Adobe Commerce APSB26-138: What Businesses Need to Know About the Security Update

10 Sep 2026
Albert Wood
Albert Wood
Adobe Commerce APSB26-138: What Businesses Need to Know About the Security Update

On September 8, 2026, Adobe released security update APSB26-138 for Adobe Commerce and Magento Open Source. This update addresses several critical, important, and moderate vulnerabilities. It mitigates risks related to arbitrary code execution, security feature bypass, and privilege escalation.

Key Vulnerabilities Addressed by the Adobe Commerce Security Update

This patch addresses various security vulnerabilities, including:

  • Cross-Site Scripting (Stored XSS)
  • Incorrect Authorization
  • Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

These vulnerabilities cause significant security risks, making it crucial for businesses to apply the update immediately to prevent potential security breaches.

Versions Affected by the Adobe Commerce Security Update APSB26-138

The Adobe Commerce Security Update APSB26-138 impacts the following versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source:

  • Adobe Commerce: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier, 2.4.5-2026-aug and earlier, 2.4.4-2026-aug and earlier
  • Adobe Commerce B2B: 1.5.3-2026-aug and earlier, 1.5.2-2026-aug and earlier, 1.4.2-2026-aug and earlier, 1.3.4-2026-aug and earlier, 1.3.3-2026-aug and earlier
  • Magento Open Source: 2.4.9-2026-aug and earlier, 2.4.8-2026-aug and earlier, 2.4.7-2026-aug and earlier, 2.4.6-2026-aug and earlier

Adobe Commerce Products Included in APSB26-138 Security Update

The security update applies to the latest supported release lines across Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. 

  • Adobe Commerce: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep
  • Adobe Commerce B2B: 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep
  • Magento Open Source: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep

Does the September Isolated Security Patch Include the APSB26-146 Hotfix?

No. The APSB26-146 hotfix addressing CVE-2026-75650 is not included in the September Isolated Security Patch. If your Adobe Commerce store is affected, you must apply the APSB26-146 hotfix separately before installing the September Isolated patch.

Why Isn’t the September Security Fixes Available as Composer Packages?

Adobe released the September 8, 2026, security fixes for Adobe Commerce versions 2.4.9 through 2.4.4 as Isolated security patches.

These fixes are provided as patch files instead of Composer packages, allowing merchants to address specific security issues without a full version upgrade.

Before applying a patch, make sure it matches your Adobe Commerce version and follow Adobe’s installation instructions. Also, remember that the APSB26-146 hotfix for CVE-2026-75650 must be applied separately if it affects your environment.

Recommended Action

Adobe strongly recommends that users apply Adobe Commerce Security Update APSB26-138 quickly to enhance security and minimize exposure to vulnerabilities.

How to Install the Update

Step 1: Download the relevant patch files.

Step 2: Install the security patch on a staging platform first.

Step 3: Verify the installation by checking the patch status using the provided tools.

Step 4: Deploy the update on the live platform after confirming stability on staging.

To enhance the solution’s security and mitigate future threats, businesses should take quick actions, such as:

  • Update the software
  • Implement strong access controls
  • Monitor for suspicious activities

ioVista, an Adobe Commerce certified partner, helps you implement the latest security patch without impacting your ongoing eCommerce operations. Connect with our certified experts to install this update.

Click here for the official link.

Albert Wood
Albert Wood linkedin

Albert Wood is an accomplished eCommerce Business Analyst. As a technology futurist and sales motivator at ioVista, Albert is dedicated to transforming struggling eCommerce businesses into thriving enterprises. With a keen focus on client’s business processes, user experience (UX), and leveraging the power of digital marketing, he helps businesses optimize their online presence and drive sustainable growth. Albert’s passion is for virtual reality (VR), augmented reality (AR), and mixed reality (MR), immersing himself in unforgettable experiences and exploring the limitless possibilities they offer. His enthusiasm for these emerging technologies fuels his drive to push the boundaries of innovation in eCommerce.

Get in Touch






    Let’s work together to create outstanding digital experiences.

    With 20+ years of industry experience, ioVista understands your eCommerce needs and delivers best-in-class solutions that help you gain a competitive edge.

    Platform Assessment

    TOP