CRITICAL

APSB26-92: Security update available for Adobe Commerce

Published Aug 11, 2026.

APSB26-92 (published 2026-08-11) discloses 7 CVEs in Adobe Commerce and Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier; no fixing release yet; isolated patch 2026-aug.

Seven vulnerabilities, led by an unauthenticated incorrect authorization flaw (CVE-2026-71362, CVSS 9.1) and two stored cross-site scripting flaws. Successful exploitation could result in security feature bypass, arbitrary code execution and privilege escalation. Adobe ships the fix as the 2026-aug isolated patch level on top of the base release, not as a new -pN release.

Published
Aug 11, 2026
Severity
critical
CVEs
7
Isolated patch
yes

CVEs

CVEs in APSB26-92
CVE CVSS Type Impact Auth required
CVE-2026-71362 9.1 improper-authorization privilege-escalation no
CVE-2026-48414 7.7 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-48413 8.7 cross-site-scripting-stored arbitrary-code-execution yes
CVE-2026-48415 7.6 improper-authorization security-feature-bypass yes
CVE-2026-48416 7.5 improper-authorization security-feature-bypass no
CVE-2026-48411 6.8 improper-authorization security-feature-bypass yes
CVE-2026-48412 2.7 improper-authorization privilege-escalation yes

Fixed in

Isolated patch only: no release fixes this. Apply the patch on the base versions listed below.

Isolated patches

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB26-92
Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.