Adobe Commerce security
Magento security patches, tracked
Every Adobe Commerce and Magento Open Source security bulletin since May 2026, in plain English: what it fixes, which versions it covers, and whether it is a scheduled release or a hotfix you have to apply separately. We run Magento stores in production, so we read each one the day it lands anyway.
Last checked against Adobe's bulletins:
Act on this now
Applied the September update? Check for the StyleSmuggler hotfix as well
The scheduled September release (APSB26-138) does not fix CVE-2026-75650. That is the separate hotfix VULN-39341 from APSB26-146, which is being exploited and needs no login. Ask your team one question: was VULN-39341 applied, by name? Then rotate the encryption key and the credentials it protects, as Adobe now requires. If your store was unpatched while exploitation was running from 4 September, check whether it was hit before assuming the patch settled it.
2026 bulletins, newest first
-
APSB26-146
7 September 2026 Out-of-band hotfixStyleSmuggler, CVE-2026-75650: unauthenticated remote code execution, exploited in the wild
Hotfix VULN-39341. Affects Adobe Commerce and Magento Open Source 2.4.4 to 2.4.9 (August 2026 releases and earlier) and Adobe Commerce B2B 1.3.3 to 1.5.3. Adobe has since updated the hotfix to be compatible with every version from 2.4.4 to 2.4.7, so a store that could not apply it at first should try again. Adobe also requires rotating the encryption key and every credential it could have exposed. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 8 September. It is not included in APSB26-138 and has to be applied on its own. Our StyleSmuggler write-up covers checking whether a store was hit before the patch landed.
-
APSB26-138
8 September 2026 Scheduled releaseSeptember update: critical, important and moderate vulnerabilities
Could lead to arbitrary code execution, privilege escalation and security feature bypass. Affects the 2.4.4 to 2.4.9 lines at their 2026-aug builds and earlier, fixed by the September isolated patches (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18). Adobe states the StyleSmuggler hotfix is not in the September patch file.
-
APSB26-92
11 August 2026 Scheduled releaseAugust update: critical and important vulnerabilities
Could lead to arbitrary code execution, security feature bypass and privilege escalation. Delivered as isolated patch files for the latest patch level of each line from 2.4.4 to 2.4.9.
-
APSB26-73
14 July 2026 Scheduled releaseJuly update: critical, important and moderate vulnerabilities
Could lead to arbitrary code execution, security feature bypass and privilege escalation. The first of the 2026 bulletins shipped as isolated patch files rather than new Composer versions, one per line from 2.4.4 to 2.4.9.
-
APSB26-49
12 May 2026 Scheduled releaseMay update: 15 vulnerabilities, Priority 2
Could lead to arbitrary code execution, arbitrary file system write, denial of service and security feature bypass. Fixed in Adobe Commerce 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18, and in Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10 and 2.4.6-p15.
Earlier bulletins are on Adobe's Magento security index.
Running a version older than 2.4.4?
Then none of the bulletins above reach you. Adobe's 2026 patches start at the 2.4.4 line, so a store on any 2.3 release or on 2.4.0 to 2.4.3 has no official fix for StyleSmuggler or for anything else published this year. Unofficial backports exist, and they are a stopgap to be code-reviewed, not a plan.
The plan is an upgrade, or a move to another platform if the upgrade costs more than the store is worth on Magento. Until then, an edge rule in front of the store is the realistic protection, and we can help put one in place.
Common questions
How often does Adobe release Magento security patches?
Two ways. Scheduled bulletins, and in 2026 there has been one in each of July, August and September, now shipped as isolated patch files for each supported line. And out-of-band hotfixes when something is being exploited, which arrive whenever they arrive: APSB26-146 landed the day before the scheduled September release, not with it. The hotfixes are the ones that catch stores out, because they are separate from the scheduled release.
Does the September 2026 Magento update include the StyleSmuggler fix?
No. APSB26-138, the scheduled September release, does not contain the fix for CVE-2026-75650. That is the separate hotfix VULN-39341 from APSB26-146, and Adobe says it must be applied in addition to the September patches. A store reporting a 2026-sep build is not covered unless the hotfix was applied as well.
Which Magento versions still get security patches?
Across the 2026 bulletins, Adobe ships patches for the 2.4.4 line and newer, up to 2.4.9. Anything older, every 2.3 release and 2.4.0 to 2.4.3, receives nothing, including the StyleSmuggler hotfix. If your store is on one of those, the fix is an upgrade, and until then the realistic protection is an edge rule in front of the store.
How do we check which patches our store actually has?
Not from the version number alone. The version tells you which scheduled release you are on; it says nothing about hotfixes applied on top. Check wherever your team records applied patches, such as the Composer patch list or the Quality Patches Tool status, for the specific hotfix by name. If nobody can answer that in a few minutes, that is worth fixing before the next bulletin.
Can you apply the patches for us?
Yes. Same-day patching, including the out-of-band kind, is part of our Magento and Adobe Commerce support, and we take over stores other agencies built. If you only need a hand with one bulletin, get in touch; you do not need to be a client.
Commerce work we do
-
Magento & Adobe Commerce
Builds, replatforms, upgrades and performance rescue, including SAP integration.
-
Adobe Commerce support
Taking over platforms other agencies built: incident response, out-of-band security patching and upgrades.
-
Magento upgrades
Version upgrades and extension audits, and when the platform is not what needs the money.
-
Shopify & Shopify Plus
Shopify-certified developers: storefronts, theme builds, app integration and headless front ends.
-
Shopify Plus
Checkout extensibility, B2B and D2C together, multi-storefront, and when the tier is not worth it.
-
E-commerce development
The whole practice: platform selection, build, integrate and run.
-
Headless commerce
Decoupled storefronts on Shopify and Adobe Commerce, and when a themed build is the better call.
-
Migration & replatforming
Moving between platforms without losing data, rankings or trading days.
-
Magento to Shopify
The specific route, and an honest view of when not to take it.
-
WooCommerce
WordPress commerce where the catalogue and the content live together.
-
E-commerce & retail
The sector view, what retail platforms are actually asked to do, and where they break.
-
B2B & wholesale commerce
Company accounts, contract pricing, quotes, credit terms and ERP-held price logic for trade suppliers.
-
Adelaide commerce
Adobe Commerce for South Australian retailers, including the duty free store trading at Adelaide Airport.
-
New Zealand commerce
GST, rural freight and trans-Tasman selling, and the duty free stores running across airports in both countries.