MAGENTO & ADOBE COMMERCE SECURITY • SEPTEMBER 2026

September 2026 Magento Security Update:
What Adobe Commerce Merchants Need to Know

Adobe has issued two separate September security updates — including an actively exploited critical vulnerability and a broader monthly security release. Here’s what changed across Adobe Commerce, Magento Open Source, B2B, and Cloud.

Security update
September 2026
14 min read
Priority 1 CVE-2026-75650
Monthly bulletin APSB26-138
Remediation Patch + Verify
Security control center / 09.2026
Action required
September 07

Emergency Hotfix

Critical unauthenticated RCE with confirmed exploitation in the wild.

VULN-39341
Store
Security
September 08

Monthly Security Update

Eight CVEs across Commerce, B2B, and Magento Open Source release lines.

APSB26-138
Hotfix is separate
v1.1.20 / v1.1.21

September 2026 is not a normal Magento security month. Adobe released two separate security bulletins within 24 hours for Adobe Commerce and Magento Open Source: an emergency Priority 1 update for CVE-2026-75650 on September 7, followed by the regularly scheduled September security update on September 8.

The distinction matters because the monthly September isolated patch does not include the CVE-2026-75650 hotfix. Adobe’s own September guidance tells merchants to apply the hotfix separately. For Adobe Commerce on Cloud, the fixes are also delivered through two different Cloud Patches for Commerce package releases.

September 2026 at a Glance

10.0
CVSS · CVE-2026-75650

Critical unauthenticated arbitrary code execution. Adobe confirms exploitation in the wild.

8
CVE entries · APSB26-138

The bulletin’s vulnerability table marks all eight as Critical, with CVSS scores from 7.5 to 9.3.

What Adobe Released — and Why There Are Two Security Streams

APSB26-146 was published on September 7, 2026 with Adobe Commerce priority rating 1. It addresses CVE-2026-75650, an improper-neutralization flaw in a template engine that Adobe rates Critical, CVSS 10.0, requiring neither authentication nor user interaction for exploitation. Adobe says it is aware of exploitation in the wild.

On September 8, Adobe published APSB26-138, its scheduled September security update. Adobe says it resolves critical, important, and moderate vulnerabilities; its vulnerability table lists eight CVEs, each marked Critical. The bulletin covers Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe also explicitly warns that the CVE-2026-75650 hotfix must be applied in addition to the September security fixes.

September 7 · APSB26-146

CVE-2026-75650

Critical · CVSS 10.0 · Priority 1
Unauthenticated arbitrary code execution. Adobe confirms exploitation in the wild. Fix: VULN-39341 hotfix.

September 8 · APSB26-138

September Monthly Security Update

Priority 2 · 8 CVEs
Stored XSS, incorrect authorization, and path traversal vulnerabilities. Delivered as version-specific isolated security patches.

Installing the September isolated patch does not mean CVE-2026-75650 is fixed.
Adobe’s two September security streams must be treated as two separate remediation actions.

CVE-2026-75650: The Emergency Magento / Adobe Commerce Hotfix

Adobe classifies CVE-2026-75650 as an improper neutralization of special elements used in a template engine (CWE-1336). The bulletin assigns a CVSS base score of 10.0, marks it Critical, and records that no authentication is required.

Independent research from Sansec reported exploitation beginning September 4, before Adobe’s September 7 hotfix. Akamai later confirmed active exploitation attempts and described a chain in which attacker-controlled data reaches Magento’s template-processing flow. Those independent findings reinforce Adobe’s “exploited in the wild” designation, but the Adobe bulletin remains the authoritative source for the affected product versions and official fix.

Why this is an application-security issue
Remote code execution can turn a storefront vulnerability into an environment-level incident.

Magento and Adobe Commerce installations commonly connect to payment gateways, ERP and CRM systems, shipping and tax services, third-party extensions, APIs, deployment tooling, and customer data. A vulnerable application layer therefore needs incident-aware remediation, not just a version-number check.

Adobe’s VULN-39341 hotfix matrix

Affected baselineAdobe hotfix package
2.4.9-2026-aug/jul; 2.4.8-2026-aug/jul; 2.4.7-2026-aug/jul; 2.4.6-2026-aug/jul; 2.4.5-2026-aug/jul; 2.4.4-2026-aug/jul; plus 2.4.8-p5/p4, 2.4.7-p10/p9, 2.4.6-p15/p14, 2.4.5-p17/p16, 2.4.4-p18/p17VULN-39341-composer-patches.zip
2.4.8-p3, 2.4.8-p2VULN-39341_248-p3.patch.zip
2.4.8-p1, 2.4.8VULN-39341_248-p1.patch.zip
2.4.7-p8, 2.4.7-p7VULN-39341_247-p8.patch.zip
2.4.7 through 2.4.7-p6VULN-39341_247-p5.patch.zip
2.4.6-p13/p12; 2.4.5-p15/p14; 2.4.4-p16/p15VULN-39341_246-p13.patch.zip
2.4.6 through 2.4.6-p11; 2.4.5 through 2.4.5-p13; 2.4.4 through 2.4.4-p14VULN-39341_246-p11.patch.zip

Adobe’s September 21 Knowledge Base update expands the official hotfix compatibility for the 2.4.4–2.4.7 lines. Always use the package mapped to the exact installed version or patch level in Adobe’s current KB rather than copying a patch from another baseline.

The Full APSB26-138 Vulnerability List

The original draft is incomplete here. Adobe’s official bulletin lists eight CVEs, and two are specific to the Adobe Commerce B2B component.

CVECategoryImpactAuth.CVSSScope
CVE-2026-76200Stored XSS (CWE-79)Privilege escalationNo9.3Adobe Commerce / Magento Open Source
CVE-2026-76201Stored XSS (CWE-79)Privilege escalationNo9.3Adobe Commerce / Magento Open Source
CVE-2026-77111Incorrect AuthorizationSecurity feature bypassYes8.7Commerce
CVE-2026-77109Incorrect AuthorizationPrivilege escalationNo8.6B2B
CVE-2026-77774Incorrect AuthorizationSecurity feature bypassNo8.6Commerce / Open Source
CVE-2026-76202Incorrect AuthorizationPrivilege escalationNo8.2Commerce / Open Source
CVE-2026-77110Path Traversal (CWE-22)Security feature bypassYes7.6Commerce / Open Source
CVE-2026-77108Incorrect AuthorizationPrivilege escalationNo7.5B2B

Six of the eight CVEs in APSB26-138 are recorded by Adobe as exploitable without authentication. The two B2B-specific issues are CVE-2026-77109 and CVE-2026-77108. Adobe says it is not aware of exploitation in the wild for the issues addressed by APSB26-138.

Which Adobe Commerce and Magento Versions Are Affected?

For APSB26-146, Adobe lists Adobe Commerce 2.4.4 through 2.4.9 at the August 2026 release level and earlier, Adobe Commerce B2B 1.3.3 through 1.5.3 at the August 2026 level and earlier, and Magento Open Source 2.4.4 through 2.4.9 at the August 2026 level and earlier as affected.

For the regular September update APSB26-138, Adobe lists affected Adobe Commerce lines 2.4.4 through 2.4.9 and B2B 1.3.3 through 1.5.3. The fixed September versions are:

Adobe Commerce 2.4.4-2026-sep 2.4.5-2026-sep 2.4.6-2026-sep 2.4.7-2026-sep 2.4.8-2026-sep 2.4.9-2026-sep

Adobe also lists B2B fixed versions 1.3.3-2026-sep through 1.5.3-2026-sep. For Magento Open Source, the September bulletin lists fixed versions 2.4.7-2026-sep, 2.4.8-2026-sep, and 2.4.9-2026-sep.

Important for Magento Open Source 2.4.4–2.4.6: Adobe’s APSB26-138 bulletin still lists those lines as affected, but its September solution table only lists fixed Open Source releases for 2.4.7–2.4.9. Do not interpret “2.4.x” as automatically protected. Separately, Adobe’s APSB26-146 hotfix covers the CVE-2026-75650 issue across the 2.4.4–2.4.9 range.

September’s Isolated Patches: Every Release-Line Download

Adobe classified the September 8 security fixes as isolated security fixes. These are narrowly scoped patch files rather than new Composer security packages. Adobe’s September KB provides one ZIP per supported Adobe Commerce release line:

Release lineSeptember isolated patchBaseline requirement
Adobe Commerce 2.4.92-4-9-sep-2026.zipLatest security-only release line + prior isolated patches
Adobe Commerce 2.4.8-p52-4-8-p5-sep-2026.zip2.4.8-p5 + prior monthly isolated patches
Adobe Commerce 2.4.7-p102-4-7-p10-sep-2026.zip2.4.7-p10 + prior monthly isolated patches
Adobe Commerce 2.4.6-p152-4-6-p15-sep-2026.zip2.4.6-p15 + prior monthly isolated patches
Adobe Commerce 2.4.5-p172-4-5-p17-sep-2026.zip2.4.5-p17 + prior monthly isolated patches
Adobe Commerce 2.4.4-p182-4-4-p18-sep-2026.zip2.4.4-p18 + prior monthly isolated patches

The ZIP can contain separate patch files for installed components such as CE, EE, B2B, PageBuilder, and other modules. Adobe instructs merchants to apply the file that matches each installed component and then verify the resulting security state.

How Adobe’s New Monthly Isolated-Patch Model Changes Patching

Adobe’s new model is designed to shorten the time between vulnerability disclosure and targeted remediation. An isolated patch contains only the code needed to address specified vulnerabilities and is folded into the next full security patch release.

01
Check the baseline
Move to the latest security-only -p baseline for your supported release line before applying the isolated file.
VersionPatch levelComponents
02
Apply missed monthly patches in order
Isolated security patches are non-cumulative. A missed July or August patch cannot simply be replaced by September.
JulyAugustSeptember
03
Apply VULN-39341 separately
The CVE-2026-75650 hotfix is not part of the September isolated patch. Adobe says there is no required install order between the hotfix and September isolated patch, but the hotfix should be applied as soon as possible.
VULN-39341Priority 1
04
Verify the outcome
Use Adobe’s Commerce Version Tool to identify applied and missing monthly patches and the CVEs for which the installation is protected.
CVTProtectedMissing

Adobe Commerce on Cloud: Two Cloud Patch Package Releases

For Adobe Commerce on Cloud infrastructure, Adobe distributes critical fixes through the Cloud Patches for Commerce package, which is a dependency of ECE-Tools.

September 8, 2026 — Cloud Patches for Commerce

v1.1.20 includes the September isolated security fixes referenced by APSB26-138.

v1.1.21 includes the security fixes referenced by APSB26-146 for CVE-2026-75650.

Adobe’s current Cloud guidance recommends keeping ECE-Tools up to date so the latest Cloud Patches package is brought into deployment.

Do not double-apply the same cloud-delivered fix. Adobe’s APSB26-138 KB notes that if the fix is already supplied by the latest Cloud Patches update, manually applying the corresponding isolated patch can cause installation failures.

Patch Is Not the Same as Remediation

The most important operational instruction in Adobe’s CVE-2026-75650 guidance goes beyond the code change itself: rotate the encryption key and the credentials that could have been encrypted or exposed using it.

Adobe explicitly calls out Admin passwords, REST/SOAP/GraphQL integration tokens, OAuth client secrets, payment-gateway API credentials, database credentials, SSH/deployment keys, and API credentials for shipping, tax, and other integrated services.

Apply VULN-39341
Enable controlled maintenance / pause scheduled jobs as appropriate
Rotate Admin + integration + OAuth + payment + API credentials at source
Flush / redeploy / verify

Adobe also makes an important distinction: rotating the encryption key alone does not invalidate credentials that may already have been exposed. The associated credentials must be rotated at their respective systems or providers.

What About a Store That May Already Have Been Exploited?

A successful patch closes the vulnerable code path; it does not prove that no attacker reached the system before the fix existed. Sansec reported exploitation beginning September 4, before Adobe released the September 7 hotfix, and recommends scanning for compromise rather than assuming a clean state from a patch status alone.

For an affected production environment, the incident question is therefore broader than “Did we install the patch?” Security teams should review application and infrastructure logs, unexpected admin activity, filesystem changes, cron or process anomalies, outbound connections, modified templates or CMS content, suspicious integration credentials, and signs of persistence.

Operational rule
If the store was exposed during the active-exploitation window, treat patching and compromise assessment as separate workstreams.

What Every Magento / Adobe Commerce Merchant Should Do Now

1
Identify the exact product, release line, patch level, B2B modules, and installed components.
2
Apply the VULN-39341 hotfix for CVE-2026-75650. Adobe says the hotfix can be applied before or after the September isolated patch.
3
Bring the installation to the latest security-only -p baseline and apply any missed monthly isolated patches in sequence.
4
For Cloud, confirm the matching Cloud Patches for Commerce package is deployed and avoid duplicate manual patching.
5
Rotate encryption keys and all associated credentials at their sources.
6
Use the Commerce Version Tool / cloud patch status tools to verify protected vs. vulnerable CVEs.
7
Review production logs and infrastructure for signs of unauthorized activity.
8
Regression-test checkout, payments, integrations, cron, APIs, extensions, and custom code before closing the remediation ticket.

One More Adobe Commerce Cloud Consideration

Adobe has also published a separate security-enforcement policy for Adobe Commerce on Cloud PaaS environments running 2.4.4 through 2.4.9. That policy is distinct from the September CVE patches, but it matters for merchants maintaining older Cloud environments.

Adobe says 2.4.4/2.4.5 Cloud environments have a June 1, 2027 deadline to upgrade to a supported Commerce version or migrate to Adobe Commerce as a Cloud Service, while 2.4.6/2.4.7 have a June 1, 2028 deadline. Adobe also lists separate third-party dependency deadlines beginning October 30, 2026 for certain unsupported MariaDB, Elasticsearch/OpenSearch, and RabbitMQ configurations.

Separate the two conversations: a store can be patched for September 2026 vulnerabilities and still have an unsupported operating baseline, third-party dependency, extension, or custom-code security problem. A security assessment should evaluate the whole application stack.

Is Your Magento or Adobe Commerce Store Actually Secure?

Ceymox can assess your Magento / Adobe Commerce environment for patch status, vulnerable release lines, custom-code and extension exposure, security hardening gaps, and post-patch verification requirements.

Patch the code. Verify the environment. Close the security gaps.

GET A MAGENTO SECURITY ASSESSMENT →

Final Takeaway

The right way to read Adobe’s September 2026 security releases is not “Adobe released a September patch.” Adobe released two separate security streams.

APSB26-146 is the emergency Priority 1 response to the actively exploited CVE-2026-75650, fixed through the VULN-39341 hotfix. APSB26-138 is the scheduled September security update covering eight CVEs, with version-specific isolated patch files for supported release lines.

The September isolated patch does not include CVE-2026-75650. Adobe also recommends encryption-key and credential rotation as part of full remediation for the critical RCE. For Cloud merchants, the corresponding fixes are delivered through Cloud Patches for Commerce v1.1.20 and v1.1.21.

Check. Patch.
Rotate. Verify.

Sources & Further Reading

This article is based primarily on Adobe’s September 2026 security bulletins and Experience League documentation, cross-checked against independent security research.

Certified
Adobe Certified Expert

Adobe Certified Expert

Adobe Certified Professional Icon

Adobe Certified Professional

Santhosh P is the Chief Technology Officer (CTO) of Ceymox, bringing over 15 years of experience in e-commerce development and more than 13 years of expertise in Magento. He has completed numerous projects for clients across various industries and regions.He has extensive experience in Magento PWA (Progressive Web Apps), VueStoreFront, and Scandi PWA, delivering fast, responsive, and user-friendly experiences for online shoppers. His proficiencies include:Hyvä Magento speed optimization Magento 2 migration and upgrade Magento extension development Magento mobile development Adobe Commerce development Third-party integration with Magento Magento core functionality enhancement Magento multi-store and multi-website development Magento SEO customization Magento marketplace integration Magento ERP/CRM integration Magento mobile integration (Android, iOS)Santhosh holds multiple Adobe certifications, including Adobe Certified Expert - Adobe Commerce Developer, Adobe Certified Professional - Adobe Commerce Developer, and Magento 1 Certified Developer Plus.

View All Articles
Have a project to discuss?

Let’s make something
amazing together

DROP US A LINE