Magento Security Alert: Adobe releases two separate September 2026 security updates

Magento Security Alert: September 2026 Adobe Commerce Updates

Adobe has released two separate security updates for Adobe Commerce and Magento Open Source within 24 hours — and there’s an important distinction merchants need to know.

◉ CVE-2026-75650

A Critical CVSS 10.0 vulnerability with confirmed exploitation in the wild. Adobe released the VULN-39341 hotfix as an emergency Priority 1 response.

◌ APSB26-138

Adobe’s regular September security update addressing 8 additional CVEs, with CVSS scores ranging from 7.5 to 9.3 across Adobe Commerce, B2B, and Magento Open Source.

⚠ The critical detail:

Installing the September monthly security patch does not fix CVE-2026-75650. The emergency hotfix must be applied separately. Adobe also recommends rotating the Magento encryption key and potentially exposed credentials as part of remediation.

For affected stores, remediation goes beyond simply installing a patch. Merchants should verify the exact version and patch level, apply the appropriate fixes, rotate credentials, check for signs of compromise, and regression-test critical commerce functionality.

Read the full Magento Security Alert Detailed Blog: https://ceymox.com/september-2026-magento-security-update-what-adobe-commerce-merchants-need-to-know/

Patch the code. Verify the environment. Close the security gaps.