Adobe has released a critical security update APSB25-94 on October 14, 2025, addressing multiple high-severity vulnerabilities that could allow:
Security feature bypass (Improper Access Control)
Privilege escalation (Cross-Site Scripting)
Arbitrary code execution (Incorrect Authorization)
Update to the latest patched version immediately.
Always back up your store before applying patches.
Test the update on a staging environment first.
Apply selective patches if a full upgrade isn’t possible.
Adobe Commerce ≤ 2.4.9-alpha2
Commerce B2B ≤ 1.5.3-alpha2
Magento Open Source ≤ 2.4.9-alpha2
2.4.9-alpha3
2.4.8-p3
2.4.7-p8
These updates are strongly recommended to prevent potential risks such as unauthorized admin access, customer data exposure, or downtime.
For a deeper look, see the official Adobe release guide or our detailed post on the Meetanshi blog.
Don’t have time to apply the patch/upgrade Magento version yourself? No worries, our experts can handle it for you. Check out our Magento Security Patch Installation Service.
To complete your post with all the relevant versions and their corresponding patches.
Affected and Patched Versions:
Adobe Commerce:
2.4.9-alpha2 and earlier → 2.4.9-alpha3
2.4.8-p2 and earlier → 2.4.8-p3
2.4.7-p7 and earlier → 2.4.7-p8
2.4.6-p12 and earlier → 2.4.6-p13
2.4.5-p14 and earlier → 2.4.5-p15
2.4.4-p15 and earlier → 2.4.4-p16
Adobe Commerce B2B:
1.5.3-alpha2 and earlier → 1.5.3-alpha3
1.5.2-p2 and earlier → 1.5.2-p3
1.4.2-p7 and earlier → 1.4.2-p8
1.3.5-p12 and earlier → 1.3.5-p13
1.3.4-p14 and earlier → 1.3.4-p13
1.3.3-p15 and earlier → 1.3.3-p16
Magento Open Source:
2.4.9-alpha2 and earlier → 2.4.9-alpha3
2.4.8-p2 and earlier → 2.4.8-p3
2.4.7-p7 and earlier → 2.4.7-p8
2.4.6-p12 and earlier → 2.4.6-p13
2.4.5-p14 and earlier → 2.4.5-p15