Shared on Mage Dispatch · 23 Feb 2026
Magento.watch
Track all Magento Open Source and Adobe Commerce releases with lifecycle information
Shared on Mage Dispatch · 23 Feb 2026
Track all Magento Open Source and Adobe Commerce releases with lifecycle information
Ports the StyleSmuggler (CVE-2026-75650, CVSS 10.0) hotfix with added hardening, includes September isolated patch APSB26-138, and fixes four bugs. Provides remediation guidance for possible compromises and notes ACL and template/block policy changes that may affect previews and custom directives.
Official bulletin for APSB26-138 detailing impacted versions, severity ratings, CVEs, and fixed releases. Only partial content was accessible during fetch; open the link for full details.
Breaks down the September 2026 MCLOUD-15053 patch: fixes rollback ACL, export path traversal, GraphQL customer scope, Instant Purchase address ownership, PayPal Express quote binding, admin VAT XSS, URL escaping, plus B2B UI ACL and validator changes. Covers version-specific differences (2.4.4–2.4.9; B2B 1.3.3–1.5.3) and notes you also need APSB26-146.
Mage Dispatch is a community-run archive and bi-weekly newsletter for the Magento, Adobe Commerce and Mage-OS ecosystem. Modules, articles, security advisories and tools, hand-picked by developers and shared so good work does not disappear into the void.
Browse the latest links → Explore by topic → Submit a link → About us →