{"id":23695,"date":"2025-10-15T15:44:16","date_gmt":"2025-10-15T10:14:16","guid":{"rendered":"https:\/\/meetanshi.com\/blog\/?p=23695"},"modified":"2025-11-15T14:31:32","modified_gmt":"2025-11-15T09:01:32","slug":"apsb25-94-security-patches-for-magento","status":"publish","type":"post","link":"https:\/\/meetanshi.com\/blog\/apsb25-94-security-patches-for-magento\/","title":{"rendered":"[APSB25-94] Adobe Commerce\/Magento Security Patch"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On October 14, 2025, Adobe released a regular security update under the bulletin ID <a href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb25-94.html\" target=\"_blank\" rel=\"noopener\">APSB25-94<\/a>, addressing the critical and important security vulnerabilities in Magento Open Source &amp; Adobe Commerce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With a priority rating of 2, this security update should be applied promptly (ideally within a few weeks).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Failing to apply may allow attackers to bypass security features, escalate privileges, or execute arbitrary code on affected systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Affected Versions<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the list of affected versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected Versions<\/strong><\/td><\/tr><tr><td>Adobe Commerce<\/td><td>2.4.9-alpha2 and earlier&nbsp;<br>2.4.8-p2 and earlier&nbsp;<br>2.4.7-p7 and earlier&nbsp;<br>2.4.6-p12 and earlier&nbsp;<br>2.4.5-p14 and earlier&nbsp;<br>2.4.4-p15 and earlier<\/td><\/tr><tr><td>Adobe Commerce B2B<\/td><td>1.5.3-alpha2 and earlier&nbsp;<br>1.5.2-p2 and earlier&nbsp;<br>1.4.2-p7 and earlier&nbsp;<br>1.3.5-p12 and earlier&nbsp;<br>1.3.4-p14 and earlier&nbsp;<br>1.3.3-p15 and earlier<\/td><\/tr><tr><td>Magento Open Source<\/td><td>2.4.9-alpha2 and earlier&nbsp;<br>2.4.8-p2 and earlier&nbsp;<br>2.4.7-p7 and earlier&nbsp;<br>2.4.6-p12 and earlier&nbsp;<br>2.4.5-p14 and earlier<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">What Security Vulnerabilities are Addressed?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Magento APSB25-94 security update resolves five vulnerabilities, including two critical ones that could have severe impacts if exploited.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Vulnerability Category<\/strong><\/td><td><strong>Vulnerability Impact<\/strong><\/td><td><strong>Severity<\/strong><\/td><td><strong>CVE number(s)<\/strong><\/td><\/tr><tr><td>Improper Access Control&nbsp;<\/td><td>Security feature bypass<\/td><td>Critical<\/td><td>CVE-2025-54263<\/td><\/tr><tr><td>Cross-site Scripting (Stored XSS)<\/td><td>Privilege escalation<\/td><td>Critical<\/td><td>CVE-2025-54264<\/td><\/tr><tr><td>Incorrect Authorization<\/td><td>Security feature bypass<\/td><td>Important<\/td><td>CVE-2025-54265<\/td><\/tr><tr><td>Cross-site Scripting(Stored XSS)<\/td><td>Arbitrary code execution<\/td><td>Important<\/td><td>CVE-2025-54266<\/td><\/tr><tr><td>Incorrect Authorization<\/td><td>Privilege escalation<\/td><td>Important<\/td><td>CVE-2025-54267<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s why these vulnerabilities are very important to fix:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Improper access control vulnerability leads to a security feature bypass that allows an attacker to achieve a high confidentiality impact on your store.<\/li>\n\n\n\n<li>The stored XSS vulnerability enables privilege escalation. Letting the attacker add malicious scripts into the admin panel.<\/li>\n\n\n\n<li>Incorrect authorization allows hackers to remotely access the store without needing to log in to the store.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This update is critical because it patches prevent allowing an unauthenticated attacker to bypass security features to enabling authenticated attackers to fully compromise the administrative backend of your Magento 2 store.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Solution: Update the Magento 2 Versions&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Adobe recommends updating to the following versions to handle these vulnerabilities.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product&nbsp;<\/strong><\/td><td><strong>Updated Version<\/strong><\/td><\/tr><tr><td>Adobe Commerce<\/td><td>2.4.9-alpha3 for 2.4.9-alpha2&nbsp;<br>2.4.8-p3 for 2.4.8-p2 and earlier&nbsp;<br>2.4.7-p8 for 2.4.7-p7 and earlier&nbsp;<br>2.4.6-p13 for 2.4.6-p12 and earlier<br>2.4.5-p15 for 2.4.5-p14 and earlier&nbsp;<br>2.4.4 p16 for 2.4.4-p15 and earlier<\/td><\/tr><tr><td>Adobe Commerce B2B<\/td><td>1.5.3-alpha3 for 1.5.3-alpha2&nbsp;<br>1.5.2-p3 for 1.5.2-p2 and earlier&nbsp;<br>1.4.2-p8 for 1.4.2-p7 and earlier&nbsp;<br>1.3.4-p13 for 1.3.4-p12 and earlier<br>1.3.3-p14 for 1.3.3-p13 and earlier<br>1.3.3-p16 for 1.3.3-p15 and earlier<\/td><\/tr><tr><td>Magento Open Source<\/td><td>2.4.9-alpha3 for 2.4.9-alpha2&nbsp;<br>2.4.8-p3 for 2.4.8-p2 and earlier&nbsp;<br>2.4.7-p8 for 2.4.7-p7 and earlier&nbsp;<br>2.4.6-p13 for 2.4.6-p12 and earlier <br>2.4.5-p15 for 2.4.5-p14 and earlier<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Protect Your Store Now!<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We strongly recommend that all affected Adobe Commerce and Magento Open Source merchants should immediately take action.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re not comfortable performing these updates yourself, our Magento Security Patches Installation Service provides professional assistance to ensure a secure and seamless update process.<\/p>\n\n\n<div class=\"meetanshi-cta\">\r\n<div class=\"cta-content-wrapper\">\r\n<span>Magento 2 Security Patches Installation<\/span>\r\n<p>Keep your store secure with the latest Magento 2 patches\u2014add them before it\u2019s too late.<\/p>\r\n<a href=\"https:\/\/meetanshi.com\/magento-security-patches-installation-service.html\" target=\"_blank\" class=\"btn-primary\">Add Now <\/a>\r\n<\/div>\r\n<div class=\"cta-image-new\">\r\n<img decoding=\"async\" src=\"https:\/\/meetanshi.com\/blog\/wp-content\/uploads\/2025\/11\/security-patches-installation-service.png\" alt=\"Magento Security Patches Installation Service\">\r\n<\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On October 14, 2025, Adobe released a regular security update under the bulletin ID APSB25-94, addressing the critical and important security vulnerabilities in Magento Open&#8230;<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34],"tags":[],"class_list":["post-23695","post","type-post","status-publish","format-standard","hentry","category-magento"],"acf":[],"_links":{"self":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/23695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/comments?post=23695"}],"version-history":[{"count":10,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/23695\/revisions"}],"predecessor-version":[{"id":26101,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/23695\/revisions\/26101"}],"wp:attachment":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/media?parent=23695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/categories?post=23695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/tags?post=23695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}