Apart from the flagship creative tools, Adobe has also patched vulnerabilities in Adobe Commerce, Magento Open Source, and Adobe Bridge, among other products. Similarly, Adobe FrameMaker had vulnerabilities that could lead to denial-of-service attacks or arbitrary code execution. Adobe also released patches for other creative tools, including Adobe Animate, Adobe FrameMaker, and Adobe XMP Toolkit SDK. Similarly, Photoshop 2025 and Photoshop 2024 versions were found to contain vulnerabilities leading to arbitrary code execution. For Premiere Pro, a critical vulnerability could allow attackers to execute arbitrary code, potentially compromising system integrity. Adobe’s latest security update also includes fixes for Adobe Premiere Pro and Adobe Photoshop, both of which are used extensively in the creative industry.
A single publishing or broadcast group runs merchandise stores for individual titles, ticketing and licensing shops, and promotional storefronts tied to specific releases. Adobe’s bulletin says the vendor is not aware of exploits in the wild for any issue in the release. According to eCommerce security company Sansec, hackers started exploiting the critical PolyShell issue en masse last week, just two days after public disclosure. Powerful, scalable, and customer-centric commerce solutions tailored for your growth. Both platforms have advantages and disadvantages, and the best choice depends on your business needs, technical expertise, and budget. Shopify is a hosted solution, meaning it takes care of hosting and maintenance, making it easier for beginners to set up an online store.
Although no active exploitation has been detected in the wild, Adobe has emphasized the critical nature of the vulnerability and urged users to apply the necessary security patches immediately. According to Adobe’s official advisory, a malicious actor could exploit this bug by interacting with the Commerce REST API, potentially taking full control of customer accounts. Buyer and Seller Protection are also available for eligible transactions, providing added confidence for both merchants and customers. Hosted fields keep card details off your server, helping merchants meet PCI compliance requirements for both payment processing and financial data storage. Payment Services is a PCI DSS compliant payment processing solution, built on PCI Level 1 certified infrastructure to ensure secure payments and protect sensitive financial data.
- Magento 2.4.9 is a highly recommended upgrade for all Magento Open Source and Adobe Commerce users who want to keep their stores secure, fast, and feature-rich.
- The Site-Wide Analysis Tool is a proactive self-service tool and central repository that includes detailed system insights and recommendations to ensure the security and operability of your Adobe Commerce installation.
- Defenders should also note the divergence between Adobe’s statement that it is not aware of in-the-wild exploitation and third-party WAF telemetry indicating blocked exploitation attempts.
- Adobe now releases monthly isolated security patches (security fixes only, no quality/feature updates).
- Additionally, the California-headquartered company pointed out that the vulnerability can be exploited by an attacker with non-administrative privileges.
Supported Browsers
Adobe Commerce and Magento Open Source power business-critical ecommerce operations and routinely process customer accounts, payment information, and order data. Nevertheless, merchants and administrators are strongly encouraged to install the latest security updates as soon as possible to reduce risk and maintain a secure e-commerce environment. Adobe has confirmed that it is not aware of any active exploitation in the wild for the vulnerabilities addressed in this release. Additionally, the California-headquartered company pointed out that the vulnerability can be exploited by an attacker with non-administrative privileges.
This is the community-supported, free version of Magento, ideal for small to medium-sized businesses. With our proven expertise and free Magento upgrades solution, we help merchants stay ahead of every Magento release with minimal effort and maximum stability. As a free upgrade solution from On Tap, it delivers all future Magento minor releases, security patches, and hotfixes in line with platform’s release cycle at no additional cost. Start building event-driven integrations and high-performance storefronts for Adobe Commerce using modern development tools.
I can’t stress enough how important services like Catalog Service are for Vaimo’s enterprise-grade customers, enabling better performance and reliability of the system. App Builder allows developers to build modern Adobe Commerce applications and extend the functionality of core applications. The Site-Wide Analysis Tool is a proactive self-service tool and central repository that includes detailed system insights and recommendations to ensure the security and operability of your Adobe Commerce installation. It can potentially be a competitor to products like Algolia and Klevu due to its native integration with Adobe Commerce and Product Recommendations by Adobe Sensei. 2 This was a new model for distributing Adobe Commerce features, as previously they were available as a core package, only to be enabled or disabled from the core code.
Embracing these advancements requires not just technology but a partner skilled in harnessing Adobe Commerce’s full potential. At the same time, features like Adobe Commerce AR Viewer are already being introduced as Adobe Commerce Marketplace Extensions. Adobe Commerce’s performance and functional bottlenecks are to be solved by introducing more Commerce. We can now expect SaaS product updates and releases with each Adobe Commerce release. This is an important feature that I wanted to highlight as it streamlines upgrade paths, including first-party modules.
If successfully exploited, these vulnerabilities could result in privilege escalation, arbitrary code execution, security feature bypass, unauthorized access to application functionality, or limited disclosure of sensitive information. In a potential attack scenario, a bad actor could abuse the affected upload-related functionality to run malicious SQL against BW/BPC data stores, extract sensitive data, and delete or corrupt database content. The company noted that it’s not aware of any of the flaws being exploited in the wild. These partners support key https://best-adobe-commerce-cloud-agencies.com/ areas such as marketing automation, payments, content management, shipping, taxation, hosting, performance optimization, and more. Many Solution Partners also develop proprietary extensions, integrations, and performance enhancements that extend the capabilities of the core platform. It shares the same core files as Magento Open Source but is not freely licensed and has additional proprietary features and functionality.
Stores on 2.4.6 must upgrade before August 2026. Multiple CE versions focused on security and performance. For more information and advanced features see theSend to Caas documentation page. The policy document will help you align with Adobe’s plan, while the other resources will help you work with customers to plan and execute the upgrade with confidence. We also encourage customers that are looking to reduce operational overhead to consider moving to Adobe Commerce as a Cloud Service, which eliminates manual upgrades and provides continuous security and feature updates in a managed SaaS environment.
Accounting Assistant IV Leland Hucks, hailing from MacGregor enjoys watching movies like “Edward, My Son” and LARPing. Took a trip to Barcelona and drives a Ferrari 275 GTB/4*S ART Spider.
