Adobe Security Bulletin – APSB26-92

On August 11, 2026, Adobe published APSB26-92, a security update for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The release resolves seven vulnerabilities rated critical, important, and moderate, including one unauthenticated, critical-severity issue. Adobe reports no known exploits in the wild for any of the issues addressed, but with public disclosure now in place, merchants should treat this Magento security update as a priority rather than something to schedule for later in the sprint.
Security update available for Adobe Commerce | APSB26-92
Key Details of the Security Update
APSB26-92 addresses vulnerabilities across three categories of impact:
- Privilege Escalation – unauthorized elevation of a user’s access level within the store or admin panel.
- Arbitrary Code Execution – delivered through stored cross-site scripting (XSS), allowing an attacker to run script in the context of another user’s session.
- Security Feature Bypass – circumvention of an authorization or access control check that should have blocked the action.
The Vulnerability That Needs Your Attention First
CVE-2026-71362 is the standout issue in this release: an incorrect-authorization vulnerability that scores 9.1 on the CVSS scale, requires no authentication and no admin privileges to exploit, and can lead to privilege escalation. Because it needs no credentials at all, it is reachable by any attacker who can hit the storefront, which makes it the item to patch first even though Adobe has not bundled it as a separately isolated patch the way some past bulletins have done.
Full Vulnerability Details
| CVE Number | Category | Impact | Severity | CVSS Score |
|---|---|---|---|---|
| CVE-2026-71362 | Incorrect Authorization | Privilege Escalation | Critical | 9.1 |
| CVE-2026-48413 | Stored XSS | Arbitrary Code Execution | Critical | 8.7 |
| CVE-2026-48414 | Stored XSS | Arbitrary Code Execution | Critical | 7.7 |
| CVE-2026-48415 | Incorrect Authorization | Security Feature Bypass | Critical | 7.6 |
| CVE-2026-48416 | Incorrect Authorization | Security Feature Bypass (B2B) | Critical | 7.5 |
| CVE-2026-48411 | Incorrect Authorization | Security Feature Bypass | Important | 6.8 |
| CVE-2026-48412 | Incorrect Authorization | Privilege Escalation | Moderate | 2.7 |
Who Should Apply This Adobe Commerce Security Update?
Adobe recommends this update for every merchant running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source. The table below summarizes affected and updated versions:
| Product | Affected Versions | Updated Version | Priority |
|---|---|---|---|
| Adobe Commerce | 2.4.4 through 2.4.9 (2026-jul builds and earlier) | 2.4.4 through 2.4.9 (2026-jul builds and earlier) | P2 |
| Adobe Commerce B2B | 1.3.3 through 1.5.3 (2026-jul builds and earlier) | 1.3.3 through 1.5.3 (2026-aug builds) | P2 |
| Magento Open Source | 2.4.6 through 2.4.9 (2026-jul builds and earlier) | 2.4.6 through 2.4.9 (2026-aug builds) | P2 |
Staying Ahead of the Next Magento Security Update
APSB26-92 is a reminder that Adobe Commerce and Magento Open Source receive security patches on a regular cadence, and each release is only protective if it actually gets installed. Merchants who fall behind on one bulletin tend to fall behind on the next, which compounds risk rather than spreading it out. Keeping a current patch baseline, testing updates in staging before they reach production, and monitoring Adobe’s security bulletins directly are the three habits that keep a store off the list of easy targets.
All Adobe Commerce & Magento security updates: Security Updates for Adobe Commerce
Need Adobe Commerce Support to Apply This Patch?
Crimson Agility’s Managed Services team provides ongoing Adobe Commerce support for merchants who would rather not carry patch management alone. With Crimson Agility, you can expect:
- Certified Magento developers who apply security patches without disrupting your storefront or checkout flow.
- Dedicated QA testing to confirm each patch is correctly applied before it reaches production.
- Proactive monitoring that flags the next Adobe security bulletin before it becomes an incident.
Best regards,
The Crimson Agility Team
Other Security Articles
- Security Update for Adobe Commerce & Magento Open Source: APSB26-92
by David Baier - Adobe Commerce & Magento Security Update: APSB25-71
by David Baier - Staying Ahead in E-Commerce: Why You Should Upgrade to Adobe Commerce 2.4.7
by Rebeka Calcagniti - Adobe Commerce & Magento Security Update: APSB24-73 (CVE-2024-45115)
by David Baier

