{"id":20237,"date":"2025-08-13T13:14:05","date_gmt":"2025-08-13T07:44:05","guid":{"rendered":"https:\/\/meetanshi.com\/blog\/?p=20237"},"modified":"2025-08-14T11:24:48","modified_gmt":"2025-08-14T05:54:48","slug":"apsb25-71-security-patch-for-magento","status":"publish","type":"post","link":"https:\/\/meetanshi.com\/blog\/apsb25-71-security-patch-for-magento\/","title":{"rendered":"[APSB25-71] Security Patch for Adobe\u202fCommerce &amp;\u202fMagento Open Source"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On August 12, 2025, Adobe released a security update bulletin ID APSB25-71 with a priority rating of 2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When Adobe gives a priority of 2, it means:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>There are no vulnerabilities that have attack sites yet, but once they are known can cause harm<\/li>\n\n\n\n<li>You need install the updates soon (within a few days)<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Summary of APSB25-71 Security Update<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This security update resolves critical and important Magento vulnerabilities.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Which means, adding this update makes your server safe from hackers executing any programs, and restricts access to confidential data, or other store resources.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With this update, Adobe has fixed the flaws, and there are no attacks yet, but it is better to take action now and safeguard your store now than to be sorry later.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Vulnerability Details for Adobe Commerce, Adobe Commerce B2B, &amp; Magento Open Source&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Below, I have highlighted the impact of the vulnerability along with its Common Weakness Enumeration (CWE) identifier.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Improper Input Validation (CWE-20)<\/strong>: This vulnerability leads to an application denial-of-service.<\/li>\n\n\n\n<li><strong>Cross-Site Request Forgery (CWE-352)<\/strong>: This impacts privilege escalation.<\/li>\n\n\n\n<li><strong>Incorrect Authorization (CWE-863)<\/strong>: This might cause an arbitrary file system read.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Each vulnerability impact comes with a severity of <strong>critical<\/strong> and <strong>important<\/strong>.\u00a0There can be chances of your store becoming unresponsive or hackers getting access to sensitive files without any permission. Here are the rest of the <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb25-71.html\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability details<\/a> to know the other implication you might face.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Affected Versions + Solution to Fix the Vulnerabilities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The simple solution here is to update the versions of the Adobe Commerce, Adobe Commerce B2B, and Magento Open Source platforms with the latest versions mentioned by Adobe.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each version comes with a priority rating of 2, making it essential to update it within a few days.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected Version&nbsp;<\/strong><\/td><td><strong>Update Version&nbsp;<\/strong><\/td><\/tr><tr><td>Adobe Commerce<\/td><td>2.4.9-alpha1<br>2.4.8-p1 and earlier<br>2.4.7-p6 and earlier<br>2.4.6-p11 and earlier<br>2.4.5-p13 and earlier<br>2.4.4-p14 and earlier<\/td><td>2.4.9-alpha2<br>2.4.8-p2<br>2.4.7-p7<br>2.4.6-p12<br>2.4.5-p14<br>2.4.4-p15<\/td><\/tr><tr><td>Adobe Commerce B2B<\/td><td>1.5.3-alpha1<br>1.5.2-p1 and earlier<br>1.4.2-p6 and earlier<br>1.3.5-p11 and earlier<br>1.3.4-p13 and earlier<br>1.3.3-p14 and earlier<\/td><td>1.5.3-alpha2<br>1.5.2-p2<br>1.4.2-p7<br>1.3.4-p14<br>1.3.3-p15<\/td><\/tr><tr><td>Magento Open Source<\/td><td>2.4.9-alpha1<br>2.4.8-p1 and earlier<br>2.4.7-p6 and earlier<br>2.4.6-p11 and earlier<br>2.4.5-p13 and earlier<\/td><td>2.4.9-alpha2<br>2.4.8-p2<br>2.4.7-p7<br>2.4.6-p12<br>2.4.5-p14<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><div class=\"meetanshi-cta\">\r\n<div class=\"cta-content-wrapper\">\r\n<span>Magento 2 Security Patches Installation<\/span>\r\n<p>Keep your store secure with the latest Magento 2 patches\u2014add them before it\u2019s too late.<\/p>\r\n<a href=\"https:\/\/meetanshi.com\/magento-security-patches-installation-service.html\" target=\"_blank\" class=\"btn-primary\">Add Now <\/a>\r\n<\/div>\r\n<div class=\"cta-image-new\">\r\n<img decoding=\"async\" src=\"https:\/\/meetanshi.com\/blog\/wp-content\/uploads\/2025\/11\/security-patches-installation-service.png\" alt=\"Magento Security Patches Installation Service\">\r\n<\/div>\r\n<\/div><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The right action is to update your versions and avoid any kind of mishap that can affect your store negatively.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, before any other store task, make it a priority to update.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On August 12, 2025, Adobe released a security update bulletin ID APSB25-71 with a priority rating of 2. When Adobe gives a priority of 2,&#8230;<\/p>\n","protected":false},"author":5,"featured_media":20326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34],"tags":[],"class_list":["post-20237","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-magento"],"acf":[],"_links":{"self":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/20237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/comments?post=20237"}],"version-history":[{"count":14,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/20237\/revisions"}],"predecessor-version":[{"id":21601,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/20237\/revisions\/21601"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/media\/20326"}],"wp:attachment":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/media?parent=20237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/categories?post=20237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/tags?post=20237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}