yes
CVE-2026-48001 3.7 information-exposure security-feature-bypass no

Fixed in

Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB26-73
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.