Research
APSB26-73 - APSB26-73: Security update available for Adobe Commerce Security Update
Bulletin Information
- Bulletin ID: APSB26-73
- Product: APSB26-73: Security update available for Adobe Commerce
- Published: July 14, 2026
- Priority: 2
- Severity: Critical
- CVE Count: 14
Affected Versions
- Adobe Commerce: 2.4.92.4.8-p5 and earlier2.4.7-p10 and earlier2.4.6-p15 and earlier2.4.5-p17 and earlier2.4.4-p18 and earlier
- Adobe Commerce B2B: 1.5.31.5.2-p5 and earlier1.4.2-p10 and earlier1.3.4-p17 and earlier1.3.3-p18 and earlier
- Magento Open Source: 2.4.92.4.8-p5 and earlier2.4.7-p10 and earlier2.4.6-p15 and earlier
- Adobe Commerce Events: 1.6.0 to 1.20.0
Vulnerability Details
Total Vulnerabilities: 14
Severity Breakdown:
- Moderate: 2
- Important: 4
- Critical: 8
Key Vulnerabilities:
1. CVE-2026-48356
- Category: Unrestricted Upload of File with Dangerous Type (CWE-434)
- Impact: Privilege escalation
- Severity: Critical
- CVSS Score: 9.6
- Authentication Required: No
2. CVE-2026-48358
- Category: Improper Encoding or Escaping of Output (CWE-116)
- Impact: Arbitrary code execution
- Severity: Critical
- CVSS Score: 9.1
- Authentication Required: Yes
3. CVE-2026-47994
- Category: Cross-site Scripting (Stored XSS) (CWE-79)
- Impact: Privilege escalation
- Severity: Critical
- CVSS Score: 8.7
- Authentication Required: Yes
…and 11 more vulnerabilities
CVE Identifiers
CVE-2026-48358, CVE-2026-47996, CVE-2026-47999, CVE-2026-47998, CVE-2026-47992, CVE-2026-47997, CVE-2026-47994, CVE-2026-47988, CVE-2026-47995, CVE-2026-48000, CVE-2026-48356, CVE-2026-48371, CVE-2026-48001, CVE-2026-47984