APSB26-138: September's Magento Patch Doesn't Contain the Zero-Day Fix
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Emyrix Blog
Practical writing on Magento, Adobe Commerce, and Laravel — the performance, security, and upgrade work that keeps stores and applications earning.
Adobe shipped two Magento security patches a day apart in September 2026, and the monthly one doesn't include the emergency fix for CVE-2026-75650. You need both, in order.
Sansec disclosed StyleSmuggler on September 5: unauthenticated remote code execution on fully patched Magento and Adobe Commerce stores, used to plant backdoors before Adobe fixed it on September 7 as CVE-2026-75650.
Four numbers that settle the argument about whether a Magento store is slow, where to get them, which pages to measure, and what each one tells you about where the problem is.
Products missing from a category, prices that don't match the admin, a reindex that never finishes. What Magento's indexers actually do, how they fail, and how to tell which failure you have.
Compiled plugins, PHP 8.4 lazy objects and bfcache all ship in the Mage-OS distribution. One of them was proposed to Magento years ago and never merged. What each does, and what to verify.
Mage-OS 3 ships an interactive installer, a 98-package minimal install, returns and an admin audit log. It also drops PHP 8.2 and removes setup:backup. What to check before you take it.
Two of the benefits are features Adobe sells only with a Commerce license. Several more are modules that exist in neither Magento nor Adobe Commerce, and one is a replacement admin theme.
The honest counterweight to the Mage-OS case. If you're on Adobe Commerce, here's what has no equivalent on the other side — the features, the services, the infrastructure, and the contract.
We don't sell Sansec and get nothing if you buy it. We do run it — daily malware scans, and Shield on stores that kept getting reinfected. Here's what it's for and what it won't fix.
Adobe's August 2026 patch fixes seven Adobe Commerce and Magento vulnerabilities. The worst lets someone take over a customer account without logging in, and attacks started within a day.
Magento 1 has no upgrade path to anywhere, so nothing carries over to Magento 2 either. What a move to Shopware 6 involves, and when it is the right call.
Magento 2.2 lost support in December 2019. You cannot jump straight to 2.4, and the release that rewrites your database on the way is 2.3, not the destination.
Magento 1 lost support in June 2020. Moving to Magento 2 is a rebuild with a data migration attached — what the Data Migration Tool covers, what it doesn't, and how to scope the rest.
Magento 2.3 lost support in September 2022. Moving to a current 2.4 release crosses a PHP major version, two framework migrations, and a mandatory search engine — here's the staged path.
Magento 1 lost vendor support in 2020, but OpenMage LTS keeps the codebase alive on PHP 8.1–8.5 with Composer installs and ongoing security backports. What it fixes, and what it doesn't.
What to look for in a Magento development agency or partner — engineering seniority, upgrade discipline, communication, and the red flags that predict a painful project.
How to configure Redis (or Valkey) and OpenSearch for a fast, stable Magento 2 store — cache vs session separation, eviction policy, heap sizing, and the defaults that hurt under load.
How to plan and execute a safe Magento 2 upgrade — compatibility audits, staged rollout, regression testing, and zero-downtime deployment without breaking a live store.
A practical Magento (Adobe Commerce) vs Shopify Plus comparison for growing merchants — control, B2B, total cost of ownership, and the trade-offs that actually decide it.
An opinionated comparison of checkout options for Magento 2 stores on Hyvä — official Hyvä Checkout, Luma via theme fallback, the React checkout, third-party one-step checkouts, and custom Magewire builds.
A prioritized, runnable Magento 2 performance checklist — baseline, backend, config, search, and frontend — with the commands to verify each item. Fix the ceiling first.
Hyvä swaps Luma's RequireJS and Knockout frontend for Tailwind and Alpine. The speed gains are real — so is the license, the extension audit, and the fact that this is a rebuild, not a reskin.
Magento is excellent for some businesses and expensive overkill for others. An honest fit test — what justifies the cost, what doesn't, and which platform to look at instead.
Magento 2.4.6 reaches end of support on August 11, 2026 — but the deadline means very different things for Adobe Commerce and Magento Open Source. What to do with the time left.
Adobe's July 2026 bulletin listed Magento 2.4.9 among the affected versions. Why the newest release line needs the most patch discipline, not the least.
Moving from a headless Medusa build to Magento or Adobe Commerce is usually about ownership, not technology. The honest reasons, the data work, and what you give up.
Most reasons for leaving Magento — it's slow, it's insecure, upgrades hurt — describe a maintenance problem, not a platform problem. What staying well actually looks like.
Magento 2.4.8 is supported to 2028, which makes it easy to defer patching. Adobe's cadence changed in 2026 — here's the patch process that keeps up with it.
Magento 2.4.7 is still supported until 2027 — but Adobe's July 2026 bulletin lists 2.4.7-p10 and earlier as vulnerable. Why patch level matters more than version number.
Medusa gives you commerce primitives in TypeScript, not a store in a box. What that trade actually costs, what your team needs to look like, and when it pays off.
There's no official Shopware to Magento migration path, so this one is custom ETL from day one. When the move is justified, and how to run it without losing your catalog structure.
Shopware's Migration Assistant moves your data. It doesn't move your store. A realistic guide to a Magento to Shopware 6 replatform, including the SEO work that decides whether it succeeds.
Moving from Mage-OS to Magento Open Source is a Composer change. Moving to Adobe Commerce is a purchase and a project. What actually drives the decision either way.
Moving from Magento Open Source to Mage-OS is mostly a Composer repository change. Moving from Adobe Commerce is a real migration. Here's the difference and how to plan each.
Why Magento 2 checkout is slow — Knockout boot time, shipping rate calls, quote table bloat, and payment scripts — and what to do about each.
How to make Magento 2 PDPs fast — gallery LCP, configurable product JSON, swatches, private content, and the third-party scripts eating your INP score.
Magento 2 PLP optimization — layered navigation queries, product collection bloat, image grids, and the cache misses that make category pages your slowest templates.
A site-wide Magento 2 performance guide for 2026 — TTFB, full-page cache, Redis, OpenSearch, PHP 8.4, and the outdated advice that's still slowing stores down.
A practical guide to upgrading Magento 2.4.6 to 2.4.9 — the two-step path, infrastructure prerequisites, the three framework changes that break extensions, and how to audit your codebase before you start.
A decision framework for stores on an unsupported Magento version. When 2.4.8 is the right target, when to go straight to 2.4.9, and the timing detail that changes the answer.
Working through one of these?
Upgrades, performance work, and emergency support for Magento, Adobe Commerce, Shopware, and custom Laravel builds.