CVE-2026-77109 CVE-2026-76200 CVE-2026-76201 CVE-2026-77111 CVE-2026-77774 CVE-2026-76202 CVE-2026-77110 CVE-2026-77108
Adobe Commerce and Magento Open Source update resolves incorrect authorization, stored XSS and path traversal (APSB26-138)
Adobe Commerce, Commerce B2B and Magento Open Source need the September 2026 builds to close eight flaws: incorrect authorization, stored XSS and path traversal. The worst is a stored XSS scored 9.3; several authorization flaws require no user action. Apply the 2026-sep release.
What happened
Adobe's APSB26-138 update fixes eight vulnerabilities across the Commerce platform. Five are incorrect authorization issues (CWE-863) that can give an attacker access to restricted resources. CVE-2026-77109 can be exploited over the network without credentials or user interaction and allows an attacker to modify restricted data. CVE-2026-77774 also needs no credentials and allows unauthorised read access to confidential data. Two more, CVE-2026-76202 and CVE-2026-77108, can expose sensitive information without credentials. The fifth, CVE-2026-77111, requires high privileges and lets an authenticated administrator bypass security controls for write access. One path traversal issue, CVE-2026-77110, also starts from high privileges and allows access to files or directories outside the intended restrictions. Several of the flaws have changed scope, meaning the compromise can extend beyond the initially affected component.
Two stored cross-site scripting flaws, CVE-2026-76200 and CVE-2026-76201, are the highest-scored at 9.3. An attacker needs to get a user to visit a page containing a malicious form field, after which JavaScript can run in that user's browser, potentially taking over the account or session. Adobe has not published any workaround. No exploitation in the wild, public disclosure or CISA KEV entry is recorded.
Who is affected
Adobe lists the affected releases as the August 2026 builds and earlier. Adobe Commerce: up to and including 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug. Adobe Commerce B2B: up to and including 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug and 1.3.3-2026-aug. Magento Open Source: up to and including 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug and 2.4.6-2026-aug. These products are the public storefront, admin and B2B commerce components many organisations run in production.
What to do now
- Apply the September 2026 builds. Fixed releases are:
- Adobe Commerce: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep and 2.4.4-2026-sep.
- Adobe Commerce B2B: 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep and 1.3.3-2026-sep.
- Magento Open Source: 2.4.9-2026-sep, 2.4.8-2026-sep and 2.4.7-2026-sep. Adobe does not list a fixed build for Magento Open Source 2.4.6, so owners of that line should review Adobe's advisory for guidance.
- There is no vendor workaround. While you plan the update, constrain access: several flaws are reachable from the network without credentials, so keep storefront and admin interfaces off the public internet or restrict them to trusted networks where possible.
- After patching, review admin and customer accounts and logs for unexpected changes to restricted resources, particularly access to sensitive data or modified content. This is the kind of activity these authorization and stored XSS issues could leave behind.
Beyond the patch
Beyond this patch, an internet-facing Commerce storefront carries several unauthenticated authorization flaws, so it is worth confirming what part of the estate is actually exposed. Virtual CISO Services can help you map exposure, while Managed Detection & Response can watch for the privilege escalation and account abuse these flaw classes leave behind. Implementation & Assessment Services covers penetration testing and hardening reviews for public shop platforms.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-77109, CVE-2026-76200, CVE-2026-76201, CVE-2026-77111, CVE-2026-77774, CVE-2026-76202, CVE-2026-77110, CVE-2026-77108 Adobe Commerce | – ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | 2.4.9-2026-sep 2.4.8-2026-sep 2.4.7-2026-sep 2.4.6-2026-sep 2.4.5-2026-sep 2.4.4-2026-sep |
| CVE-2026-77109, CVE-2026-76200, CVE-2026-76201, CVE-2026-77111, CVE-2026-77774, CVE-2026-76202, CVE-2026-77110, CVE-2026-77108 Adobe Commerce B2B | – ≤ 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug | 1.5.3-2026-sep 1.5.2-2026-sep 1.4.2-2026-sep 1.3.4-2026-sep 1.3.3-2026-sep |
| CVE-2026-77109, CVE-2026-76200, CVE-2026-76201, CVE-2026-77111, CVE-2026-77774, CVE-2026-76202, CVE-2026-77110, CVE-2026-77108 Magento Open Source | – ≤ 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug | 2.4.9-2026-sep 2.4.8-2026-sep 2.4.7-2026-sep |
References
Vendor advisory
CVE
- CVE-2026-77109 — cve.org
- CVE-2026-77109 — NVD
- EUVD-2026-74035 — ENISA EUVD
- CVE-2026-76200 — cve.org
- CVE-2026-76200 — NVD
- EUVD-2026-74037 — ENISA EUVD
- CVE-2026-76201 — cve.org
- CVE-2026-76201 — NVD
- EUVD-2026-74036 — ENISA EUVD
- CVE-2026-77111 — cve.org
- CVE-2026-77111 — NVD
- EUVD-2026-74030 — ENISA EUVD
- CVE-2026-77774 — cve.org
- CVE-2026-77774 — NVD
- EUVD-2026-74031 — ENISA EUVD
- CVE-2026-76202 — cve.org
- CVE-2026-76202 — NVD
- EUVD-2026-74032 — ENISA EUVD
- CVE-2026-77110 — cve.org
- CVE-2026-77110 — NVD
- EUVD-2026-74034 — ENISA EUVD
- CVE-2026-77108 — cve.org
- CVE-2026-77108 — NVD
- EUVD-2026-74033 — ENISA EUVD