Adobe APSB26-73 Security Bulletin is a security advisory published by Adobe in July 2026 for Adobe Commerce and Magento Open Source. The bulletin documents multiple security vulnerabilities affecting supported versions of the ecommerce platform and provides guidance for applying security updates.

Overview

APSB26-73 addresses vulnerabilities of varying severity, including issues that could allow arbitrary code execution, privilege escalation, and security feature bypass. The security bulletin applies to several supported versions of Adobe Commerce and Magento Open Source.

Adobe releases security bulletins periodically to notify customers of newly identified vulnerabilities and to provide recommended remediation procedures. These advisories include information about affected software versions, Common Vulnerabilities and Exposures (CVEs), severity ratings, and available security updates.

Affected Versions

According to Adobe, APSB26-73 affects multiple supported releases of Adobe Commerce and Magento Open Source, including:

Adobe Commerce 2.4.9 Adobe Commerce 2.4.8-p5 and earlier Adobe Commerce 2.4.7-p10 and earlier Adobe Commerce 2.4.6-p15 and earlier Adobe Commerce 2.4.5-p17 and earlier Adobe Commerce 2.4.4-p18 and earlier

The bulletin also applies to corresponding Magento Open Source releases supported by Adobe.

Security Improvements

The July 2026 bulletin introduces updated security patches intended to address reported vulnerabilities across supported platform versions. Adobe also updated isolated security patches for eligible installations and expanded tools available for verifying installed security updates.

The security bulletin includes vulnerability classifications, CVE references, and technical guidance for administrators responsible for maintaining Adobe Commerce installations.

Deployment Considerations

Adobe recommends reviewing system requirements before applying security updates. Organizations are encouraged to verify software compatibility, back up production environments, and validate updates in staging environments before deployment. Stores using third-party extensions or custom modules may require additional compatibility testing after the update has been installed.

See Also Adobe Commerce Magento Open Source Common Vulnerabilities and Exposures (CVE) Application security Software patch References Adobe. APSB26-73 Security Bulletin for Adobe Commerce and Magento Open Source. Adobe Experience League. Adobe Commerce Security Documentation.