Skip to content

Adobe Commerce security

Magento security patches, tracked

Every Adobe Commerce and Magento Open Source security bulletin since May 2026, in plain English: what it fixes, which versions it covers, and whether it is a scheduled release or a hotfix you have to apply separately. We run Magento stores in production, so we read each one the day it lands anyway.

Last checked against Adobe's bulletins:

Act on this now

Applied the September update? Check for the StyleSmuggler hotfix as well

The scheduled September release (APSB26-138) does not fix CVE-2026-75650. That is the separate hotfix VULN-39341 from APSB26-146, which is being exploited and needs no login. Ask your team one question: was VULN-39341 applied, by name? Then rotate the encryption key and the credentials it protects, as Adobe now requires. If your store was unpatched while exploitation was running from 4 September, check whether it was hit before assuming the patch settled it.

2026 bulletins, newest first

  1. APSB26-146

    7 September 2026 Out-of-band hotfix

    StyleSmuggler, CVE-2026-75650: unauthenticated remote code execution, exploited in the wild

    Hotfix VULN-39341. Affects Adobe Commerce and Magento Open Source 2.4.4 to 2.4.9 (August 2026 releases and earlier) and Adobe Commerce B2B 1.3.3 to 1.5.3. Adobe has since updated the hotfix to be compatible with every version from 2.4.4 to 2.4.7, so a store that could not apply it at first should try again. Adobe also requires rotating the encryption key and every credential it could have exposed. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 8 September. It is not included in APSB26-138 and has to be applied on its own. Our StyleSmuggler write-up covers checking whether a store was hit before the patch landed.

    Adobe's bulletin for APSB26-146

  2. APSB26-138

    8 September 2026 Scheduled release

    September update: critical, important and moderate vulnerabilities

    Could lead to arbitrary code execution, privilege escalation and security feature bypass. Affects the 2.4.4 to 2.4.9 lines at their 2026-aug builds and earlier, fixed by the September isolated patches (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18). Adobe states the StyleSmuggler hotfix is not in the September patch file.

    Adobe's bulletin for APSB26-138

  3. APSB26-92

    11 August 2026 Scheduled release

    August update: critical and important vulnerabilities

    Could lead to arbitrary code execution, security feature bypass and privilege escalation. Delivered as isolated patch files for the latest patch level of each line from 2.4.4 to 2.4.9.

    Adobe's bulletin for APSB26-92

  4. APSB26-73

    14 July 2026 Scheduled release

    July update: critical, important and moderate vulnerabilities

    Could lead to arbitrary code execution, security feature bypass and privilege escalation. The first of the 2026 bulletins shipped as isolated patch files rather than new Composer versions, one per line from 2.4.4 to 2.4.9.

    Adobe's bulletin for APSB26-73

  5. APSB26-49

    12 May 2026 Scheduled release

    May update: 15 vulnerabilities, Priority 2

    Could lead to arbitrary code execution, arbitrary file system write, denial of service and security feature bypass. Fixed in Adobe Commerce 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18, and in Magento Open Source 2.4.9, 2.4.8-p5, 2.4.7-p10 and 2.4.6-p15.

    Adobe's bulletin for APSB26-49

Earlier bulletins are on Adobe's Magento security index.

Running a version older than 2.4.4?

Then none of the bulletins above reach you. Adobe's 2026 patches start at the 2.4.4 line, so a store on any 2.3 release or on 2.4.0 to 2.4.3 has no official fix for StyleSmuggler or for anything else published this year. Unofficial backports exist, and they are a stopgap to be code-reviewed, not a plan.

The plan is an upgrade, or a move to another platform if the upgrade costs more than the store is worth on Magento. Until then, an edge rule in front of the store is the realistic protection, and we can help put one in place.

Common questions

How often does Adobe release Magento security patches?

Two ways. Scheduled bulletins, and in 2026 there has been one in each of July, August and September, now shipped as isolated patch files for each supported line. And out-of-band hotfixes when something is being exploited, which arrive whenever they arrive: APSB26-146 landed the day before the scheduled September release, not with it. The hotfixes are the ones that catch stores out, because they are separate from the scheduled release.

Does the September 2026 Magento update include the StyleSmuggler fix?

No. APSB26-138, the scheduled September release, does not contain the fix for CVE-2026-75650. That is the separate hotfix VULN-39341 from APSB26-146, and Adobe says it must be applied in addition to the September patches. A store reporting a 2026-sep build is not covered unless the hotfix was applied as well.

Which Magento versions still get security patches?

Across the 2026 bulletins, Adobe ships patches for the 2.4.4 line and newer, up to 2.4.9. Anything older, every 2.3 release and 2.4.0 to 2.4.3, receives nothing, including the StyleSmuggler hotfix. If your store is on one of those, the fix is an upgrade, and until then the realistic protection is an edge rule in front of the store.

How do we check which patches our store actually has?

Not from the version number alone. The version tells you which scheduled release you are on; it says nothing about hotfixes applied on top. Check wherever your team records applied patches, such as the Composer patch list or the Quality Patches Tool status, for the specific hotfix by name. If nobody can answer that in a few minutes, that is worth fixing before the next bulletin.

Can you apply the patches for us?

Yes. Same-day patching, including the out-of-band kind, is part of our Magento and Adobe Commerce support, and we take over stores other agencies built. If you only need a hand with one bulletin, get in touch; you do not need to be a client.

Commerce work we do