Adobe published security bulletin APSB26-49 on May 12, 2026 — the same day 2.4.9 reached general availability. If the release got all the attention, this is the one that applies to you if you are staying put for now.
What it patches
The patched versions are 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18.
The bulletin covers 2.4.9-beta1, 2.4.8-p4 and earlier, 2.4.7-p9 and earlier, 2.4.6-p14 and earlier, 2.4.5-p16 and earlier, and 2.4.4-p17 and earlier. Adobe Commerce B2B is in scope too, back through 1.5.0 and earlier, 1.4.2-p3 and earlier, 1.3.5-p8 and earlier, 1.3.4-p10 and earlier and 1.3.3-p11 and earlier — worth checking if you run B2B, because it is easy to patch the core and forget the extension.
Severity ratings reach up to CVSS 8.7. Successful exploitation could lead to arbitrary code execution, arbitrary file system write, application denial-of-service and security feature bypass.
The practical bit
Upgrading to 2.4.9 is not a substitute for reading this one, and the reverse is also true. Applying the May patch buys you time to plan the 2.4.9 move properly rather than doing it in a hurry because you conflated the two.
For B2B merchants: check the extension version separately. That is the gap we most often find on stores we inherit.
:quality(75))