APSB26-138: Magento Security Update September 2026

On September 8, 2026, Adobe released a critical security bulletin, APSB26-138, addressing multiple vulnerabilities in Adobe Commerce and Magento Open Source.

This update carries a Priority 2 rating. While Adobe reports no known exploits in the wild, the patch resolves severe security flaws that allow unauthorized privilege escalation and security bypass.

Staying ahead of these official patches is vital to secure customer transaction data and prevent administrative store takeover.

Who Is at Risk? (Affected Versions)

If your store runs any of the versions listed below, you are vulnerable to attacks. Review your current deployment to confirm if you need to patch:

ProductImpacted Versions
Adobe Commerce2.4.9-2026-aug & earlier, 2.4.8-2026-aug & earlier, 2.4.7-2026-aug & earlier, 2.4.6-2026-aug & earlier, 2.4.5-2026-aug & earlier, 2.4.4-2026-aug & earlier
Magento Open Source2.4.9-2026-aug & earlier, 2.4.8-2026-aug & earlier, 2.4.7-2026-aug & earlier, 2.4.6-2026-aug & earlier
Adobe Commerce B2B1.5.3-2026-aug & earlier, 1.5.2-2026-aug & earlier, 1.4.2-2026-aug & earlier, 1.3.4-2026-aug & earlier, 1.3.3-2026-aug & earlier

Critical Vulnerabilities Explained

The APSB26-138 update addresses multiple high-risk flaws, particularly Stored XSS and broken access controls. Several of these require no authentication, making them easy targets for attackers.

Vulnerability TypePotential ImpactSeverityCVSSRequires Auth?CVE Reference
Stored XSSPrivilege EscalationCritical9.3NoCVE-2026-76200
Stored XSSPrivilege EscalationCritical9.3NoCVE-2026-76201
Incorrect AuthorizationSecurity Feature BypassCritical8.7YesCVE-2026-77111
Incorrect AuthorizationPrivilege Escalation (B2B)Critical8.6NoCVE-2026-77109
Incorrect AuthorizationSecurity Feature BypassCritical8.6NoCVE-2026-77774
Incorrect AuthorizationPrivilege EscalationCritical8.2NoCVE-2026-76202
Path TraversalSecurity Feature BypassCritical7.6YesCVE-2026-77110
Incorrect AuthorizationPrivilege Escalation (B2B)Critical7.5NoCVE-2026-77108

Key Risks:

  • Stored XSS (CVE-2026-76200 & CVE-2026-76201): Attackers inject malicious scripts into your database without credentials. When an admin views the affected area, the script triggers privilege escalation.
  • Incorrect Authorization: Multiple flaws permit malicious actors to bypass native access controls and execute restricted actions.
  • Path Traversal (CVE-2026-77110): Allows attackers to access restricted file paths and bypass standard security boundaries.

The Fix: New Patched Versions Released

Adobe has delivered official lifecycle releases to fix these vulnerabilities. Upgrade your environment to the corresponding September 2026 release:

ProductPatched Version (September 2026 Release)
Adobe Commerce2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep
Magento Open Source2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
Adobe Commerce B2B1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep

Important Note on APSB26-146:

On September 7, 2026, Adobe issued emergency advisory APSB26-146. You must apply the separate hotfix for CVE-2026-75650 alongside APSB26-138 to stay fully protected.

Action Plan: How to Secure Your Store

Do not wait for active exploits. Follow these steps to secure your store:

1. Audit & Backup

  • Run the Adobe Security Scan Tool to evaluate your current setup.
  • Create a complete backup of your database, media directory, and configuration files.

2. Test in Staging

  • Always apply the patch on a staging server first.
  • Verify critical workflows: customer checkout, cart, payment gateways, and Magento 2 extensions.

3. Apply via CLI (Technical Upgrade)

Run Composer commands from your store’s root directory. Replace [VERSION] with your target build (e.g., 2.4.7-2026-sep):

Bash

composer require-community magento/product-community-edition=[VERSION] --no-update
composer update
php bin/magento setup:upgrade
php bin/magento setup:di:compile
php bin/magento setup:static-content:deploy -f
php bin/magento cache:clean

Get Expert Magento Upgrade Support

Upgrading core platform files can create conflicts with third-party extensions, custom modules, and theme layouts.

Meetanshi offers a dedicated Magento Upgrade Service

to eliminate deployment risks. Our certified Adobe Commerce developers manage the entire cycle from audit and staging verification to production rollout with zero downtime.

Why choose Meetanshi?

  • Full compatibility audit for all third-party modules and custom code.
  • Proper application of both APSB26-138 and the CVE-2026-75650 hotfix.
  • Zero data loss and verified post-upgrade performance.

Conclusion

The APSB26-138 update is essential to protect your store from critical unauthorized privilege escalation and security bypass flaws. Check your current Magento version, apply the new September 2026 patches in staging, and install the APSB26-146 hotfix to keep your store safe.

Move to Magento 2.4.8

Enjoy a hassle free upgrade to the latest Magento version with our Adobe-certified experts.

Upgrade Now
Upgrade Magento 2

Sanjay Jethva

Article by

Sanjay Jethva

Sanjay is the co-founder and CTO of Meetanshi with hands-on expertise with Magento since 2011. He specializes in complex development, integrations, extensions, and customizations. Sanjay is one the top 50 contributor to the Magento community and is recognized by Adobe. His passion for Magento 2 and Shopify solutions has made him a trusted source for...