Pinned
Official bulletin for APSB26-138 detailing impacted versions, severity ratings, CVEs, and fixed releases. Only partial content was accessible during fetch; open the link for full details.
Ports the StyleSmuggler (CVE-2026-75650, CVSS 10.0) hotfix with added hardening, includes September isolated patch APSB26-138, and fixes four bugs. Provides remediation guidance for possible compromises and notes ACL and template/block policy changes that may affect previews and custom directives.
Breaks down the September 2026 MCLOUD-15053 patch: fixes rollback ACL, export path traversal, GraphQL customer scope, Instant Purchase address ownership, PayPal Express quote binding, admin VAT XSS, URL escaping, plus B2B UI ACL and validator changes. Covers version-specific differences (2.4.4–2.4.9; B2B 1.3.3–1.5.3) and notes you also need APSB26-146.
Rapidez, the Laravel/Vue headless frontend for Magento 2, hit v5: flat tables are gone as a dependency, the stack is now on Vue 3 and Tailwind 4, customer group and tier pricing display properly, and there's product video support, cache tags, and four new packages (Quick Order, Custom Reorder, Fullscreen Search, Statamic Quote).
Track all Magento Open Source and Adobe Commerce releases with lifecycle information
Mage-OS Distribution 2.1.0 is released, featuring bug fixes, performance enhancements, and new features like theme detection commands. Key fixes include resolving customer attributes issues and minor improvements in MySQL/MariaDB compatibility. This update also includes maintenance updates to the documentation.