APSB26-138: September's Magento Patch Doesn't Contain the Zero-Day Fix
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Emyrix Blog
Every security post we’ve published, newest first.
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Sansec disclosed StyleSmuggler on September 5: unauthenticated remote code execution on fully patched Magento and Adobe Commerce stores, used to plant backdoors before Adobe fixed it on September 7 as CVE-2026-75650.
We don't sell Sansec and get nothing if you buy it. We do run it — daily malware scans, and Shield on stores that kept getting reinfected. Here's what it's for and what it won't fix.
Adobe's August 2026 patch fixes seven Adobe Commerce and Magento vulnerabilities. The worst lets someone take over a customer account without logging in, and attacks started within a day.
Magento 2.4.6 reaches end of support on August 11, 2026 — but the deadline means very different things for Adobe Commerce and Magento Open Source. What to do with the time left.
Adobe's July 2026 bulletin listed Magento 2.4.9 among the affected versions. Why the newest release line needs the most patch discipline, not the least.
Magento 2.4.8 is supported to 2028, which makes it easy to defer patching. Adobe's cadence changed in 2026 — here's the patch process that keeps up with it.
Magento 2.4.7 is still supported until 2027 — but Adobe's July 2026 bulletin lists 2.4.7-p10 and earlier as vulnerable. Why patch level matters more than version number.
Working through one of these?
Upgrades, performance work, and emergency support for Magento, Adobe Commerce, Shopware, and custom Laravel builds.