APSB26-73: Security update available for Adobe Commerce
Published Jul 14, 2026.
APSB26-73 (published 2026-07-14) discloses 14 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-jul.
Fourteen vulnerabilities, led by an unauthenticated unrestricted file upload (CVE-2026-48356, CVSS 9.6) and several incorrect authorization and stored cross-site scripting flaws. Successful exploitation could lead to arbitrary code execution, privilege escalation and security feature bypass. Adobe ships the fix as the 2026-jul isolated patch level on top of the base release, not as a new -pN release.
- Published
- Jul 14, 2026
- Severity
- critical
- CVEs
- 14
- Isolated patch
- yes
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-48356 | 9.6 | unrestricted-upload-of-file-with-dangerous-type | privilege-escalation | no |
| CVE-2026-48358 | 9.1 | improper-encoding-or-escaping-of-output | arbitrary-code-execution | yes |
| CVE-2026-47994 | 8.7 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-47988 | 8.6 | improper-authorization | security-feature-bypass | no |
| CVE-2026-47984 | 8.2 | improper-authorization | security-feature-bypass | no |
| CVE-2026-47995 | 8.1 | cross-site-scripting-stored | privilege-escalation | yes |
| CVE-2026-47996 | 7.6 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-47992 | 7.2 | improper-input-validation | privilege-escalation | yes |
| CVE-2026-47997 | 5.9 | improper-authorization | security-feature-bypass | no |
| CVE-2026-47998 | 5.9 | improper-authorization | security-feature-bypass | no |
| CVE-2026-48371 | 5.4 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-47999 | 4.8 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-48000 | 4.3 | url-redirection-to-untrusted-site | security-feature-bypass | yes |
| CVE-2026-48001 | 3.7 | information-exposure | security-feature-bypass | no |
Fixed in
Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.
Isolated patches
- 2026-jul — applies to 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-73
