On September 8, 2026, Adobe released a critical security bulletin, APSB26-138, addressing multiple vulnerabilities in Adobe Commerce and Magento Open Source.
This update carries a Priority 2 rating. While Adobe reports no known exploits in the wild, the patch resolves severe security flaws that allow unauthorized privilege escalation and security bypass.
Staying ahead of these official patches is vital to secure customer transaction data and prevent administrative store takeover.
Who Is at Risk? (Affected Versions)
If your store runs any of the versions listed below, you are vulnerable to attacks. Review your current deployment to confirm if you need to patch:
| Product | Impacted Versions |
| Adobe Commerce | 2.4.9-2026-aug & earlier, 2.4.8-2026-aug & earlier, 2.4.7-2026-aug & earlier, 2.4.6-2026-aug & earlier, 2.4.5-2026-aug & earlier, 2.4.4-2026-aug & earlier |
| Magento Open Source | 2.4.9-2026-aug & earlier, 2.4.8-2026-aug & earlier, 2.4.7-2026-aug & earlier, 2.4.6-2026-aug & earlier |
| Adobe Commerce B2B | 1.5.3-2026-aug & earlier, 1.5.2-2026-aug & earlier, 1.4.2-2026-aug & earlier, 1.3.4-2026-aug & earlier, 1.3.3-2026-aug & earlier |
Critical Vulnerabilities Explained
The APSB26-138 update addresses multiple high-risk flaws, particularly Stored XSS and broken access controls. Several of these require no authentication, making them easy targets for attackers.
| Vulnerability Type | Potential Impact | Severity | CVSS | Requires Auth? | CVE Reference |
| Stored XSS | Privilege Escalation | Critical | 9.3 | No | CVE-2026-76200 |
| Stored XSS | Privilege Escalation | Critical | 9.3 | No | CVE-2026-76201 |
| Incorrect Authorization | Security Feature Bypass | Critical | 8.7 | Yes | CVE-2026-77111 |
| Incorrect Authorization | Privilege Escalation (B2B) | Critical | 8.6 | No | CVE-2026-77109 |
| Incorrect Authorization | Security Feature Bypass | Critical | 8.6 | No | CVE-2026-77774 |
| Incorrect Authorization | Privilege Escalation | Critical | 8.2 | No | CVE-2026-76202 |
| Path Traversal | Security Feature Bypass | Critical | 7.6 | Yes | CVE-2026-77110 |
| Incorrect Authorization | Privilege Escalation (B2B) | Critical | 7.5 | No | CVE-2026-77108 |
Key Risks:
- Stored XSS (CVE-2026-76200 & CVE-2026-76201): Attackers inject malicious scripts into your database without credentials. When an admin views the affected area, the script triggers privilege escalation.
- Incorrect Authorization: Multiple flaws permit malicious actors to bypass native access controls and execute restricted actions.
- Path Traversal (CVE-2026-77110): Allows attackers to access restricted file paths and bypass standard security boundaries.
The Fix: New Patched Versions Released
Adobe has delivered official lifecycle releases to fix these vulnerabilities. Upgrade your environment to the corresponding September 2026 release:
| Product | Patched Version (September 2026 Release) |
| Adobe Commerce | 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep |
| Magento Open Source | 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
| Adobe Commerce B2B | 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep |
Important Note on APSB26-146:
On September 7, 2026, Adobe issued emergency advisory APSB26-146. You must apply the separate hotfix for CVE-2026-75650 alongside APSB26-138 to stay fully protected.
Action Plan: How to Secure Your Store
Do not wait for active exploits. Follow these steps to secure your store:
1. Audit & Backup
- Run the Adobe Security Scan Tool to evaluate your current setup.
- Create a complete backup of your database, media directory, and configuration files.
2. Test in Staging
- Always apply the patch on a staging server first.
- Verify critical workflows: customer checkout, cart, payment gateways, and Magento 2 extensions.
3. Apply via CLI (Technical Upgrade)
Run Composer commands from your store’s root directory. Replace [VERSION] with your target build (e.g., 2.4.7-2026-sep):
Bash
composer require-community magento/product-community-edition=[VERSION] --no-update composer update php bin/magento setup:upgrade php bin/magento setup:di:compile php bin/magento setup:static-content:deploy -f php bin/magento cache:clean
Get Expert Magento Upgrade Support
Upgrading core platform files can create conflicts with third-party extensions, custom modules, and theme layouts.
Meetanshi offers a dedicated Magento Upgrade Service
to eliminate deployment risks. Our certified Adobe Commerce developers manage the entire cycle from audit and staging verification to production rollout with zero downtime.
Why choose Meetanshi?
- Full compatibility audit for all third-party modules and custom code.
- Proper application of both APSB26-138 and the CVE-2026-75650 hotfix.
- Zero data loss and verified post-upgrade performance.
Conclusion
The APSB26-138 update is essential to protect your store from critical unauthorized privilege escalation and security bypass flaws. Check your current Magento version, apply the new September 2026 patches in staging, and install the APSB26-146 hotfix to keep your store safe.
Enjoy a hassle free upgrade to the latest Magento version with our Adobe-certified experts.
Upgrade Now