APSB26-92: Security update available for Adobe Commerce
Published Aug 11, 2026.
APSB26-92 (published 2026-08-11) discloses 7 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-aug.
Seven vulnerabilities, led by an unauthenticated incorrect authorization flaw (CVE-2026-71362, CVSS 9.1) and two stored cross-site scripting flaws. Successful exploitation could result in security feature bypass, arbitrary code execution and privilege escalation. Adobe ships the fix as the 2026-aug isolated patch level on top of the base release, not as a new -pN release.
- Published
- Aug 11, 2026
- Severity
- critical
- CVEs
- 7
- Isolated patch
- yes
CVEs
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2026-71362 | 9.1 | improper-authorization | privilege-escalation | no |
| CVE-2026-48414 | 7.7 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-48413 | 8.7 | cross-site-scripting-stored | arbitrary-code-execution | yes |
| CVE-2026-48415 | 7.6 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-48416 | 7.5 | improper-authorization | security-feature-bypass | no |
| CVE-2026-48411 | 6.8 | improper-authorization | security-feature-bypass | yes |
| CVE-2026-48412 | 2.7 | improper-authorization | privilege-escalation | yes |
Fixed in
Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.
Isolated patches
- 2026-aug — applies to 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
References
For integrators
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB26-92
