Critical Magento security activity is current — verify your September 2026 patch status.
Magento security alert
🐞

Is Your Magento or Adobe Commerce Store Protected?

Adobe says CVE-2026-75650 is being actively exploited. A separate September security update also addresses additional vulnerabilities — and one patch does not cover everything.

For Magento Open Source, Adobe Commerce, and Adobe Commerce B2B merchants.
Active exploitation reported by Adobe
CVE-2026-75650
CVSS 10.0
CriticalSeverity
UnauthenticatedAttack requirement
ActiveExploitation status
Adobe released the VULN-39341 hotfix on September 7, 2026. Adobe's September 8 security update is separate and does not include this hotfix.
2September Adobe security streams
10.0CVE-2026-75650 CVSS score
8Critical CVEs in APSB26-138
2Security actions: hotfix + Sep. update
What merchants need to know

September has two security tracks.

Treating the September update as a single “apply the patch” task can leave a store exposed. Adobe's guidance separates the emergency CVE-2026-75650 hotfix from the regular September security update.

Emergency hotfix

APSB26-146 / VULN-39341

Addresses CVE-2026-75650, a critical vulnerability Adobe says is actively exploited. The hotfix is separate from the regular September isolated security patch.

September security update

APSB26-138

Addresses additional critical, important and moderate vulnerabilities. Adobe says it is not aware of exploitation in the wild for the vulnerabilities covered by this bulletin.

UpdateDateWhat it addressesMerchant action
APSB26-146Sep 7, 2026CVE-2026-75650Apply VULN-39341 hotfix
APSB26-138Sep 8, 2026Additional security vulnerabilitiesApply applicable Sep patch
Cloud PatchesSep 8, 2026Cloud delivery of September fixesVerify package / deployment state
Are you affected?

Check the exact product and patch level.

Adobe's September guidance is version-specific. The September APSB26-138 update affects Adobe Commerce 2.4.4 through 2.4.9 release lines, Adobe Commerce B2B 1.3.3 through 1.5.3 release lines, and Magento Open Source 2.4.6 through 2.4.9, depending on the exact August patch level.

Adobe Commerce / Magento Open Source

  • Adobe Commerce: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier.
  • Magento Open Source: 2.4.9-2026-aug and earlier through 2.4.6-2026-aug and earlier.
  • Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, and 1.3.3-2026-aug and earlier.

What to verify first

  • Exact Commerce / Magento release and security patch level.
  • Installed B2B, PageBuilder and other Commerce components.
  • Whether the September isolated patch sequence is complete.
  • Whether the separate CVE-2026-75650 hotfix is present.
  • Whether Adobe Commerce Cloud Patches are current, where applicable.
Important: Adobe says the APSB26-146 hotfix for CVE-2026-75650 is separate from the September isolated security patch. A September patch alone does not establish protection against that actively exploited vulnerability.
APSB26-138

Eight critical vulnerabilities in the September security update.

Adobe's September 8 bulletin lists eight critical vulnerabilities covering stored XSS, incorrect authorization and path traversal. Two entries are specifically identified as B2B issues.

CVETypeImpactAuth.CVSSB2B
CVE-2026-76200Stored XSSPrivilege escalationNo9.3 Critical
CVE-2026-76201Stored XSSPrivilege escalationNo9.3 Critical
CVE-2026-77111Incorrect AuthorizationSecurity feature bypassYes8.7 Critical
CVE-2026-77109Incorrect AuthorizationPrivilege escalationNo8.6 CriticalYes
CVE-2026-77774Incorrect AuthorizationSecurity feature bypassNo8.6 Critical
CVE-2026-76202Incorrect AuthorizationPrivilege escalationNo8.2 Critical
CVE-2026-77110Path TraversalSecurity feature bypassYes7.6 Critical
CVE-2026-77108Incorrect AuthorizationPrivilege escalationNo7.5 CriticalYes
If your store may have been exposed

Patching is not the same as incident review.

Because Adobe says CVE-2026-75650 has been exploited in the wild, merchants who were running an affected installation should consider whether additional review is warranted after remediation.

Review the environment

  • Admin and privileged-account activity.
  • Unexpected code, files or configuration changes.
  • Application, web-server and infrastructure logs.
  • Custom modules and third-party extensions.

Rotate sensitive access

  • Adobe Commerce encryption keys.
  • Integration and API credentials.
  • OAuth or application secrets.
  • Payment, database, deployment and SSH credentials where applicable.
Not sure whether your store was exposed? Don't assume that a successful patch deployment answers that question. Request a security assessment to determine what should be reviewed and verified.
Adobe Commerce on Cloud

There is another deadline Cloud merchants need to know about.

Adobe's September 18, 2026 security-enforcement guidance adds version and third-party dependency requirements for Adobe Commerce on Cloud (PaaS) environments running 2.4.4 through 2.4.9.

2.4.4 / 2.4.5
June 1, 2027 Upgrade to a supported Cloud version or migrate to Adobe Commerce as a Cloud Service. Third-party dependency requirements begin earlier, with some deadlines on October 30, 2026.
2.4.6 / 2.4.7
June 1, 2028 Commerce version upgrade deadline. Third-party dependency requirements can apply earlier, depending on the dependency.
2.4.8 / 2.4.9
Check dependencies No Commerce version upgrade deadline is set at this time, but supported third-party software dependency requirements still apply.
Adobe's policy covers dependencies including PHP, MariaDB, Elasticsearch/OpenSearch, Redis/Valkey and RabbitMQ. Environments that do not meet the requirements by the applicable enforcement dates may have inbound traffic suspended, taking the storefront offline.
Think your store may be affected?

Get a security assessment for your Magento or Adobe Commerce store.

GET MY SECURITY ASSESSMENT
What Ceymox checks

A security review should cover the whole Commerce stack.

A patch can touch more than the core application. The review should account for the installed Commerce components, customizations, integrations and deployment environment around the fix.

01 — Commerce versionExact Adobe Commerce / Magento release, patch level and support status.
02 — Security patchesVULN-39341 and applicable September 2026 security fixes.
03 — B2B & extensionsAdobe Commerce B2B, PageBuilder, third-party extensions and custom modules.
04 — Keys & credentialsEncryption keys, integration tokens, API credentials and privileged access.
05 — Cloud dependenciesPHP, database, OpenSearch/Elasticsearch, Redis/Valkey and RabbitMQ where applicable.
06 — VerificationDeployment state, logs, patch-status evidence and indicators that require further review.
Remediation

Patch. Rotate. Review. Verify.

For an actively exploited vulnerability, remediation should not stop after a deployment succeeds.

01

Identify your exact version

Confirm the Magento or Adobe Commerce release and patch level before selecting the fix.

02

Apply the applicable patches

Address VULN-39341 and the separate September security fixes relevant to your environment.

03

Rotate keys & credentials

Follow Adobe's guidance for encryption-key rotation and associated credentials or secrets.

04

Review and verify

Check logs, deployment state, custom code and extensions, then verify remediation.

Ceymox Magento security

Don't let patching become a production outage.

Magento security work can involve custom modules, third-party extensions, payment integrations, APIs, ERP connections and deployment pipelines. Ceymox can help you assess the impact before and after remediation.

Magento security patch assessmentIdentify applicable fixes and prerequisites for your release.
VULN-39341 remediationApply the critical CVE-2026-75650 hotfix correctly.
September 2026 patchingAddress the separate APSB26-138 security update.
Key & credential rotationSupport post-remediation credential and secret rotation.
Extension & custom-code reviewAssess the store stack around security changes.
Post-patch verificationValidate that remediation is deployed and the environment is checked.
Magento security assessment

Find out what your store needs — before attackers do.

Share your store details and our Magento experts can identify the applicable September 2026 security actions, review the surrounding Commerce stack, and help define a safer remediation path for your production environment.

Version-specificReview based on your actual Commerce release.
Production-awareConsider integrations and customizations.
ActionablePrioritized remediation findings.
Security-focusedPatch and post-patch verification.