Where Magento 2 patches live now, and how to apply them safely
Adobe has moved Magento patch distribution repeatedly. Here is where security, quality, and hotfix patches actually live now, and a workflow to apply and track
Read articleBlog
Magento 2 and Adobe Commerce operations, commerce migrations to Medusa.js and Vendure, Next.js storefronts, and the hard parts of cutting over without freezing the business.
Adobe has moved Magento patch distribution repeatedly. Here is where security, quality, and hotfix patches actually live now, and a workflow to apply and track
Read articleNext.js 16.3.6 patches GHSA-vcvr-r3jv-pc5j, a remote code execution flaw in next/og ImageResponse. Here's how to find exposure, upgrade, and harden OG routes.
Read articleA huge Action Scheduler backlog means a stalled runner, a failing hook, or a flooding plugin. How to diagnose it, drain it safely, and stop it recurring.
Read articleWhy you shouldn't apply a p10-targeted security fix to 2.4.7-p9, and a repeatable pre-flight, test and rollback process for -p upgrades.
Read articleMagento 2.4.8-p5's di.xml and Adobe's system requirements disagree on MariaDB. How to pick 10.5, 11.4 or 11.8, then upgrade and roll back safely.
Read articleMedusa v2.21.0 enforces a strict allowlist on Store API fields. How to find the storefront queries it silently breaks and fix them without over-exposing data.
Read articleEditing a paid Vendure order re-tests every promotion and ignores freezePromotions; here is how to detect re-priced orders and guard the edit flow.
Read articleMedusa's cancelFulfillment calls its shipped/delivered guard by class name, so subclass overrides never run — how to spot the shape and work around it.
Read articleMedusa 2.20.0 fixes payment providers reachable outside their region and an admin MFA bypass — what changes, how to check your config, and what to test.
Read articleMedusa 2.20.1 makes field filters strip disallowed fields without the RBAC flag. What the gap exposed, how to upgrade from 2.19.x, and how to test it.
Read articleVendure 3.7.3 fixes eleven reported vulnerabilities, four critical, plus channel-scoping and shipping-line changes that alter behaviour after upgrade.
Read articleVendure evaluates cron expressions in the Node process timezone, so nightly jobs fire at the wrong local hour and drift at DST. How to audit and fix it.
Read articleIn Medusa 2.19.0 the admin create-fulfillment flow drops items.variant.metadata, so dropship and print-on-demand providers get line items they cannot map.
Read articleNext.js 16.3.3 fixes two critical advisories — Windows-hosted server RCE and Image Optimization AVIF RCE. Here's who is exposed and how to mitigate.
Read articleMedusa 2.19.0's inventory reservations are not concurrency-safe when called directly — here's where the race is and how to detect and close it.
Read articleVendure 3.7.2 fixes four reported vulnerabilities and tightens channel scoping on update and delete paths — here is what to test before you ship it.
Read articleOrder exports in Medusa 2.18.0 and 2.19.0 fail silently on any order with a shipping method. How to confirm it and what to do until it's fixed.
Read articleWhy Medusa 2.19.0's caching module runs unbounded invalidation on worker_mode: server processes, how to confirm it, and what to change before a migration
Read articleVendure 3.7.0 fixes five advisories, including a critical account takeover never backported to 3.6.x. Who is exposed, and what the upgrade actually costs.
Read articleHow to confirm a SessionReaper/PolyShell compromise on Magento 2.4.x, remove the injected backdoors, restore wiped catalog data, and close the entry point.
Read articleHow Magento 2 and Adobe Commerce shops accumulate extension debt, how to inventory it, and when rescue work is cheaper than a full replatform.
Read articleA practical comparison of Medusa.js and Vendure when you are leaving Magento 1, Magento 2, Adobe Commerce, or WooCommerce - without the hype.
Read articleWhat enterprise Next.js commerce work actually includes when Magento, Medusa.js, or Vendure owns the cart - and when headless CMS fits.
Read article