Security update available for Adobe Commerce - APSB26-136

IMPORTANT
On September 7, 2026, Adobe released a critical security update (APSB26-146) affecting Adobe Commerce and Magento Open Source. Please apply the Hotfix for CVE-2026-75650 in addition to the September Isolated patch file listed in this document. Adobe also strongly recommends rotating your encryption keys and associated credentials as part of remediation.

On September 8, 2026, Adobe released a regularly scheduled security update for Adobe Commerce and Magento Open Source. This update resolves critical, important and moderate vulnerabilities.   Successful exploitation could lead to arbitrary code execution, privilege escalation, and security feature bypass. More information can be found in the Adobe Security Bulletin (APSB26-138).

Adobe isn’t aware of any exploits in the wild for any of the issues addressed in these updates.

Notes:

To help ensure that the remediation for the issues listed in the Adobe Security Bulletin (APSB26-138), can be applied as promptly as possible, Adobe has also released a monthly Isolated patch that resolves the issues in the Adobe Security Bulletin (APSB26-138). This allows merchants to apply the fix in isolation with fewer risks of delay due to potential integration issues.

Please apply the latest security updates as soon as possible. If you fail to do so, you will be vulnerable to these security issues, and Adobe will have limited means to help remediate the issue further.

Please contact Support Services if you encounter any issues applying the security patch/Isolated patch.

Description description

Affected products and versions

Adobe Commerce on Cloud infrastructure, Adobe Commerce on-premises, and Magento Open Source:

  • 2.4.9-2026-aug and earlier
  • 2.4.8-2026-aug and earlier
  • 2.4.7-2026-aug and earlier
  • 2.4.6-2026-aug and earlier
  • 2.4.5-2026-aug and earlier
  • 2.4.4-2026-aug and earlier

Resolution resolution

For Adobe Commerce on Cloud, Adobe Commerce on-premises, and Magento Open Source software

Note: This issue is resolved by the latest cloud-patches update. Attempting to apply the Isolated patch when the fix is already in place from the cloud-patches update can cause installation failures.

To help resolve the vulnerability for the affected products and versions, you must apply the Isolated patch, depending on your Adobe Commerce/Magento Open Source version.

Isolated Patch Details

Use the following attached Isolated patches, depending on your Adobe Commerce/Magento Open Source version:

Note: To apply an Isolated security patch file, merchants must be on the latest security-only patch release (the latest -p version) for their supported release line, as Isolated security fixes are tested exclusively against that version. In addition, merchants must have already applied all previous monthly Isolated security patches for their release line, because each monthly Isolated patch builds on the ones released before it and must be applied cumulatively, in release order.
See the Patch release schedule for more information.

Note: The ZIP file can include a separate patch file for each Adobe Commerce component (CE, EE, B2B, PageBuilder, etc.), and some components may have more than one file, each built for a different version of that component.

For each component installed in your environment, apply the one file whose version matches your installed version of that component. After applying, use the Commerce Version Tool (see below) to confirm your installation is fully patched.

Note: The September 2026 patches build on top of the August 2026 patches. Before applying any of the files below, make sure the matching August 2026 patches for your version are already applied.

Example: If you have Community Edition (CE) on version 2.4.6-p15, first apply the July & August patch, then:

  • 246p15-2026-08-001-CE → 246p15-2026-09-001-CE

If you have Enterprise Edition (EE) on 2.4.6-p15, apply the July & August patches first, then the September CE and EE files:

  • 246p15-2026-08-001-CE → 246p15-2026-08-001-EE → 246p15-2026-09-001-CE → 246p15-2026-09-001-EE

If you have B2B and are on CE/EE 2.4.6-p15, first apply the July & August CE/EE and B2B patches, then the September CE and EE files above, followed by the matching September B2B patch:

  • If on B2B 1.5.2-p5 → apply 152p5-2026-08-001-B2B → 152p5-2026-09-001-B2B
  • If on B2B 1.4.2-p10 → apply 142p10-2026-08-001-B2B → 142p10-2026-09-001-B2B

Download Isolated patches

Notes

  • Open Source merchants can only download patches for version 2.4.7 or later.
  • Adobe Commerce merchants on version 2.4.6 or earlier must enter their Composer keys to download older patches.
For version 2.4.9

Note: This Isolated patch applies to version 2.4.9. Before applying the August 2026 Isolated patch, make sure that the matching July & August 2026 Isolated patch has already been applied.

For version 2.4.8-p5

Note: This Isolated patch applies only to version 2.4.8-p5 after the matching July 2026 Isolated patch has been applied. If you are using an earlier patch level in the 2.4.8 release line, first update to 2.4.8-p5, apply the matching July 2026 Isolated patch, and then apply this August 2026 Isolated patch.

For version 2.4.7-p10

Note: This Isolated patch applies only to version 2.4.7-p10 after the matching July 2026 Isolated patch has been applied. If you are using an earlier patch level in the 2.4.7 release line, first update to 2.4.7-p10, apply the matching July 2026 Isolated patch, and then apply this August 2026 Isolated patch.

For version 2.4.6-p15

Note: This Isolated patch applies only to version 2.4.6-p15 after the matching July 2026 Isolated patch has been applied. If you are using an earlier patch level in the 2.4.6 release line, first update to 2.4.6-p15, apply the matching July 2026 Isolated patch, and then apply this August 2026 Isolated patch.

For version 2.4.5-p17

Note: This Isolated patch applies only to version 2.4.5-p17 after the matching July & August 2026 Isolated patch has been applied. If you are using an earlier patch level in the 2.4.5 release line, first update to 2.4.5-p17, apply the matching July & August 2026 Isolated patch, and then apply this September 2026 Isolated patch.

Note: After clicking the patch file link below for 2-4-5-p17-sep-2026.zip in a browser, merchants will see a pop-up dialog box, where they should enter their Composer public key as the username, and their Private key as the password.

For version 2.4.4-p18

Note: This Isolated patch applies only to version 2.4.4-p18 after the matching July & August 2026 Isolated patch has been applied. If you are using an earlier patch level in the 2.4.4 release line, first update to 2.4.4-p18, apply the matching July & August 2026 Isolated patch, and then apply this September 2026 Isolated patch.

Note: After clicking the patch file link below for 2-4-4-p18-sep-2026.zip in a browser, merchants will see a pop-up dialog box, where they should enter their Composer public key as the username, and their Private key as the password.

How to apply the Isolated patch

Unzip the file, and you may see more than one patch file. Please follow the example above to understand how to apply these patches in order to avoid any potential code conflict.
Please see How to apply a Isolated security patch file provided by Adobe in our support knowledge base for instructions.

How to verify whether the Isolated security patches have been applied

Because a monthly security release can include several Isolated patch files and the fixes are non-cumulative, use one of the following methods to confirm your installation is fully patched.

Recommended: Commerce Version Tool (CVT) — For both Adobe Commerce on-premises and Adobe Commerce on Cloud infrastructure

CVT reports which monthly security patches are installed, which are missing, and which CVEs your installation is protected against.

Important: CVT is only available in the July 2026 Security Isolated patch file. If your release line doesn’t already include the tool, you must apply July 2026 Security Isolated Patch file Isolated patch to obtain it.

You can check if the security Isolated patch file is applied by taking the following steps:

  1. Check whether CVT is already installed. From the Adobe Commerce project root, run:

    php vendor/bin/patch-status --version

    If the command reports a version, the tool is present — Skip to step 3.

  2. If the tool isn’t found, apply the July 2026 security Isolated patch file, starting with the Community Edition (CE) Isolated patch file for your release line. CVT installs at vendor/bin/patch-status.

  3. Run the tool from the Adobe Commerce project root:

    php vendor/bin/patch-status

  4. Review the output: applied_patches, missing_patches, and per-CVE vulnerability_status (PROTECTED / VULNERABLE / UNKNOWN). For command options and how to interpret results, see the Commerce Version Tool documentation.

Alternative (Adobe Commerce on Cloud only): Quality Patches Tool (QPT) — If CVT isn’t available, Cloud infrastructure merchants can verify a specific Isolated patch with QPT, using the file 246p15-2026-07-001-CE.patch as an example:

  1. Install the Quality Patches Tool.
  2. Run the command: vendor/bin/magento-patches -n status |grep "246p15-2026-07-001-CE\|Status"
  3. You should see output similar to this, where the patch returns the Applied status:

║ Id │ Title │ Category │ Origin │ Status │ Details ║

║ N/A │ …/m2-hotfixes/246p15-2026-07-001-CE.patch │ Other │ Local │ Applied │ Patch type: Custom ║

Note:

Adobe is introducing a new tool with these security updates:

Adobe Commerce Patching Automation: A standalone service within the Adobe Commerce Site Wide Analysis Tool that helps merchants apply monthly Adobe Commerce security patch. It allows users to view available patches for a selected project and environment through the Commerce Admin and streamlines the patching process via automation. Additional information is available here.

Security updates

Security updates available for Adobe Commerce:

I’m planning to apply the September Isolated security patch. Do I still need to apply the APSB26-146 hotfix separately?

Yes. The APSB26-146 hotfix for CVE-2026-75650 is not included in the September Isolated patch file. You must apply the hotfix first, then apply the Isolated patch. As CVE-2026-75650 is being actively exploited in the wild, Adobe recommends applying the hotfix as soon as possible following the installation instructions here.

Why this month’s Security Patches aren’t available as Composer packages

As outlined in the official Adobe Commerce release schedule (available on Experience League: Release Schedule), the security fixes released on September 8, 2026, for Adobe Commerce versions 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5, and 2.4.4 were classified as Isolated security fixes.

For this type of release, Adobe provides the fixes as Isolated patch files only, and Composer packages aren’t published alongside them. This is intentional: Isolated patches are designed to give merchants a fast, lightweight way to apply critical security fixes without needing to go through a full Composer-based update cycle, which can take longer and may involve additional dependency resolution.

For merchants on Adobe Commerce on Cloud infrastructure:

These security patches can also be applied directly through Magento Cloud Patches.

You can find the relevant details here: Cloud Patches – Release Notes. This gives Cloud merchants a streamlined path to stay current without manually managing the Isolated patch file.

recommendation-more-help
experience-cloud-kcs-help-kbarticles