MageSmith
31 bulletins · catalog snapshot 2026-06-16

Magento 2 Security Patch Tracker

Adobe Commerce + Magento Open Source security bulletins, with CVE references, affected and fixed version ranges, and a quick "is my version safe?" check.

Get notified when Adobe ships a new bulletin

One email per new bulletin (or batch, when several drop together). Filter by severity. Unsubscribe with one click from any email. Free.

Have a MageSmith account? Manage your subscription in app — auto-confirmed, no email round-trip.

Sign in to manage →

Is my version safe?

Paste your Magento version (e.g. 2.4.6-p3) to see which bulletins still apply.

7 result(s) in critical · Clear

APSB25-50 critical 2025-07-08
3 CVE(s)

Security update available for Adobe Commerce | APSB25-50

Fixes multiple vulnerabilities including XSS, server-side request forgery, and improper input validation. Adobe is not aware of any exploits in the wild but recommends prioritising this patch.

APSB25-08 critical 2025-02-11
3 CVE(s)

Security update available for Adobe Commerce | APSB25-08

Critical-severity update addresses arbitrary file system read and authentication bypass. Apply immediately on internet-facing installs.

APSB24-73 critical 2024-10-08
3 CVE(s)

Security update available for Adobe Commerce | APSB24-73

Multiple vulnerabilities, the most severe of which could result in arbitrary code execution. Affects every supported Adobe Commerce + Magento Open Source line.

APSB24-40 critical 2024-06-11
4 CVE(s)

CosmicSting: XXE in REST API (CVE-2024-34102) | APSB24-40

Critical XXE vulnerability in the REST API allows unauthenticated attackers to read arbitrary files including the encrypted env.php key — leading to full session hijack and remote code execution. Widely exploited in the wild within days of disclosure. Mass-scanned by botnets; emergency patching mandatory.

APSB24-18 critical 2024-04-09
5 CVE(s)

Security update available for Adobe Commerce | APSB24-18

Multiple vulnerabilities resulting in arbitrary code execution, security feature bypass, and privilege escalation. Includes a critical pre-auth chain affecting the storefront API.

APSB23-35 critical 2023-06-13
4 CVE(s)

XSLT pre-auth code execution | APSB23-35

Pre-authenticated remote code execution via the XSLT processor's external entity handling. Critical — exploitable from the public internet without credentials. Adobe shipped this out-of-band.

APSB22-12 critical 2022-02-13
2 CVE(s)

TrojanOrders pre-auth RCE (CVE-2022-24086) | APSB22-12

Improper input validation in the checkout flow allows unauthenticated attackers to execute arbitrary code via crafted email-template inputs. Mass-exploited via the 'TrojanOrders' campaign within 48 hours of disclosure — every unpatched store is presumed compromised. Adobe shipped APSB22-13 a week later as a follow-up to widen the fix.

Catalog mirrors Adobe Security Bulletins. Always verify against the official source before patching production — this catalog is rebuilt on each MageSmith release and may lag a brand-new bulletin by days.

Every Magento dev tool, in one hosted workspace.

Free to sign up. Nothing to install. Drafts, audits, and projects saved across every tool.