Magento 2 E2E Testing: A Playwright Suite You Configure, Not Fork
An open source Playwright end to end testing suite for Magento 2.4.7 to 2.4.9 and Mage-OS, with Luma and Hyvä supported out of the box, adapted to a store through five JSON config files instead of a per-client fork.
m2-meta-security-patches Swaps vaimo for a New Patch Installer
m2-meta-security-patches now applies patches through samjuk/magento-patch-installer instead of vaimo/composer-patches. Two config lines, one composer update, and it coexists with vaimo or cweagans.
StyleSmuggler and September's Isolated Patch Land in m2-meta-security-patches
Adobe shipped two Magento 2 security patches a day apart — the StyleSmuggler emergency fix (VULN-39341 / APSB26-146) and September's routine isolated patch (2026-09-001 / APSB26-138). Both are now wired into m2-meta-security-patches.
StyleSmuggler (CVE-2026-75650): Emergency Magento 2 Mitigation & Recovery
How to detect, contain and recover from StyleSmuggler (CVE-2026-75650 / VULN-39341, APSB26-146) — the actively exploited Magento and Adobe Commerce zero-day RCE.
APSB26-92: Adobe Commerce's August 2026 Isolated Patch
APSB26-92 is Adobe Commerce's August 2026 isolated security patch, stacking on top of July's. Here's what's in it, WAF rules for the account takeover, the July packaging problems now fixed properly, and a vaimo/composer-patches bug that silently reverts your patches.
APSB26-73: How to Apply Adobe Commerce's July 2026 Isolated Security Patch
APSB26-73 is Adobe Commerce's July 2026 isolated security patch, covering 2.4.6-p15, 2.4.7-p10, 2.4.8-p5 and 2.4.9. Here's what's in it, the non-cumulative gotcha that trips people up, and the fastest way to apply it.