Site Security, Health, & Performance
Site Security, Health, & Performance

Security Update for Adobe Commerce & Magento Open Source: APSB26-92

BY David Baier
August 11, 2026

Adobe Security Bulletin – APSB26-92

On August 11, 2026, Adobe published APSB26-92, a security update for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The release resolves seven vulnerabilities rated critical, important, and moderate, including one unauthenticated, critical-severity issue. Adobe reports no known exploits in the wild for any of the issues addressed, but with public disclosure now in place, merchants should treat this Magento security update as a priority rather than something to schedule for later in the sprint.

Security update available for Adobe Commerce | APSB26-92

 

 

Key Details of the Security Update

APSB26-92 addresses vulnerabilities across three categories of impact:

  • Privilege Escalation – unauthorized elevation of a user’s access level within the store or admin panel.
  • Arbitrary Code Execution – delivered through stored cross-site scripting (XSS), allowing an attacker to run script in the context of another user’s session.
  • Security Feature Bypass – circumvention of an authorization or access control check that should have blocked the action.

The Vulnerability That Needs Your Attention First

CVE-2026-71362 is the standout issue in this release: an incorrect-authorization vulnerability that scores 9.1 on the CVSS scale, requires no authentication and no admin privileges to exploit, and can lead to privilege escalation. Because it needs no credentials at all, it is reachable by any attacker who can hit the storefront, which makes it the item to patch first even though Adobe has not bundled it as a separately isolated patch the way some past bulletins have done.

Full Vulnerability Details

CVE Number Category Impact Severity CVSS Score
CVE-2026-71362 Incorrect Authorization Privilege Escalation Critical 9.1
CVE-2026-48413 Stored XSS Arbitrary Code Execution Critical 8.7
CVE-2026-48414 Stored XSS Arbitrary Code Execution Critical 7.7
CVE-2026-48415 Incorrect Authorization Security Feature Bypass Critical 7.6
CVE-2026-48416 Incorrect Authorization Security Feature Bypass (B2B) Critical 7.5
CVE-2026-48411 Incorrect Authorization Security Feature Bypass Important 6.8
CVE-2026-48412 Incorrect Authorization Privilege Escalation Moderate 2.7
CVE-2026-48416 affects the Adobe Commerce B2B module specifically. Full CVSS vectors and researcher acknowledgements are available in Adobe’s official bulletin.

Who Should Apply This Adobe Commerce Security Update?

Adobe recommends this update for every merchant running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source. The table below summarizes affected and updated versions:

Product Affected Versions Updated Version Priority
Adobe Commerce 2.4.4 through 2.4.9 (2026-jul builds and earlier) 2.4.4 through 2.4.9 (2026-jul builds and earlier) P2
Adobe Commerce B2B 1.3.3 through 1.5.3 (2026-jul builds and earlier) 1.3.3 through 1.5.3 (2026-aug builds) P2
Magento Open Source 2.4.6 through 2.4.9 (2026-jul builds and earlier) 2.4.6 through 2.4.9 (2026-aug builds) P2

Staying Ahead of the Next Magento Security Update

APSB26-92 is a reminder that Adobe Commerce and Magento Open Source receive security patches on a regular cadence, and each release is only protective if it actually gets installed. Merchants who fall behind on one bulletin tend to fall behind on the next, which compounds risk rather than spreading it out. Keeping a current patch baseline, testing updates in staging before they reach production, and monitoring Adobe’s security bulletins directly are the three habits that keep a store off the list of easy targets.

All Adobe Commerce & Magento security updates: Security Updates for Adobe Commerce

Need Adobe Commerce Support to Apply This Patch?

Crimson Agility’s Managed Services team provides ongoing Adobe Commerce support for merchants who would rather not carry patch management alone. With Crimson Agility, you can expect:

  • Certified Magento developers who apply security patches without disrupting your storefront or checkout flow.
  • Dedicated QA testing to confirm each patch is correctly applied before it reaches production.
  • Proactive monitoring that flags the next Adobe security bulletin before it becomes an incident.

Best regards,
The Crimson Agility Team

Other Security Articles

On this page

  • Loading...

Popular Tags

recent posts

Ecommerce Strategy for 2026: Why AI Commerce Investments Keep Underperforming

Beyond the Ban: Strategic Advertising & Organic Growth for Regulated 2A E-Commerce

Security Update for Adobe Commerce & Magento Open Source: APSB26-92

Product Data vs Product Pages: Why AI Search Changes Everything

How AI Search Works: From Keywords to Recommendations

NEWSLETTER

Subscribe for latest resources

Commerce systems your team controls. Data AI can trust.

Powerful, scalable, and customer-centric commerce solutions tailored for your growth.

Subscribe for Latest Resources

Fill out the form below, and receive the latest in blogs, webinars and more.

Ready to Transform Your Commerce Business?

Fill out the form below, and we will be in touch shortly.