Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe’s relevant notices are from September 2026, not a confirmed October Patch Tuesday release. The most urgent action is for Adobe Commerce and Magento Open Source administrators: Adobe says a separate hotfix for CVE-2026-75650 is being actively exploited, and that fix is not included in the September Commerce patch. Photoshop, Illustrator and InDesign have separate September bulletins, but their specific severity, affected versions and fixes should be checked in each product’s own advisory.

Which Adobe security bulletins were published in September 2026?

Adobe’s PSIRT archive lists bulletins through September 2026 and directs readers to its Trust Center for notices from October onward. The listed dates below are publication dates; they do not establish that all four advisories were released on the same Patch Tuesday.

Product Bulletin Publication date What is established
Adobe Commerce and Magento Open Source APSB26-138 September 8, 2026 Priority 2; addresses critical, important and moderate vulnerabilities.
Photoshop APSB26-130 September 8, 2026 The official product index confirms the bulletin and date; consult the bulletin for affected versions, severity, impact and fixed builds.
Illustrator APSB26-131 September 8, 2026 The official product index confirms the bulletin and date; consult the bulletin for affected versions, severity, impact and fixed builds.
InDesign APSB26-145 September 22, 2026 The official product index confirms the bulletin and date; consult the bulletin for affected versions, severity, impact and fixed builds.

Do not treat the Commerce exploitation warning or its severity as applying to the creative-app advisories. Each bulletin is product-specific.

What should Commerce and Magento administrators do first?

Apply the separate CVE-2026-75650 hotfix

Adobe’s remediation guidance says CVE-2026-75650 is being actively exploited. Adobe issued a separate hotfix under APSB26-146; it is not included in the APSB26-138 September isolated patch. Apply the hotfix as soon as possible, following Adobe’s instructions for the installed Commerce version and components.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe also strongly recommends rotating encryption keys and associated credentials as part of the APSB26-146 remediation.

Install the APSB26-138 update for the applicable release line

APSB26-138, dated September 8, identifies Adobe Commerce and Magento Open Source and is rated Priority 2. Adobe says it addresses critical, important and moderate vulnerabilities. Its bulletin lists versions marked August 2026 and earlier as affected on the named release lines, with September 2026 versions as the update. The bulletin also covers Commerce B2B version lines.

Confirm the exact installed edition, release line and component versions against Adobe’s bulletin and release notes before concluding an installation is covered. The September isolated patch and the APSB26-146 hotfix are separate remediations; applying one does not establish that the other has been applied.

Follow the version-specific patch order and verify

Adobe says isolated patches must match the applicable version and be applied in the required cumulative release order. Cloud merchants may have a patch path through Magento Cloud Patches. Use Adobe’s current instructions and Commerce Version Tool to check applied and missing patches and vulnerability status. A single patch file should not be assumed to work across every installation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the Commerce CVSS scores mean?

Adobe’s APSB26-138 bulletin assigns CVSS base scores to individual vulnerabilities; for example, it lists 9.3 for CVE-2026-76200 and 9.3 for CVE-2026-76201. Those scores are not a rating for every issue in the bulletin, a count of affected stores, a deployment-specific likelihood estimate or a measure of customer harm. Read each CVE entry for its own score and impact.

Adobe stated of the issues addressed in APSB26-138: “Adobe isn’t aware of any exploits in the wild for any of the issues addressed in these updates.” That statement applies to the issues in those updates; it does not negate Adobe’s separate warning that CVE-2026-75650, handled by APSB26-146, is actively exploited.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the Photoshop, Illustrator and InDesign fixes?

The official index confirms Photoshop APSB26-130 and Illustrator APSB26-131 on September 8, and InDesign APSB26-145 on September 22. The index information available here does not establish each advisory’s affected versions, vulnerability classes, severity or fixed build. Check the corresponding Adobe product bulletin before deciding whether a particular creative-app installation needs an update or describing the flaw’s impact.

In particular, there is no basis here to label those three creative-app bulletins critical or actively exploited merely because the separate Commerce hotfix addresses an actively exploited flaw.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.