{"id":26856,"date":"2026-09-15T11:18:41","date_gmt":"2026-09-15T05:48:41","guid":{"rendered":"https:\/\/meetanshi.com\/blog\/?p=26856"},"modified":"2026-09-15T11:18:42","modified_gmt":"2026-09-15T05:48:42","slug":"apsb26-138-security-update-available-adobe-commerce","status":"publish","type":"post","link":"https:\/\/meetanshi.com\/blog\/apsb26-138-security-update-available-adobe-commerce\/","title":{"rendered":"APSB26-138: Magento Security Update September 2026"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On September 8, 2026, Adobe released a critical security bulletin, APSB26-138, addressing multiple vulnerabilities in Adobe Commerce and Magento Open Source.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This update carries a Priority 2 rating. While Adobe reports no known exploits in the wild, the patch resolves severe security flaws that allow unauthorized privilege escalation and security bypass.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Staying ahead of these official patches is vital to secure customer transaction data and prevent administrative store takeover.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who Is at Risk? (Affected Versions)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your store runs any of the versions listed below, you are vulnerable to attacks. Review your current deployment to confirm if you need to patch:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Product<\/strong><\/td><td><strong>Impacted Versions<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Adobe Commerce<\/strong><\/td><td><code>2.4.9-2026-aug<\/code> &amp; earlier, <code>2.4.8-2026-aug<\/code> &amp; earlier, <code>2.4.7-2026-aug<\/code> &amp; earlier, <code>2.4.6-2026-aug<\/code> &amp; earlier, <code>2.4.5-2026-aug<\/code> &amp; earlier, <code>2.4.4-2026-aug<\/code> &amp; earlier<\/td><\/tr><tr><td><strong>Magento Open Source<\/strong><\/td><td><code>2.4.9-2026-aug<\/code> &amp; earlier, <code>2.4.8-2026-aug<\/code> &amp; earlier, <code>2.4.7-2026-aug<\/code> &amp; earlier, <code>2.4.6-2026-aug<\/code> &amp; earlier<\/td><\/tr><tr><td><strong>Adobe Commerce B2B<\/strong><\/td><td><code>1.5.3-2026-aug<\/code> &amp; earlier, <code>1.5.2-2026-aug<\/code> &amp; earlier, <code>1.4.2-2026-aug<\/code> &amp; earlier, <code>1.3.4-2026-aug<\/code> &amp; earlier, <code>1.3.3-2026-aug<\/code> &amp; earlier<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Critical Vulnerabilities Explained<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The APSB26-138 update addresses multiple high-risk flaws, particularly Stored XSS and broken access controls. Several of these require no authentication, making them easy targets for attackers.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Vulnerability Type<\/strong><\/td><td><strong>Potential Impact<\/strong><\/td><td><strong>Severity<\/strong><\/td><td><strong>CVSS<\/strong><\/td><td><strong>Requires Auth?<\/strong><\/td><td><strong>CVE Reference<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Stored XSS<\/strong><\/td><td>Privilege Escalation<\/td><td>Critical<\/td><td>9.3<\/td><td>No<\/td><td>CVE-2026-76200<\/td><\/tr><tr><td><strong>Stored XSS<\/strong><\/td><td>Privilege Escalation<\/td><td>Critical<\/td><td>9.3<\/td><td>No<\/td><td>CVE-2026-76201<\/td><\/tr><tr><td><strong>Incorrect Authorization<\/strong><\/td><td>Security Feature Bypass<\/td><td>Critical<\/td><td>8.7<\/td><td>Yes<\/td><td>CVE-2026-77111<\/td><\/tr><tr><td><strong>Incorrect Authorization<\/strong><\/td><td>Privilege Escalation (B2B)<\/td><td>Critical<\/td><td>8.6<\/td><td>No<\/td><td>CVE-2026-77109<\/td><\/tr><tr><td><strong>Incorrect Authorization<\/strong><\/td><td>Security Feature Bypass<\/td><td>Critical<\/td><td>8.6<\/td><td>No<\/td><td>CVE-2026-77774<\/td><\/tr><tr><td><strong>Incorrect Authorization<\/strong><\/td><td>Privilege Escalation<\/td><td>Critical<\/td><td>8.2<\/td><td>No<\/td><td>CVE-2026-76202<\/td><\/tr><tr><td><strong>Path Traversal<\/strong><\/td><td>Security Feature Bypass<\/td><td>Critical<\/td><td>7.6<\/td><td>Yes<\/td><td>CVE-2026-77110<\/td><\/tr><tr><td><strong>Incorrect Authorization<\/strong><\/td><td>Privilege Escalation (B2B)<\/td><td>Critical<\/td><td>7.5<\/td><td>No<\/td><td>CVE-2026-77108<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Key Risks:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Stored XSS (CVE-2026-76200 &amp; CVE-2026-76201):<\/strong> Attackers inject malicious scripts into your database without credentials. When an admin views the affected area, the script triggers privilege escalation.<\/li>\n\n\n\n<li><strong>Incorrect Authorization:<\/strong> Multiple flaws permit malicious actors to bypass native access controls and execute restricted actions.<\/li>\n\n\n\n<li><strong>Path Traversal (CVE-2026-77110):<\/strong> Allows attackers to access restricted file paths and bypass standard security boundaries.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The Fix: New Patched Versions Released<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Adobe has delivered official lifecycle releases to fix these vulnerabilities. Upgrade your environment to the corresponding September 2026 release:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><td><strong>Product<\/strong><\/td><td><strong>Patched Version (September 2026 Release)<\/strong><\/td><\/tr><\/thead><tbody><tr><td><strong>Adobe Commerce<\/strong><\/td><td><code>2.4.9-2026-sep<\/code>, <code>2.4.8-2026-sep<\/code>, <code>2.4.7-2026-sep<\/code>, <code>2.4.6-2026-sep<\/code>, <code>2.4.5-2026-sep<\/code>, <code>2.4.4-2026-sep<\/code><\/td><\/tr><tr><td><strong>Magento Open Source<\/strong><\/td><td><code>2.4.9-2026-sep<\/code>, <code>2.4.8-2026-sep<\/code>, <code>2.4.7-2026-sep<\/code><\/td><\/tr><tr><td><strong>Adobe Commerce B2B<\/strong><\/td><td><code>1.5.3-2026-sep<\/code>, <code>1.5.2-2026-sep<\/code>, <code>1.4.2-2026-sep<\/code>, <code>1.3.4-2026-sep<\/code>, <code>1.3.3-2026-sep<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important Note on APSB26-146:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On September 7, 2026, Adobe issued emergency advisory APSB26-146. You must apply the separate hotfix for CVE-2026-75650 alongside APSB26-138 to stay fully protected.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Action Plan: How to Secure Your Store<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not wait for active exploits. Follow these steps to secure your store:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Audit &amp; Backup<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Run the Adobe Security Scan Tool to evaluate your current setup.<\/li>\n\n\n\n<li>Create a complete backup of your database, media directory, and configuration files.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2. Test in Staging<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Always apply the patch on a staging server first.<\/li>\n\n\n\n<li>Verify critical workflows: customer checkout, cart, payment gateways, and <a href=\"https:\/\/meetanshi.com\/magento-2-extensions.html\" target=\"_blank\" rel=\"noreferrer noopener\">Magento 2 extensions<\/a>.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3. Apply via CLI (Technical Upgrade)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Run Composer commands from your store\u2019s root directory. Replace <code>[VERSION]<\/code> with your target build (e.g., <code>2.4.7-2026-sep<\/code>):<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bash<\/p>\n\n\n\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\" data-enlighter-theme=\"\" data-enlighter-highlight=\"\" data-enlighter-linenumbers=\"\" data-enlighter-lineoffset=\"\" data-enlighter-title=\"\" data-enlighter-group=\"\">composer require-community magento\/product-community-edition=[VERSION] --no-update\ncomposer update\nphp bin\/magento setup:upgrade\nphp bin\/magento setup:di:compile\nphp bin\/magento setup:static-content:deploy -f\nphp bin\/magento cache:clean\n<\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">Get Expert Magento Upgrade Support<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Upgrading core platform files can create conflicts with third-party extensions, custom modules, and theme layouts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meetanshi offers a dedicated Magento Upgrade Service<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">to eliminate deployment risks. Our certified Adobe Commerce developers manage the entire cycle from audit and staging verification to production rollout with zero downtime.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why choose Meetanshi?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Full compatibility audit for all third-party modules and custom code.<\/li>\n\n\n\n<li>Proper application of both APSB26-138 and the CVE-2026-75650 hotfix.<\/li>\n\n\n\n<li>Zero data loss and verified post-upgrade performance.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The APSB26-138 update is essential to protect your store from critical unauthorized privilege escalation and security bypass flaws. Check your current Magento version, apply the new September 2026 patches in staging, and install the APSB26-146 hotfix to keep your store safe.<\/p>\n\n\n<div class=\"meetanshi-cta\">\r\n<div class=\"cta-content-wrapper\">\r\n<span>Move to Magento 2.4.8<\/span>\r\n<p>Enjoy a hassle free upgrade to the latest Magento version with our Adobe-certified experts.<\/p>\r\n<a href=\"https:\/\/meetanshi.com\/magento-upgrade-service.html\" target=\"_blank\" class=\"btn-primary\">Upgrade Now<\/a>\r\n<\/div>\r\n<div class=\"cta-image-new\">\r\n<img decoding=\"async\" src=\"https:\/\/meetanshi.com\/blog\/wp-content\/uploads\/2025\/10\/magento-2-upgrade-service.svg\" alt=\"Upgrade Magento 2\">\r\n<\/div>\r\n<\/div>\r\n\r\n\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 8, 2026, Adobe released a critical security bulletin, APSB26-138, addressing multiple vulnerabilities in Adobe Commerce and Magento Open Source. This update carries a&#8230;<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[34],"tags":[],"class_list":["post-26856","post","type-post","status-publish","format-standard","hentry","category-magento"],"acf":[],"_links":{"self":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/26856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/comments?post=26856"}],"version-history":[{"count":3,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/26856\/revisions"}],"predecessor-version":[{"id":26862,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/posts\/26856\/revisions\/26862"}],"wp:attachment":[{"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/media?parent=26856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/categories?post=26856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/meetanshi.com\/blog\/wp-json\/wp\/v2\/tags?post=26856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}