Skip to content

CVE-2026-48413 CVE-2026-71362 CVE-2026-48414 CVE-2026-48415 CVE-2026-48416 CVE-2026-48411 CVE-2026-48412

Adobe Commerce APSB26-92 fixes stored XSS and authorization flaws (CVE-2026-48413 and five others)

Critical 9.1 KEV Vendor: Adobe Commerce / Magento Published · Updated

Adobe Commerce APSB26-92 fixes six flaws: stored XSS CVE-2026-48413 and CVE-2026-48414, and authorization flaws CVE-2026-48415, CVE-2026-48416, CVE-2026-48411, CVE-2026-48412. Exploited CVE-2026-71362 has its own page. Upgrade to August 2026 releases.

What happened

Adobe's APSB26-92 bulletin for Adobe Commerce and Magento Open Source addresses seven vulnerabilities. CVE-2026-71362, an incorrect authorization flaw scored 9.1, is covered on its own page on this site. It is marked as exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 24 September 2026 with a due date of 27 September 2026, CISA SSVC assesses exploitation as active, and ENISA EUVD records exploitation since 24 September 2026. It allows an unauthenticated, network-based attacker to gain elevated access to sensitive resources without user interaction.

The other six flaws fixed in this bulletin are two stored cross-site scripting vulnerabilities (CVE-2026-48413, CVE-2026-48414) and four incorrect authorization vulnerabilities (CVE-2026-48415, CVE-2026-48416, CVE-2026-48411, CVE-2026-48412). The XSS flaws can be exploited by a low-privileged attacker who injects scripts into vulnerable form fields; the scripts run in a victim's browser when the page is viewed and may take over the account or session. The authorization flaws vary in required privileges and impact, from unauthenticated data reads to privilege escalation and security bypass; none of the six is recorded as exploited in the sources provided.

Who is affected

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected. These are typically internet-facing storefront and commerce platforms holding customer data.

The affected version ranges are as follows, noting that for Adobe Commerce the source record lists some -2026-aug builds as both affected and fixed; confirm your exact build against Adobe's bulletin before planning the update.

  • Adobe Commerce: up to and including 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug.
  • Adobe Commerce B2B: up to and including 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul.
  • Magento Open Source: up to and including 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul.

What to do now

  1. Apply the August 2026 security release for your line. Fixed builds are:
  • Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug.
  • Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug.
  • Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug.
  1. Treat CVE-2026-71362 as the priority. It has its own page on this site; CISA's due date is 27 September 2026, and ENISA EUVD records exploitation since 24 September 2026.
  2. After patching, review administrator accounts and roles for unexpected changes, since the authorization flaws can allow elevated access or privilege escalation.
  3. Adobe's bulletin does not list a workaround. If you cannot patch immediately, restrict administrative access and monitor for unusual administrative activity.

How to detect it

Adobe's bulletin does not publish indicators of compromise. For CVE-2026-71362, treat any affected Adobe Commerce or Magento Open Source instance that was reachable from the internet before patching as potentially exposed, and review administrator account changes and unusual administrative activity. For the stored XSS flaws, examine publicly visible form fields and storefront content that renders user-supplied input for unexpected scripts.

Beyond the patch

Adobe Commerce instances are public, payment-adjacent platforms, and this bulletin shows why patch timing and exposure control matter. A penetration test and hardening review covers the public storefront and admin boundaries that these authorization flaws abuse, while supply chain defense tracks how quickly your commerce suppliers—including Adobe's release cycle—close the gap. If CVE-2026-71362 may have been live before patching, an incident response retainer gives you a prepared path for containment.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-48413, CVE-2026-71362, CVE-2026-48414, CVE-2026-48415, CVE-2026-48416, CVE-2026-48411, CVE-2026-48412
Adobe Commerce
– ≤ 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug2.4.9-2026-aug
2.4.8-2026-aug
2.4.7-2026-aug
2.4.6-2026-aug
2.4.5-2026-aug
2.4.4-2026-aug
CVE-2026-48413, CVE-2026-71362, CVE-2026-48414, CVE-2026-48415, CVE-2026-48416, CVE-2026-48411, CVE-2026-48412
Adobe Commerce B2B
– ≤ 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul1.5.3-2026-aug
1.5.2-2026-aug
1.4.2-2026-aug
1.3.4-2026-aug
1.3.3-2026-aug
CVE-2026-48413, CVE-2026-71362, CVE-2026-48414, CVE-2026-48415, CVE-2026-48416, CVE-2026-48411, CVE-2026-48412
Magento Open Source
– ≤ 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul2.4.9-2026-aug
2.4.8-2026-aug
2.4.7-2026-aug
2.4.6-2026-aug

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.