Adobe released a security update on August 11 for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, fixing seven vulnerabilities. Four carry a critical severity rating, and one can be exploited without any login credentials at all. Meetanshi, a Magento and Shopify development agency, is advising merchants on the affected version lines to review their exposure and patch without delay.
The most severe issue, tracked as CVE-2026-71362, is an incorrect authorization vulnerability scoring 9.1 on the CVSS v3.1 scale. It requires no authentication and no administrative access to exploit, a detail that puts it well outside the profile of a routine monthly patch. Two additional critical-rated issues involve stored cross-site scripting bugs capable of leading to arbitrary code execution, and a separate authorization flaw affecting the Commerce B2B module allows a security feature bypass. Adobe states it has no evidence of active exploitation at the time of publication.
Affected versions include Adobe Commerce and Magento Open Source on 2.4.9-2026-jul and earlier, and Adobe Commerce B2B from 1.3.3 through 1.5.3 on 2026-jul builds and earlier. The exposure spans both Cloud infrastructure and on-premises deployments, so hosting model alone does not determine whether a store is in scope.
Full technical detail, including CVSS scoring and affected component lists, is available in Adobe's official security bulletin at https://helpx.adobe.com/security/products/magento/apsb26-92.html.
This release also marks a change in how the fix gets delivered, and it's the part catching most merchants off guard. Rather than distributing the update as a Composer package, Adobe classified the August fixes as an Isolated security patch. Under this model, the fix ships as a downloadable file applied directly, not through a dependency manager. Installation only succeeds if a store already runs the latest security-only release for its version line, with every prior monthly patch already applied in sequence. Skipping a step in that sequence is enough to make the patch fail to apply cleanly. Adobe explains the full reasoning behind the change in its official release notes at https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380.
Merchants on Adobe Commerce or Magento Open Source version 2.4.4 or 2.4.5 face one additional step, since the patch download for those versions sits behind a Composer key authentication prompt rather than a direct link.
Adobe ships a Commerce Version Tool alongside the release, letting store operators check which patches are already installed and which CVEs remain unaddressed. The tool becomes available once a required component patch has been applied, and Adobe's documentation describes it as covering both on-premises and Cloud infrastructure environments.
Meetanshi's Magento support team has spent the days since the bulletin's release answering a recurring question from store owners, namely which patch file applies to their exact setup and how to confirm it actually took hold. The agency is offering guided patch application for this release, covering version verification, sequential patching for any missing prior updates, Composer key handling for older builds, and post-patch validation through the Commerce Version Tool. For stores running B2B modules, the team also checks that the B2B patch version matches the CE and EE files already in use, since a mismatch there is one of the more common causes of a failed install.
None of this addresses custom code sitting on top of the core platform. Third-party extensions, custom checkout logic, ERP or CRM connections, and payment gateway integrations are not tested by Adobe as part of this release, and a clean patch install does not guarantee any of them continue working afterward. Merchants managing customized stores should apply the patch on a staging environment first, check extension compatibility, and confirm checkout and payment flows behave as expected before pushing the update to production.
Merchants can review the complete CVE list and severity ratings directly on Adobe's security bulletin, or reach out to a Magento partner for a direct patch audit. More information on Meetanshi's security patch support is available at https://meetanshi.com/blog/magento-adobe-commerce-security-update-apsb26-92/.
Company Information
Meetanshi is a Magento and Shopify development agency based in Bhavnagar, Gujarat, India, with a second office in Stuttgart, Germany. The company was founded in 2017 and builds Magento 2 extensions and Shopify apps alongside client development work, including platform migrations, store builds, and security patch installation. Meetanshi operates as a Hyvä partner agency and works with Magento Open Source, Adobe Commerce, and Shopify merchants. More information is available at https://meetanshi.com.
Want me to drop this updated version into the full prfree.org submission text so you have the complete, ready-to-paste body in one block?