Shared on Mage Dispatch · 24 Mar 2026
PolyshellPatch
Mitigates the PolyShell vulnerability (APSB25-94) — an unrestricted file upload in the Magento REST API that allows attackers to upload executable files via cart item custom option file uploads.
Shared on Mage Dispatch · 24 Mar 2026
Mitigates the PolyShell vulnerability (APSB25-94) — an unrestricted file upload in the Magento REST API that allows attackers to upload executable files via cart item custom option file uploads.
Fixes 403s on admin page/block saves by identifying and removing Fastly VCL snippets (accord-rce, accord_rce_1) via the CLI, with steps to clone, validate, and activate a clean version; also covers applying the real CVE-2026-75650 patch or scoping a storefront-only rule.
Covers how the Style Smuggler vulnerability (CVE-2026-75650) works, how to detect potential compromise, and practical remediation and hardening steps. Note: Content could not be fetched; details inferred from the URL.
Ports the StyleSmuggler (CVE-2026-75650, CVSS 10.0) hotfix with added hardening, includes September isolated patch APSB26-138, and fixes four bugs. Provides remediation guidance for possible compromises and notes ACL and template/block policy changes that may affect previews and custom directives.
Mage Dispatch is a community-run archive and bi-weekly newsletter for the Magento, Adobe Commerce and Mage-OS ecosystem. Modules, articles, security advisories and tools, hand-picked by developers and shared so good work does not disappear into the void.
Browse the latest links → Explore by topic → Submit a link → About us →