Adobe Commerce APSB26-92: Security Risks, Affected Versions, and Next Steps

13 Aug 2026
Albert Wood
Albert Wood
Adobe Commerce APSB26-92: Security Risks, Affected Versions, and Next Steps

On August 11, 2026, Adobe released security update APSB26-92 for Adobe Commerce and Magento Open Source. The new release resolves several critical, important, and moderate vulnerabilities. It mitigates risks related to arbitrary code execution, security feature bypass, and privilege escalation.

The most serious issue in this update is a Critical privilege-escalation flaw that requires no existing account, administrator privileges, or user interaction to exploit. After analyzing Adobe’s patch, security researchers pinned the problem to Magento improperly handling customer identity in an account session.

The researchers examined the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data, making it one of the most urgent fixes in this release for any store handling customers.

Key Vulnerabilities Addressed by the Adobe Commerce Security Update

This patch addresses various security vulnerabilities, including:

  • Incorrect Authorization
  • Cross-Site Scripting (Stored XSS)

These vulnerabilities cause significant security risks, making it crucial for businesses to apply the update immediately to prevent potential security breaches.

Versions Affected by the Adobe Commerce Security Update APSB26-92

The Adobe Commerce Security Update APSB26-92 impacts the following versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source:

  • Adobe Commerce: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier, 2.4.4-2026-jul and earlier
  • Adobe Commerce B2B: 1.5.3-2026-jul and earlier, 1.5.2-2026-jul and earlier, 1.4.2-2026-jul and earlier, 1.3.4-2026-jul and earlier, 1.3.3-2026-jul and earlier
  • Magento Open Source: 2.4.9-2026-jul and earlier, 2.4.8-2026-jul and earlier, 2.4.7-2026-jul and earlier, 2.4.6-2026-jul and earlier

Adobe Commerce Products Included in APSB26-92 Security Update

The security update applies to the latest supported release lines across Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.

  • Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
  • Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
  • Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug

Recommended Action

Adobe strongly recommends that users apply the Adobe Commerce Security Update APSB26-92 quickly to enhance security and minimize exposure to vulnerabilities.

How to Install the Update

Step 1: Download the relevant patch files.

Step 2: Install the security patch on a staging platform first

Step 3: Verify the installation by checking the patch status using the provided tools

Step 4: Deploy the update on the live platform after confirming stability on staging.

To enhance the solution’s security and mitigate future threats, businesses should take quick actions such as:

  • Update the Software
  • Implement Strong Access Controls
  • Monitor for Suspicious Activities

ioVista, an Adobe Commerce certified partner, helps you implement the latest security patch without impacting your ongoing eCommerce operations. Connect with our certified experts to install this update.

Click here for the official link.

Albert Wood
Albert Wood linkedin

Albert Wood is an accomplished eCommerce Business Analyst. As a technology futurist and sales motivator at ioVista, Albert is dedicated to transforming struggling eCommerce businesses into thriving enterprises. With a keen focus on client’s business processes, user experience (UX), and leveraging the power of digital marketing, he helps businesses optimize their online presence and drive sustainable growth. Albert’s passion is for virtual reality (VR), augmented reality (AR), and mixed reality (MR), immersing himself in unforgettable experiences and exploring the limitless possibilities they offer. His enthusiasm for these emerging technologies fuels his drive to push the boundaries of innovation in eCommerce.

Get in Touch






    Let’s work together to create outstanding digital experiences.

    With 20+ years of industry experience, ioVista understands your eCommerce needs and delivers best-in-class solutions that help you gain a competitive edge.

    Platform Assessment

    TOP