Adobe’s July Magento Patch (APSB26-73): What You Actually Need to Do
Adobe published APSB26-73 on 14 July 2026. Open the bulletin and you get fourteen CVEs and a wall of version strings. That is fine for a security engineer. It is not an answer when someone asks, at 9am, “do we patch this week?”
Here is the version we give store owners. What changed, what is actually dangerous, and how to put the July patch on without turning checkout into a science project.
The short version
- Priority 2. Plan it this month. You do not need a midnight emergency unless the store takes public file uploads or runs a lot of webhooks.
- The first issue we care about is an unauthenticated file upload (CVE-2026-48356, CVSS 9.6). No login. No admin.
- July is now the floor. The August and September patches assume this one is already on.
Who this actually hits
If you are still on a May or June-era 2.4.x line, treat the store as affected. Adobe called out Adobe Commerce from 2.4.4 through 2.4.9, Magento Open Source 2.4.6 through 2.4.9, the matching B2B packages, and Commerce Events 1.6 to 1.20.
The fix is the 2026-jul build for your line – 2.4.9-2026-jul, 2.4.8-2026-jul, and so on. Events goes to 1.21.0. Stay on the minor you are on. You do not have to jump to 2.4.9 just to take this patch.
What is worth worrying about
We are not going to reprint Adobe’s table. Three patterns show up again and again.
File upload without a login. If that lands, privilege escalation is the next step. Custom modules that accept images, CSVs or “quick import” files should be on your smoke-test list after the patch.
Stored XSS that needs an account. A customer or a tired admin pastes something nasty. The next person who opens that page in admin pays for it. That is how sessions disappear without anyone noticing a “hack.”
Authorization bugs that skip the “are you allowed?” check. A few of those do not need a login either. That is customer data walking out the door, not a theoretical CWE number.
There is also a webhook encoding issue that can lead to code execution. It needs an admin, so it is not the internet-wide scanner problem. It is a problem if you have been loose with admin accounts or webhook endpoints.
Adobe said they were not aware of exploits in the wild when they published this. That is comforting for about a week. Magento patches get reverse-engineered quickly. We treat “no known exploit” as “you still have a little time,” not “this can wait until Q4.”
How we apply it
- Check Admin → System → About Magento. If the version already ends in
2026-jul, you are done with this bulletin. - Full backup. Then staging – not production first.
- Apply the matching 2026-jul package, plus the B2B or Events piece if you use them.
- Walk checkout, account login, admin, and any upload or webhook flow you actually use.
- Then look at August. This patch is not the end of the story.
Adobe’s source bulletin is APSB26-73. Read that if you need the CVE list. Use this page if you need a decision.
Questions we keep getting
Do we have to be on 2.4.9 first?
No. Stay on your current 2.4.x line and take the July build for that line. Jumping minors and patching security in the same window is how weekends get ruined.
What if we have a lot of custom modules?
That is why staging exists. File-upload forms and admin tools are where we see surprises. If a module still type-hints something the patch touched, you want to find that on Tuesday, not on a live checkout.
Is Priority 2 an excuse to wait?
It means you can schedule it. It does not mean you can ignore it. The unauthenticated upload alone is enough reason to get this done before the next bulletin stacks on top.
Want this applied without a Friday-night surprise?
Tell us the Magento version, whether you run B2B, and when you can give us a staging copy. We will come back with a clear patch plan – not a 14-row CVE spreadsheet.
