September’s Magento Patch (APSB26-138) Is Separate From the Hotfix
Adobe released two Magento security updates on consecutive days in September. We have already had clients ask if “the September patch” means they are done. It does not.
7 September: APSB26-146, a Priority 1 hotfix for an exploited remote code execution bug. 8 September: APSB26-138, the regular monthly security update. Priority 2. Different CVEs. Different package. Adobe’s own bulletin tells you to apply the hotfix and this one.
The short version
- APSB26-138 is the 2026-sep build. It does not replace the CVE-2026-75650 hotfix.
- The highest scores here are stored XSS at 9.3, and they do not need a login.
- B2B has its own holes again. If you sell to companies, take the B2B September package.
What is in 138, without the spreadsheet
Two stored XSS issues an unauthenticated visitor can plant. A pile of incorrect-authorization bugs, a couple tagged B2B. A path-traversal issue that needs an admin. Adobe was not aware of in-the-wild exploits for this set. That is the only comfortable sentence in the bulletin.
XSS without a login is the one we explain to non-engineers like this: someone leaves a script in a place your staff will open later. The next admin who views that order, review or form can hand over their session without noticing. You do not need a movie-hacker soundtrack for that to ruin a week.
Source: APSB26-138. The hotfix you should already have is APSB26-146.
Which version string you want to see
Adobe Commerce: 2.4.9-2026-sep down through 2.4.4-2026-sep. B2B: the matching 2026-sep packages. Magento Open Source: 2.4.9, 2.4.8 or 2.4.7-2026-sep. If you are on Open Source 2.4.6, read Adobe’s notes for that line before you assume a September zip exists.
If the store is behind, this is the order
- Hotfix APSB26-146 if it is not on. That is the fire.
- Confirm July and August isolated patches are present. These monthlies stack. Do not leap to September and hope.
- Apply 2026-sep on staging. Checkout, admin, B2B company flow, any content or file upload you actually use.
- Production in a quiet window. Watch logs for a day. You are looking for fatals and odd admin logins, not a novel.
Questions we keep getting
We applied the hotfix. Are we done?
You are done with the Priority 1 fire. You are not done with September. APSB26-138 is a separate set of bugs. Apply the 2026-sep build when staging is green.
Priority 2 means we can wait a month?
Adobe’s rating means “soon,” not “whenever.” A few of these issues need no login. We would rather see this on production this week than on a backlog titled “security (later).”
What if July or August never landed?
Stop and put those on first. Isolated monthly files are cumulative. Skipping a month and taking only September is how you get a half-patched store that looks updated in the admin and is not.
Behind on the 2026 Magento monthlies?
Tell us the current version string. We will map which patches are missing, apply them in order on staging, and get production to a place you can defend.
