If you're running Adobe Commerce, Adobe Commerce B2B, or Magento Open Source, it's time to schedule some maintenance. Adobe published security bulletin APSB26-92 on August 11, 2026, and it addresses seven vulnerabilities: four of them rated critical.
The short version
Adobe fixed a batch of critical, important, and moderate severity issues that could allow attackers to bypass security features, execute arbitrary code, or escalate their privileges within a store. The bulletin carries a Priority 2 rating, which means Adobe wants affected users patched soon, even though there's no evidence of active exploitation yet.
The good news: Adobe says it is not aware of any exploits in the wild for any of these issues at this time. The bad news: that window closes fast once a bulletin like this goes public, since attackers routinely reverse-engineer patches to build exploits within days.
Who's affected
This update touches nearly every currently supported branch of Adobe's commerce platforms:
-
Adobe Commerce: versions 2.4.4 through 2.4.9 (all "-2026-jul" builds and earlier)
-
Adobe Commerce B2B: versions 1.3.3 through 1.5.3 (all "-2026-jul" builds and earlier)
-
Magento Open Source: versions 2.4.6 through 2.4.9 (all "-2026-jul" builds and earlier)
All platforms, all deployments. If you haven't applied the "-2026-aug" builds yet, you're on an affected version.
What's actually broken
The seven CVEs break down like this:
| Severity | Issue type | Impact | CVSS | Auth required? |
| Critical | Incorrect Authorisation | Privilege escalation | 9.1 | No |
| Critical | Stored XSS | Arbitrary code execution | 8.7 | Yes |
| Critical | Stored XSS | Arbitrary code execution | 7.7 | Yes (admin) |
| Critical | Incorrect Authorisation | Security feature bypass | 7.6 | Yes (B2B only) |
| Critical | Incorrect Authorisation | Security feature bypass | 7.5 | No |
| Important | Incorrect Authorisation | Security feature bypass | 6.8 | Yes (admin) |
| Moderate | Incorrect Authorisation | Privilege escalation | 2.7 | Yes (admin) |
The standout is CVE-2026-71362, a 9.1-severity incorrect authorisation flaw that needs no authentication at all, the kind of bug that tends to get weaponised quickly once details leak. Two stored XSS vulnerabilities (CVE-2026-48413 and CVE-2026-48414) round out the critical tier and could let an attacker run arbitrary code through injected content. One authorisation bypass, CVE-2026-48415, is specific to the B2B module, so pure Open Source or Commerce-only stores can rule that one out.
For full technical details, including CVE numbers and CVSS vectors, see Adobe's official bulletin.
What to do
-
Update to the August 2026 builds. Every affected product line has a corresponding "-2026-aug" release (e.g., 2.4.9-2026-aug, 1.5.3-2026-aug). Check Adobe's release notes for the exact steps for your version.
-
Prioritise based on your exposure. If you're running B2B, don't skip the B2B-specific fix. If your admin panel is internet-facing, treat the admin-privileged bugs as more urgent than the CVSS score alone suggests.
-
Don't wait for exploitation reports. "No known exploits in the wild" is a snapshot, not a guarantee. Priority 2 bulletins for e-commerce platforms are a favorite target once the patch diff is public.
-
Test in staging first, then push to production. Commerce platforms tend to have enough customisations that a blind prod deploy is asking for trouble.
Bottom line
Four critical vulnerabilities, one of them unauthenticated and scoring 9.1, is enough reason to move this to the top of the maintenance queue. Adobe says there's no known exploitation yet, but that window closes fast once a patch like this goes public, so the priority is clear: get patched before that changes.
On Tap didn't wait to find out. As soon as APSB26-92 was released, our team began rolling it out across every Magento/Adobe Commerce customer's store, at no additional cost and with no action required on their side, as part of our Evergreen programme. If your store isn't with On Tap yet, this is exactly the scenario Evergreen is built for. Instead of scrambling to track, test, and apply every Adobe Commerce or Magento bulletin yourself, get in touch and let On Tap handle it for you, permanently.


