Is Your Magento or Adobe Commerce Store Protected?
Adobe says CVE-2026-75650 is being actively exploited. A separate September security update also addresses additional vulnerabilities — and one patch does not cover everything.
September has two security tracks.
Treating the September update as a single “apply the patch” task can leave a store exposed. Adobe's guidance separates the emergency CVE-2026-75650 hotfix from the regular September security update.
APSB26-146 / VULN-39341
Addresses CVE-2026-75650, a critical vulnerability Adobe says is actively exploited. The hotfix is separate from the regular September isolated security patch.
APSB26-138
Addresses additional critical, important and moderate vulnerabilities. Adobe says it is not aware of exploitation in the wild for the vulnerabilities covered by this bulletin.
| Update | Date | What it addresses | Merchant action |
|---|---|---|---|
| APSB26-146 | Sep 7, 2026 | CVE-2026-75650 | Apply VULN-39341 hotfix |
| APSB26-138 | Sep 8, 2026 | Additional security vulnerabilities | Apply applicable Sep patch |
| Cloud Patches | Sep 8, 2026 | Cloud delivery of September fixes | Verify package / deployment state |
Check the exact product and patch level.
Adobe's September guidance is version-specific. The September APSB26-138 update affects Adobe Commerce 2.4.4 through 2.4.9 release lines, Adobe Commerce B2B 1.3.3 through 1.5.3 release lines, and Magento Open Source 2.4.6 through 2.4.9, depending on the exact August patch level.
Adobe Commerce / Magento Open Source
- Adobe Commerce: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier.
- Magento Open Source: 2.4.9-2026-aug and earlier through 2.4.6-2026-aug and earlier.
- Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, and 1.3.3-2026-aug and earlier.
What to verify first
- Exact Commerce / Magento release and security patch level.
- Installed B2B, PageBuilder and other Commerce components.
- Whether the September isolated patch sequence is complete.
- Whether the separate CVE-2026-75650 hotfix is present.
- Whether Adobe Commerce Cloud Patches are current, where applicable.
Eight critical vulnerabilities in the September security update.
Adobe's September 8 bulletin lists eight critical vulnerabilities covering stored XSS, incorrect authorization and path traversal. Two entries are specifically identified as B2B issues.
| CVE | Type | Impact | Auth. | CVSS | B2B |
|---|---|---|---|---|---|
| CVE-2026-76200 | Stored XSS | Privilege escalation | No | 9.3 Critical | — |
| CVE-2026-76201 | Stored XSS | Privilege escalation | No | 9.3 Critical | — |
| CVE-2026-77111 | Incorrect Authorization | Security feature bypass | Yes | 8.7 Critical | — |
| CVE-2026-77109 | Incorrect Authorization | Privilege escalation | No | 8.6 Critical | Yes |
| CVE-2026-77774 | Incorrect Authorization | Security feature bypass | No | 8.6 Critical | — |
| CVE-2026-76202 | Incorrect Authorization | Privilege escalation | No | 8.2 Critical | — |
| CVE-2026-77110 | Path Traversal | Security feature bypass | Yes | 7.6 Critical | — |
| CVE-2026-77108 | Incorrect Authorization | Privilege escalation | No | 7.5 Critical | Yes |
Patching is not the same as incident review.
Because Adobe says CVE-2026-75650 has been exploited in the wild, merchants who were running an affected installation should consider whether additional review is warranted after remediation.
Review the environment
- Admin and privileged-account activity.
- Unexpected code, files or configuration changes.
- Application, web-server and infrastructure logs.
- Custom modules and third-party extensions.
Rotate sensitive access
- Adobe Commerce encryption keys.
- Integration and API credentials.
- OAuth or application secrets.
- Payment, database, deployment and SSH credentials where applicable.
There is another deadline Cloud merchants need to know about.
Adobe's September 18, 2026 security-enforcement guidance adds version and third-party dependency requirements for Adobe Commerce on Cloud (PaaS) environments running 2.4.4 through 2.4.9.
Get a security assessment for your Magento or Adobe Commerce store.
A security review should cover the whole Commerce stack.
A patch can touch more than the core application. The review should account for the installed Commerce components, customizations, integrations and deployment environment around the fix.
Patch. Rotate. Review. Verify.
For an actively exploited vulnerability, remediation should not stop after a deployment succeeds.
Identify your exact version
Confirm the Magento or Adobe Commerce release and patch level before selecting the fix.
Apply the applicable patches
Address VULN-39341 and the separate September security fixes relevant to your environment.
Rotate keys & credentials
Follow Adobe's guidance for encryption-key rotation and associated credentials or secrets.
Review and verify
Check logs, deployment state, custom code and extensions, then verify remediation.
Don't let patching become a production outage.
Magento security work can involve custom modules, third-party extensions, payment integrations, APIs, ERP connections and deployment pipelines. Ceymox can help you assess the impact before and after remediation.
Find out what your store needs — before attackers do.
Share your store details and our Magento experts can identify the applicable September 2026 security actions, review the surrounding Commerce stack, and help define a safer remediation path for your production environment.