Security

Adobe Releases Security Patch APSB26-73

John Cuthbert 15 July 2026 2 min read

Adobe released its regularly scheduled security update for Commerce and Magento Open Source on 14 July 2026 (APSB26-73), addressing a mix of critical, important, and moderate vulnerabilities that could allow arbitrary code execution, security feature bypass, or privilege escalation. If you’re running either platform, here’s what actually needs your attention.

What’s affected

The bulletin covers every actively supported release line: Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier — plus the equivalent Magento Open Source versions. One of the vulnerabilities is tracked as VULN-27015; full technical detail sits behind Adobe’s own advisory.

If you’ve fallen behind on prior patches Adobe’s isolated patches for this bulletin are cumulative on top of the latest security-only release for your line, not standalone. Apply any outstanding prior patches first, or this one may not apply cleanly.

How to apply it

Patches are version-specific — download the one matching your exact release from repo.magento.com, not a generic 2.4.x patch. On Cloud infrastructure, run the Quality Patches Tool first to confirm what’s already applied before layering the new one on top. As always: apply to staging, run your regression suite, then roll to production. Adobe hasn’t published a hard deadline for this one, but “as soon as possible” is the actual guidance — vulnerabilities at this severity are exactly the kind that get reverse-engineered from the patch diff shortly after release.

If patch management is the thing that keeps landing on your desk at the worst possible time, that’s exactly the gap a Development Retainer closes — we track bulletins like this as part of ongoing maintenance, not as a fire drill.

John Cuthbert

Devsigh — commerce and technology specialists working directly with ambitious retail, hospitality, and B2B brands.

Need your Adobe Commerce store patched properly?