Adobe security update, 8 September 2026

    APSB26-138: Apply Adobe's September Magento Patch as Well as StyleSmuggler

    By Simon Bumford, Founder of EveryHost••6 min read

    TL;DR

    Adobe's regular September security update, APSB26-138, came out on 8 September 2026. It is separate from the StyleSmuggler emergency hotfix (APSB26-146) from 7 September. Adobe says the hotfix is not included in the September isolated patch, so a Magento Open Source or Adobe Commerce store needs both. Adobe is not aware of exploits in the wild for the APSB26-138 issues, but its bulletin lists eight critical CVEs, including two stored cross-site scripting flaws. Magento Open Source merchants can only download the September isolated patch for 2.4.7 or later.

    Adobe's regularly scheduled Magento security update for September 2026, APSB26-138, landed on 8 September, and it is not the same fix as the StyleSmuggler emergency hotfix from the day before. If you only applied APSB26-146 / CVE-2026-75650, your store is still missing a separate set of fixes for critical authorisation and cross-site scripting flaws.

    That distinction matters for UK Magento Open Source and self-managed Adobe Commerce merchants. September produced two security events on consecutive days. One was an actively exploited zero-day. The other was the normal monthly isolated patch. It is easy to patch the emergency and assume the month is done.

    APSB26-146 (StyleSmuggler) compared with APSB26-138 (September update)
    DetailAPSB26-146 (StyleSmuggler)APSB26-138 (September update)
    Published7 September 20268 September 2026
    Adobe priority12
    The fixHotfix VULN-39341 for CVE-2026-75650September isolated patch for eight CVEs
    Exploited in the wild?Yes, according to AdobeAdobe is not aware of any

    What APSB26-138 fixed

    According to Adobe's bulletin, APSB26-138 resolves critical, important and moderate vulnerabilities in Adobe Commerce and Magento Open Source. The bulletin says successful exploitation could result in security feature bypass and privilege escalation, and Adobe's knowledge-base article also mentions arbitrary code execution. Adobe says it is not aware of any exploits in the wild for the issues in this bulletin, unlike StyleSmuggler.

    The bulletin lists eight CVEs, each rated Critical, with CVSS scores from 7.5 to 9.3. Two are stored cross-site scripting flaws, CVE-2026-76200 and CVE-2026-76201, both scored 9.3. Five are incorrect-authorisation flaws, such as CVE-2026-77111 (security feature bypass, CVSS 8.7, authentication required). One is a path traversal flaw.

    Adobe lists Magento Open Source 2.4.6 to 2.4.9 as affected, each at the August 2026 build or earlier, alongside Adobe Commerce 2.4.4 to 2.4.9. Updated versions for Open Source are offered for 2.4.7 and later.

    In plain language: these flaws can let an attacker gain access they should not have, get past a security control, or inject script into storefront or admin content. Published bulletins describe what was fixed, and attackers read them too.

    Adobe shipped the fixes as a monthly isolated patch (patch files per version), not as a new Composer -p release: Adobe's knowledge-base article says Composer packages are not published alongside isolated patches. Download the ZIP for your exact line, apply the matching component files in order, and verify. The ZIP names and prerequisites are in Adobe's APSB26-138 article.

    Three ways to miss this update

    1. "We did StyleSmuggler." The StyleSmuggler hotfix (VULN-39341 for CVE-2026-75650) is not included in the September isolated patch, and Adobe's knowledge-base article says to apply the hotfix in addition to it. Rotating your encryption keys and credentials after StyleSmuggler, as Adobe advises, does not replace applying APSB26-138.
    2. Wrong baseline. Isolated patches are tested only against the latest security-only (-p) release for each line, and each monthly patch builds on the ones before it. For 2.4.8, the September file expects 2.4.8-p5 with the July isolated patch already applied. Adobe's article lists what each line needs first.
    3. Open Source 2.4.6 download limits. Adobe's September notes say Magento Open Source merchants can only download these isolated patches for 2.4.7 or later. Open Source 2.4.6 left standard support on 11 August 2026, and there is no September isolated patch to download for it, although the VULN-39341 hotfix does cover Open Source 2.4.6. Licensed Adobe Commerce customers on 2.4.6 are in extended support under Adobe's lifecycle policy and can download older patches with their Composer keys. See our 2.4.6 end of life guide.

    Many Magento stores freeze code at the end of October. If you trade a November peak and September's patch is not on yet, waiting until January means months of running with fixes Adobe has already published, on a live checkout.

    Practical steps

    Do these with your developer or agency, on staging first.

    1. Confirm what you already have. Note the output of bin/magento --version. Then check whether Adobe's Commerce Version Tool (CVT) is installed by running the command below from the project root. Adobe says CVT arrived in the July 2026 isolated patch, so if the command finds nothing you need that patch first.
      php vendor/bin/patch-status --version
    2. Confirm StyleSmuggler separately. APSB26-146 / VULN-39341 is a different package. Adobe's article says the hotfix can be applied either before or after the September isolated patch, with no required order, and recommends applying it as soon as possible because CVE-2026-75650 is being actively exploited. If it is outstanding, do that first, then complete APSB26-138. Our StyleSmuggler write-up has the check script and the rotation notes, and Adobe's hotfix article has the patch files.
    3. Get onto the required baseline for your line: the release Adobe names for it (for example 2.4.9, 2.4.8-p5 or 2.4.7-p10), with every earlier monthly isolated patch for that line applied in release order before September's ZIP.
    4. Apply the September isolated patch. For each component you have installed (CE, EE, B2B, PageBuilder and so on), apply the one file in the ZIP whose version matches yours, in Adobe's order. Then clear the cache and retest checkout, admin login, payment callbacks and any GraphQL or headless storefront. If you are on Adobe Commerce on Cloud, follow Adobe's cloud patches route instead: Adobe warns that applying the isolated patch where the cloud-patches update has already fixed the issue can cause installation failures.
    5. Re-verify. Run the tool again from the project root.
      php vendor/bin/patch-status
      Adobe says the output lists applied patches, missing patches, and a PROTECTED, VULNERABLE or UNKNOWN status for each CVE. Check that September is applied and the CVEs show PROTECTED.
    6. If you are on Magento Open Source 2.4.6 or earlier, the September isolated patches are not available to you. Applying the hotfixes Adobe has released limits the damage, but it is not a plan: schedule an upgrade to a supported line, typically 2.4.8.

    How EveryHost handles this

    On EveryHost managed Magento hosting we watch Adobe's security bulletins as they land. Magento application patches, including monthly isolated patches and emergency hotfixes, are reviewed against your store, applied in staging first, then coordinated to production with your team. We do not silently push Magento application patches onto a live catalogue without that check.

    Sentinel, included on every plan, is our server-side security monitoring. It watches your admin, checkout, files and traffic for the attacks aimed at Magento, and our UK engineers act on what it finds. It gives them early warning and a faster response while a patch goes on, but it does not replace Adobe's security updates: the fixes for CVE-2026-75650 and for the APSB26-138 issues come from Adobe's hotfix and isolated patch.

    Server and stack components (OS, PHP, Varnish, Redis or Valkey, OpenSearch) are patched on our side as part of the managed service. The Magento application layer remains a joint exercise with your developer or agency.

    Sources

    Checked against Adobe's pages on 5 October 2026.

    Not sure September's patch is on your store?

    If you are unsure whether September's isolated patch is actually on your store, or you are still on 2.4.6 and need a supported line before the peak freeze, talk to us about your version and hosting setup.