Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code.
The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9.1 out of 10 under the CVSS scoring system. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access.
Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make unauthorized changes within affected commerce environments.
Adobe Commerce Vulnerabilities
Adobe also addressed two critical stored cross-site scripting vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Both flaws may result in arbitrary code execution when exploited successfully.
Stored XSS vulnerabilities occur when an application saves malicious script content and later delivers it to other users through legitimate pages, forms, product information, customer records, or administrative interfaces.
CVE-2026-48414 has a CVSS score of 7.7 and requires authentication, administrator privileges, user interaction, and high attack complexity. CVE-2026-48413 is more accessible, with a CVSS score of 8.7.
It requires a low-privileged authenticated account and user interaction, but does not require administrator privileges. The update, tracked as APSB26-92, was published on August 11, 2026, with a priority rating of 2.
In a real attack, a threat actor may attempt to use a compromised customer, employee, or partner account to inject malicious content into a commerce platform.
Another critical vulnerability, CVE-2026-48415, affects Adobe Commerce B2B deployments. The incorrect authorization flaw could enable an authenticated attacker without administrator privileges to bypass security features.
Adobe assigned it a CVSS score of 7.6. CVE-2026-48416 is also an authorization issue, rated 7.5, that may allow an unauthenticated attacker to bypass security controls.
The update additionally fixes CVE-2026-48411, an important authorization flaw with a CVSS score of 6.8, and CVE-2026-48412, a moderate privilege-escalation issue rated 2.7.
Although these vulnerabilities have lower severity ratings, organizations should treat the update as a complete security package rather than selectively addressing only the critical bugs.
Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 with the July 2026 security update or earlier, Magento Open Source versions 2.4.6 through 2.4.9, and multiple Adobe Commerce B2B releases. Adobe recommends updating to the August 2026 releases as soon as possible.
Adobe stated that it is not aware of active exploitation of these vulnerabilities in the wild. However, public security advisories can increase attacker interest, particularly where internet-facing stores remain unpatched.
Administrators should apply the relevant August 2026 update, review privileged accounts, monitor application logs for unusual activity, and validate that web application firewall rules and access controls are functioning correctly.