Adobe has released a critical Magento 2 security update (APSB25-50) as of June 10, 2025. This update addresses multiple high-risk vulnerabilities that could expose stores to unauthorized access, privilege escalation, and XSS attacks. Affected versions include both Adobe Commerce and Magento Open Source 2.4.x lines. Adobe strongly recommends applying the latest patches or isolated fixes immediately to ensure store security and compliance. In this post, we break down what the update includes, which CVEs it resolves, and how store owners can apply the patch safely.

Affected Magento Versions

The following versions of Adobe Commerce and Magento Open Source are affected by the vulnerabilities in APSB25-50:

Product Affected Versions
Adobe Commerce (Cloud & On-Premise) 2.4.8 and earlier, 2.4.7-p5 and earlier, 2.4.6-p10 and earlier, 2.4.5-p12 and earlier, 2.4.4-p13 and earlier
Magento Open Source 2.4.8  2.4.7-p5 and earlier  2.4.6-p10 and earlier  2.4.5-p12 and earlier
Adobe Commerce B2B Extension 1.5.2 and earlier, 1.4.2-p5 and earlier, 1.3.5-p10 and earlier

Solution

All12.4.x release notes

Product Updated Version Platform Priority Rating Installation Instructions Adobe Commerce
2.4.9-alpha1

2.4.8-p1 for 2.4.8

2.4.7-p6 for 2.4.7-p5 and earlier

2.4.6-p11 for 2.4.6-p10 and earlier

2.4.5-p13 for 2.4.5-p12 and earlier

2.4.4-p14 for 2.4.4-p13 and earlier

  Adobe Commerce B2B
1.5.3-alpha1

1.5.2-p1 for 1.5.2

1.4.2-p6 for 1.4.2-p5 and earlier

1.3.4-p13 for 1.3.4-p12 and earlier

1.3.3-p14 for 1.3.3-p13 and earlier

All 2 Magento Open Source 
2.4.9-alpha1

2.4.8-p1 for 2.4.8

2.4.7-p6 for 2.4.7-p5 and earlier

2.4.6-p11 for 2.4.6-p10 and earlier

2.4.5-p13 for 2.4.5-p12 and earlier

All 2 Adobe Commerce and Magento Open Source  Isolated patch on CVE-2025-47110 All 1 Release Notes for Isolated Patch on CVE-2025-47110.

Adobe advises all Magento users to install the latest available patches based on their current version. The updates address recent security vulnerabilities and are assigned high-priority ratings. The fix includes patch releases for Adobe Commerce, Magento Open Source, and B2B packages—ranging from versions 2.4.4 to 2.4.8 and their patch updates.

For those who can’t upgrade fully, an isolated patch is available to specifically resolve CVE-2025-47110.

View official Adobe patch instructions

 

Vulnerability Details

The APSB25-50 bulletin addresses five vulnerabilities, summarized below:

CVE ID Severity Type Description
CVE‑2025‑47110 Critical Stored XSS via SSTI Admin users could inject malicious scripts through server-side templates
CVE‑2025‑43585 Critical Improper Authorization Attackers could access restricted features by bypassing checks
CVE‑2025‑27206 Important Access Control Misconfiguration Could allow unauthorized users to access data they shouldn’t
CVE‑2025‑27207 Important Privilege Escalation (B2B) Users may gain elevated privileges through flawed role permissions
CVE‑2025‑43586 Important Another B2B Privilege Escalation Similar issue, specific to B2B features

How to Apply APSB25-50 Security Patches in Magento 2

To secure your Magento store against the vulnerabilities covered in APSB25-50:

Back Up Your Site – Always take a full backup of your files and database before applying any patch.
Download the Correct Patch – Choose the appropriate patch file based on your current Magento version. These are available from Adobe’s Security Bulletin or partners.
Upload Patch Files – Place the .patch file in your Magento root directory.
Run Patch Command – Use SSH to run the patch. Example:

For VULN-31609_2.4.X.patch:
patch -p1 < VULN-31609_2.4.X.patch

For VULN-31547_2.4.8.patch:
patch -p1 < VULN-31547_2.4.8.patch

After applying the patch, make sure to refresh Magento’s cache so the updates take effect properly across your site.

Published On: September 2nd, 2026 / Categories: Magento 2 / By /

Let’s Make Things Happen

Transforming your ideas into reality is our expertise. Share your vision without hesitation, and let our skilled team bring it to life.

“Akshar Group Technologies did such a great job at resolving the initial problem that the partnership expanded to include further development and is still ongoing. Diligent and committed, the team goes above and beyond to deliver their work promptly. They have an extensive knowledge base.”

Justin Delp

Digital Engage, US

By submitting my data I agree to be contacted