Adobe released APSB26-73 on July 14, 2026. We do not usually tell clients to break a release freeze for a patch. We did for this one.
Why this one is different
The bulletin resolves 13 vulnerabilities, 8 of them critical. The one that matters is CVE-2026-48358: an unauthenticated, zero-interaction flaw in the webhooks component leading to arbitrary code execution, rated 10.0 by NVD.
Unpack that phrasing, because every word in it is load-bearing. Unauthenticated means no account is needed. Zero-interaction means nobody at your end has to click anything. Arbitrary code execution means the attacker runs their code on your server. A 10.0 is as bad as the scale goes.
Second in line is CVE-2026-48356, an unrestricted file upload flaw at CVSS 9.6.
Who is affected
Every supported line: 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier.
Being on the newest version is not cover here. 2.4.9 shipped in May and is on the list.
What to do
Patch. Today, if you have not.
Adobe stated it was not aware of any exploits in the wild for the issues addressed — which is the argument for moving now rather than a reason to relax. The window between a bulletin like this and working exploit code is measured in days, because the bulletin tells everyone where to look. Card-skimming groups have historically been quick with Adobe Commerce specifically.
Adobe shipped isolated patches for this, so the change is security-only and the regression surface is small. If your process says a patch needs a full UAT cycle, this is the case for having a faster lane for security-only releases — and a good moment to define it, before the next one.
If we look after your store, this went on in July. If you are not sure who applied yours, that is worth confirming today rather than assuming.
:quality(75))