Adobe released its regularly scheduled security update for Commerce and Magento Open Source on 14 July 2026 (APSB26-73), addressing a mix of critical, important, and moderate vulnerabilities that could allow arbitrary code execution, security feature bypass, or privilege escalation. If you’re running either platform, here’s what actually needs your attention.
What’s affected
The bulletin covers every actively supported release line: Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier — plus the equivalent Magento Open Source versions. One of the vulnerabilities is tracked as VULN-27015; full technical detail sits behind Adobe’s own advisory.
How to apply it
Patches are version-specific — download the one matching your exact release from repo.magento.com, not a generic 2.4.x patch. On Cloud infrastructure, run the Quality Patches Tool first to confirm what’s already applied before layering the new one on top. As always: apply to staging, run your regression suite, then roll to production. Adobe hasn’t published a hard deadline for this one, but “as soon as possible” is the actual guidance — vulnerabilities at this severity are exactly the kind that get reverse-engineered from the patch diff shortly after release.
If patch management is the thing that keeps landing on your desk at the worst possible time, that’s exactly the gap a Development Retainer closes — we track bulletins like this as part of ongoing maintenance, not as a fire drill.
