Shared on Mage Dispatch · 16 Sep 2026
StyleSmuggler APSB26-146: What the Patch Changes and What's Still Vulnerable
Breaks down the APSB26-146/VULN-39341 hotfix: neutralizing payloads in error reports, restricting email template data types, adding admin preview ACL checks, and validating block types before instantiation. Clarifies why disabling GraphQL wasn't enough, covers the additional Bigbridge directive-signing patch, and shares practical steps for applying patches and cleaning compromised stores.