September 2026 Magento Security Update:
What Adobe Commerce Merchants Need to Know
Adobe has issued two separate September security updates — including an actively exploited critical vulnerability and a broader monthly security release. Here’s what changed across Adobe Commerce, Magento Open Source, B2B, and Cloud.
Emergency Hotfix
Critical unauthenticated RCE with confirmed exploitation in the wild.
VULN-39341Security
Monthly Security Update
Eight CVEs across Commerce, B2B, and Magento Open Source release lines.
APSB26-138September 2026 is not a normal Magento security month. Adobe released two separate security bulletins within 24 hours for Adobe Commerce and Magento Open Source: an emergency Priority 1 update for CVE-2026-75650 on September 7, followed by the regularly scheduled September security update on September 8.
The distinction matters because the monthly September isolated patch does not include the CVE-2026-75650 hotfix. Adobe’s own September guidance tells merchants to apply the hotfix separately. For Adobe Commerce on Cloud, the fixes are also delivered through two different Cloud Patches for Commerce package releases.
September 2026 at a Glance
Critical unauthenticated arbitrary code execution. Adobe confirms exploitation in the wild.
The bulletin’s vulnerability table marks all eight as Critical, with CVSS scores from 7.5 to 9.3.
What Adobe Released — and Why There Are Two Security Streams
APSB26-146 was published on September 7, 2026 with Adobe Commerce priority rating 1. It addresses CVE-2026-75650, an improper-neutralization flaw in a template engine that Adobe rates Critical, CVSS 10.0, requiring neither authentication nor user interaction for exploitation. Adobe says it is aware of exploitation in the wild.
On September 8, Adobe published APSB26-138, its scheduled September security update. Adobe says it resolves critical, important, and moderate vulnerabilities; its vulnerability table lists eight CVEs, each marked Critical. The bulletin covers Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Adobe also explicitly warns that the CVE-2026-75650 hotfix must be applied in addition to the September security fixes.
CVE-2026-75650
Critical · CVSS 10.0 · Priority 1
Unauthenticated arbitrary code execution. Adobe confirms exploitation in the wild. Fix: VULN-39341 hotfix.
September Monthly Security Update
Priority 2 · 8 CVEs
Stored XSS, incorrect authorization, and path traversal vulnerabilities. Delivered as version-specific isolated security patches.
Installing the September isolated patch does not mean CVE-2026-75650 is fixed.
Adobe’s two September security streams must be treated as two separate remediation actions.
CVE-2026-75650: The Emergency Magento / Adobe Commerce Hotfix
Adobe classifies CVE-2026-75650 as an improper neutralization of special elements used in a template engine (CWE-1336). The bulletin assigns a CVSS base score of 10.0, marks it Critical, and records that no authentication is required.
Independent research from Sansec reported exploitation beginning September 4, before Adobe’s September 7 hotfix. Akamai later confirmed active exploitation attempts and described a chain in which attacker-controlled data reaches Magento’s template-processing flow. Those independent findings reinforce Adobe’s “exploited in the wild” designation, but the Adobe bulletin remains the authoritative source for the affected product versions and official fix.
Magento and Adobe Commerce installations commonly connect to payment gateways, ERP and CRM systems, shipping and tax services, third-party extensions, APIs, deployment tooling, and customer data. A vulnerable application layer therefore needs incident-aware remediation, not just a version-number check.
Adobe’s VULN-39341 hotfix matrix
| Affected baseline | Adobe hotfix package |
|---|---|
| 2.4.9-2026-aug/jul; 2.4.8-2026-aug/jul; 2.4.7-2026-aug/jul; 2.4.6-2026-aug/jul; 2.4.5-2026-aug/jul; 2.4.4-2026-aug/jul; plus 2.4.8-p5/p4, 2.4.7-p10/p9, 2.4.6-p15/p14, 2.4.5-p17/p16, 2.4.4-p18/p17 | VULN-39341-composer-patches.zip |
| 2.4.8-p3, 2.4.8-p2 | VULN-39341_248-p3.patch.zip |
| 2.4.8-p1, 2.4.8 | VULN-39341_248-p1.patch.zip |
| 2.4.7-p8, 2.4.7-p7 | VULN-39341_247-p8.patch.zip |
| 2.4.7 through 2.4.7-p6 | VULN-39341_247-p5.patch.zip |
| 2.4.6-p13/p12; 2.4.5-p15/p14; 2.4.4-p16/p15 | VULN-39341_246-p13.patch.zip |
| 2.4.6 through 2.4.6-p11; 2.4.5 through 2.4.5-p13; 2.4.4 through 2.4.4-p14 | VULN-39341_246-p11.patch.zip |
Adobe’s September 21 Knowledge Base update expands the official hotfix compatibility for the 2.4.4–2.4.7 lines. Always use the package mapped to the exact installed version or patch level in Adobe’s current KB rather than copying a patch from another baseline.
The Full APSB26-138 Vulnerability List
The original draft is incomplete here. Adobe’s official bulletin lists eight CVEs, and two are specific to the Adobe Commerce B2B component.
| CVE | Category | Impact | Auth. | CVSS | Scope |
|---|---|---|---|---|---|
| CVE-2026-76200 | Stored XSS (CWE-79) | Privilege escalation | No | 9.3 | Adobe Commerce / Magento Open Source |
| CVE-2026-76201 | Stored XSS (CWE-79) | Privilege escalation | No | 9.3 | Adobe Commerce / Magento Open Source |
| CVE-2026-77111 | Incorrect Authorization | Security feature bypass | Yes | 8.7 | Commerce |
| CVE-2026-77109 | Incorrect Authorization | Privilege escalation | No | 8.6 | B2B |
| CVE-2026-77774 | Incorrect Authorization | Security feature bypass | No | 8.6 | Commerce / Open Source |
| CVE-2026-76202 | Incorrect Authorization | Privilege escalation | No | 8.2 | Commerce / Open Source |
| CVE-2026-77110 | Path Traversal (CWE-22) | Security feature bypass | Yes | 7.6 | Commerce / Open Source |
| CVE-2026-77108 | Incorrect Authorization | Privilege escalation | No | 7.5 | B2B |
Six of the eight CVEs in APSB26-138 are recorded by Adobe as exploitable without authentication. The two B2B-specific issues are CVE-2026-77109 and CVE-2026-77108. Adobe says it is not aware of exploitation in the wild for the issues addressed by APSB26-138.
Which Adobe Commerce and Magento Versions Are Affected?
For APSB26-146, Adobe lists Adobe Commerce 2.4.4 through 2.4.9 at the August 2026 release level and earlier, Adobe Commerce B2B 1.3.3 through 1.5.3 at the August 2026 level and earlier, and Magento Open Source 2.4.4 through 2.4.9 at the August 2026 level and earlier as affected.
For the regular September update APSB26-138, Adobe lists affected Adobe Commerce lines 2.4.4 through 2.4.9 and B2B 1.3.3 through 1.5.3. The fixed September versions are:
Adobe also lists B2B fixed versions 1.3.3-2026-sep through 1.5.3-2026-sep. For Magento Open Source, the September bulletin lists fixed versions 2.4.7-2026-sep, 2.4.8-2026-sep, and 2.4.9-2026-sep.
September’s Isolated Patches: Every Release-Line Download
Adobe classified the September 8 security fixes as isolated security fixes. These are narrowly scoped patch files rather than new Composer security packages. Adobe’s September KB provides one ZIP per supported Adobe Commerce release line:
| Release line | September isolated patch | Baseline requirement |
|---|---|---|
| Adobe Commerce 2.4.9 | 2-4-9-sep-2026.zip | Latest security-only release line + prior isolated patches |
| Adobe Commerce 2.4.8-p5 | 2-4-8-p5-sep-2026.zip | 2.4.8-p5 + prior monthly isolated patches |
| Adobe Commerce 2.4.7-p10 | 2-4-7-p10-sep-2026.zip | 2.4.7-p10 + prior monthly isolated patches |
| Adobe Commerce 2.4.6-p15 | 2-4-6-p15-sep-2026.zip | 2.4.6-p15 + prior monthly isolated patches |
| Adobe Commerce 2.4.5-p17 | 2-4-5-p17-sep-2026.zip | 2.4.5-p17 + prior monthly isolated patches |
| Adobe Commerce 2.4.4-p18 | 2-4-4-p18-sep-2026.zip | 2.4.4-p18 + prior monthly isolated patches |
The ZIP can contain separate patch files for installed components such as CE, EE, B2B, PageBuilder, and other modules. Adobe instructs merchants to apply the file that matches each installed component and then verify the resulting security state.
How Adobe’s New Monthly Isolated-Patch Model Changes Patching
Adobe’s new model is designed to shorten the time between vulnerability disclosure and targeted remediation. An isolated patch contains only the code needed to address specified vulnerabilities and is folded into the next full security patch release.
Adobe Commerce on Cloud: Two Cloud Patch Package Releases
For Adobe Commerce on Cloud infrastructure, Adobe distributes critical fixes through the Cloud Patches for Commerce package, which is a dependency of ECE-Tools.
September 8, 2026 — Cloud Patches for Commerce
v1.1.20 includes the September isolated security fixes referenced by APSB26-138.
v1.1.21 includes the security fixes referenced by APSB26-146 for CVE-2026-75650.
Adobe’s current Cloud guidance recommends keeping ECE-Tools up to date so the latest Cloud Patches package is brought into deployment.
Patch Is Not the Same as Remediation
The most important operational instruction in Adobe’s CVE-2026-75650 guidance goes beyond the code change itself: rotate the encryption key and the credentials that could have been encrypted or exposed using it.
Adobe explicitly calls out Admin passwords, REST/SOAP/GraphQL integration tokens, OAuth client secrets, payment-gateway API credentials, database credentials, SSH/deployment keys, and API credentials for shipping, tax, and other integrated services.
Adobe also makes an important distinction: rotating the encryption key alone does not invalidate credentials that may already have been exposed. The associated credentials must be rotated at their respective systems or providers.
What About a Store That May Already Have Been Exploited?
A successful patch closes the vulnerable code path; it does not prove that no attacker reached the system before the fix existed. Sansec reported exploitation beginning September 4, before Adobe released the September 7 hotfix, and recommends scanning for compromise rather than assuming a clean state from a patch status alone.
For an affected production environment, the incident question is therefore broader than “Did we install the patch?” Security teams should review application and infrastructure logs, unexpected admin activity, filesystem changes, cron or process anomalies, outbound connections, modified templates or CMS content, suspicious integration credentials, and signs of persistence.
What Every Magento / Adobe Commerce Merchant Should Do Now
One More Adobe Commerce Cloud Consideration
Adobe has also published a separate security-enforcement policy for Adobe Commerce on Cloud PaaS environments running 2.4.4 through 2.4.9. That policy is distinct from the September CVE patches, but it matters for merchants maintaining older Cloud environments.
Adobe says 2.4.4/2.4.5 Cloud environments have a June 1, 2027 deadline to upgrade to a supported Commerce version or migrate to Adobe Commerce as a Cloud Service, while 2.4.6/2.4.7 have a June 1, 2028 deadline. Adobe also lists separate third-party dependency deadlines beginning October 30, 2026 for certain unsupported MariaDB, Elasticsearch/OpenSearch, and RabbitMQ configurations.
Is Your Magento or Adobe Commerce Store Actually Secure?
Ceymox can assess your Magento / Adobe Commerce environment for patch status, vulnerable release lines, custom-code and extension exposure, security hardening gaps, and post-patch verification requirements.
Patch the code. Verify the environment. Close the security gaps.
GET A MAGENTO SECURITY ASSESSMENT →Final Takeaway
The right way to read Adobe’s September 2026 security releases is not “Adobe released a September patch.” Adobe released two separate security streams.
APSB26-146 is the emergency Priority 1 response to the actively exploited CVE-2026-75650, fixed through the VULN-39341 hotfix. APSB26-138 is the scheduled September security update covering eight CVEs, with version-specific isolated patch files for supported release lines.
The September isolated patch does not include CVE-2026-75650. Adobe also recommends encryption-key and credential rotation as part of full remediation for the critical RCE. For Cloud merchants, the corresponding fixes are delivered through Cloud Patches for Commerce v1.1.20 and v1.1.21.
Check. Patch.
Rotate. Verify.
Sources & Further Reading
This article is based primarily on Adobe’s September 2026 security bulletins and Experience League documentation, cross-checked against independent security research.