The last few weeks have been particularly busy for Adobe Commerce and Magento Open Source merchants. Two security updates from Adobe within less than a month, both addressing critical vulnerabilities, followed by a large security release affecting dozens of Amasty extensions.
Unfortunately, this may be a sign of what is ahead for the entire software industry.
AI is accelerating security research
Artificial Intelligence is changing software development, but it is also changing the way software is tested.
Security researchers can analyse code faster, automate repetitive vulnerability research and examine much larger codebases than before. The same capabilities are also becoming available to attackers.
This is not a Magento-specific problem. Operating systems, frameworks, applications and open-source projects are all being examined more intensively than ever before.
From a security perspective, this is a positive development. Vulnerabilities that may previously have remained undiscovered for years can now be identified and fixed much faster.
For merchants, however, there is another side to the story: more vulnerabilities discovered means more security updates, more testing and ultimately additional maintenance costs.
And July and August 2026 have been a very good example of this.
Two critical Adobe security releases in less than a month
On July 14, Adobe published security bulletin APSB26-73 for Adobe Commerce and Magento Open Source.
The update addressed multiple vulnerabilities, including critical issues. One of them, CVE-2026-48358, received a CVSS score of 9.1 and could result in arbitrary code execution. Another critical authorization vulnerability could allow an attacker to bypass security mechanisms and gain unauthorised access.
Less than a month later, on August 11, Adobe published another security update - APSB26-92.
Once again, the bulletin contained critical vulnerabilities alongside several important security issues affecting supported Adobe Commerce and Magento Open Source releases.
For merchants, this means that security work which would normally be planned as part of a maintenance cycle suddenly needs to be prioritised twice within a few weeks.
Amasty patches dozens of Magento extensions
Amasty, one of the largest Magento extension providers, has also recently released security updates affecting 25 extensions.
Sansec's security team analysed the disclosure and identified vulnerabilities ranging from low and medium severity to issues requiring immediate attention.
Two extensions in particular should be treated as urgent:
Advanced Product Reviews - affected versions contain a critical vulnerability that can allow an unauthenticated attacker to upload a web shell and ultimately execute code on the store. Sansec recommends upgrading amasty/advanced-review to at least 1.17.1 and its GraphQL package to 1.0.6.
Gift Card - a similarly critical vulnerability can allow an attacker to upload a web shell without authentication. The affected packages should be upgraded to amasty/module-gift-card 2.16.4 and amasty/module-gift-card-graphql 1.0.11 or newer.
If your Magento installation uses either of these extensions, we recommend treating the upgrade as an immediate priority.
The remaining affected Amasty modules should not be ignored either. However, their vulnerabilities are less critical and can generally be addressed as part of a planned security update rather than an emergency deployment. Sansec recommends scheduling the remaining upgrades within weeks rather than leaving them indefinitely.
What if you cannot deploy every patch immediately?
A Magento security update is rarely just a matter of running one command on production. Every update needs to be reviewed, deployed to a test environment and tested against custom functionality, integrations, checkout, payments and third-party extensions.
For heavily customised Adobe Commerce and Magento Open Source stores, deploying several independent security updates within a few weeks can require considerable development and QA resources. In practice, this means that even when a patch is available, deploying it immediately is not always possible.
This is where Sansec Shield can provide an important additional layer of protection.
Shield is a Magento-specific Web Application Firewall designed by Sansec specifically for eCommerce applications. Its protection rules are continuously updated based on Sansec's Magento security research and threat intelligence, helping block known exploitation attempts before they can reach vulnerable application code.
For merchants unable to deploy every security update immediately, Sansec Shield can therefore be one of the most valuable security investments: it gives your development team time to properly test and deploy patches without leaving the store unnecessarily exposed.
It does not replace regular security updates. Critical vulnerabilities still need to be patched. But it provides an additional line of defence during the period between a vulnerability being disclosed and the corresponding update being safely deployed to production.
Security is part of the cost of owning your platform
There is no point pretending otherwise: owning an open and highly customisable eCommerce platform such as Magento Open Source or Adobe Commerce comes with maintenance responsibilities.
Sometimes that means investing additional development hours into security patches which bring no new functionality visible to customers.
But ownership of the platform also brings something increasingly valuable.
In the age of AI, the ability to control your own codebase, integrations, checkout and business logic creates opportunities that closed SaaS platforms cannot always offer. Development itself is becoming faster, and merchants with access to their own technology stack will increasingly be able to build unique customer experiences and business processes in much shorter timeframes.
The same AI revolution that increases the pressure on software security can therefore also increase the value of owning and controlling your technology.
The challenge is to make sure that flexibility is supported by the right security processes.
At Alekseon, security monitoring is part of how we maintain Magento platforms. Merchants working with us are protected with Sansec's security technology, giving us continuous visibility into vulnerabilities and threats and an additional layer of protection when immediate patching is not possible.
Because Magento gives merchants freedom.
Our job is to make sure they can use that freedom safely.
