Adobe Commerce: the latest news you need to know

On PaaS, the observer.sales_quote_item_set_product webhook payload now includes shopper-entered custom option values. Our Adobe Commerce experts help businesses implement seamless upgrades that align with their growth objectives. Keeping your store updated with the latest Adobe Commerce release helps maintain a secure, reliable, and future-ready ecommerce experience. For countries like Italy and Spain, the Pay Later option and banners have been added to the payment gateway Braintree. There is a significant improvement in reCAPTCHA; it will appear every time when an unexpected error occurs during payment processing.
These updates make storefront and PWA integrations more efficient and responsive. Verify your database version and plan a migration from Elasticsearch to OpenSearch if required. This release adds compatibility with PHP 8.4 for Adobe Commerce, including bundled extensions and Adobe-owned services.
It encompasses various aspects of the product, including features, integrations, cloud services, and more. The Adobe Commerce roadmap outlines the future development and innovation plans for Adobe Commerce. I look after our SEO clients and lead the team making sure their websites aren’t just If you’re a well-established eCommerce business, you might be on your second or third platform or still running a first-generation system that’s been adapted and

What the 2.4.8 Security Patches Actually Fixed

Here’s what changed, what was removed, and what deserves coordination across your engineering, infrastructure, and https://best-adobe-commerce-b2b-agencies.com/ business teams. If your store is still running 2.4.4, 2.4.5, 2.4.6, or even 2.4.7 and you have not started planning, the window for a comfortable Magento upgrade is getting narrow. It is now four security patches deep, with 2.4.8-p4 released in March 2026. Applying security patches promptly is essential to maintaining a secure and reliable storefront.

  • Whether you’re focused on site speed, better payment UX, or enhanced security, this release checks all the boxes.
  • Adobe releases regular patches for the Magento 2.4.8 release to keep the platform secure and running at its best.
  • Our team specializes in Adobe Commerce upgrades, helping merchants migrate smoothly without disrupting operations.
  • Staying ahead in the rapidly evolving digital landscape requires running the most secure, scalable, and feature-rich version of your e-commerce platform.
  • It is also worth noting that the p1 patch fixed a side-effect of the earlier APSB25-08 security update , applying that patch had unintentionally slowed down bulk asynchronous API operations.

Start building event-driven integrations and high-performance storefronts for Adobe Commerce using modern development tools. One-time password (OTP) settings – This update is required to resolve an error that was introduced by a backward-incompatible change in 2.4.7. New CLI commands are now available for changing keys and re-encrypting certain system configuration, payment, and custom field data. While direct upgrades are possible, moving from an older 2.3.x environment to 2.4.7 requires substantial planning.
New functionality is available sooner and users benefit from simplified data sharing and reduced costs for integrations and customisations. Adobe product upgrades and patches provide simple and predictable ways to make improvements and add new features. This includes creating faster ecommerce sites and improving tools to deliver personalised experiences at scale.
You can securely update and re-encrypt sensitive data, such as payment information and system settings, using straightforward command-line steps. Here are the key updates of the release that you must consider to run your operations efficiently. Whether you’re focused on site speed, better payment UX, or enhanced security, this release checks all the boxes. If you’re unsure how to time your upgrade, what App Builder means for your dev team, or when to start planning your cloud migration, you’re not alone. While Magento 2.x isn’t “dead,” its future is evolving towards this new model.
Applying the latest PCI compliance Magento patch ensures your store meets industry standards and protects customer payment data. In the meantime, we recommend keeping an eye out for any security patches or hotfixes to keep your webstore as secure as possible. Given the recent security changes, we strongly urge developers to review REST API constructor parameter validation and update their extensions for compliance. The Adobe Commerce REST API is a tool that can be leveraged by developers to create apps and integrations with external tools such as CRMs or content management systems.

Merchants running Adobe Commerce B2B will recognise this one. For team members who did not own a hardware key, this was an outright blocker. Here are the changes with the most direct impact on store operations. Stores relying on bulk product imports, order processing pipelines, or integrations that use async endpoints would have seen degraded performance until p1 was installed. It is also worth noting that the p1 patch fixed a side-effect of the earlier APSB25-08 security update , applying that patch had unintentionally slowed down bulk asynchronous API operations. Any store still running an unpatched version of 2.4.8 remains exposed to this attack right now.
This update enhances cache performance and maintainability, and ensures long-term compatibility with PHP 8.x and future platform updates. Adobe Commerce 2.4.9 primarily focuses on the product’s future direction rather than adding new features. VDCstore exists to take that operational burden off store owners and their teams. At VDCstore, we run patch deployments as structured engineering operations. The Catalog Price Rules grid in the admin now includes the same bulk actions that Cart Price Rules have offered for some time , activate, deactivate, and delete multiple rules at once.

37 yr old Programmer Analyst II Isa Govan, hailing from Vancouver enjoys watching movies like “Edward, My Son” and Jogging. Took a trip to Kathmandu Valley and drives a Ferrari 212 Export Berlinetta.

Beyond the Checkbox: Why Adobe Commerce Security Scanning Is the Invisible Backbone of HighConverting Stores

The partner monitors Adobe announcements, applies patches to staging, runs tests, deploys to production on a documented schedule, and handles hotfixes within SLA. You still need to test patches in your integration environment, promote to staging, validate, then promote to production. How do we keep our staging environment in sync with production? These five issues account for roughly 80 percent of the production breakage we see when teams skip the staging step or run a non-mirrored staging environment. Both are catchable in staging before they hit production.
For Adobe Commerce stores with B2B enabled, this includes the negotiable quote and shared catalog configuration paths that generic scanners do not know to check. A daily read of the config table, hashed at the config-path level and diffed against the prior snapshot, catches silent configuration changes. An attacker who creates a persistence account after gaining initial access has at most a one-day operational window before detection. If a third-party extension vendor ships a version bump on Tuesday and a CVE lands in the Sansec advisory feed on Thursday, your next scheduled scan might not run until next month. The scanner checks your current module list against a static CVE feed on the day you run it. The only way to catch admin account drift is a credentialed check against the admin user and role tables, run often enough that a one-day-old account is flagged before it is used.
Security isn’t just about checking a few boxes – it’s a multi-layered approach that covers all aspects of your site from backend access control to customer data protection. This guide provides actionable steps to secure your site, from regular maintenance to advanced configurations with tools like Cloudflare and Sucuri. Protecting your Adobe Commerce / Magento store is essential in today’s digital landscape. The app/etc directory is mounted from a separate filesystem, so the flag makes eComscan stop before it reaches env.php, silently skipping the module and database checks.

  • No website is completely infallable, but by doing your best, using all best practices and modern tools, you will be much better off when facing off against those pesky attackers.
  • One of the essential for any online business is to ensure their store is safe from a hacker.
  • Our service lets you convert your text or document files to clean HTML instantly.
  • When the scan is a natural by‑product of pushing code, delivering audit‑ready documentation becomes a frictionless export, not an all‑hands scramble.
  • A technical audit is more than a checklist — it’s your first step toward a reliable, secure, high-performing Adobe Commerce implementation.
  • It helps sellers using Magento Commerce and Magento Open Source to increase the security of their websites.

We also construct a backup plan to minimise store downtime that helps to boat business continuity in the upgrade process. If none of the above helps, submit a support ticket and provide the store URL and error message from the report. The statistics collection script is run once a day, then the Security Scan tool has to pick up the new data later. Having a backup and disaster recovery plan is essential to get back up and running in case of an emergency.
A 2020 study by IBM reveals that the average cost of a data breach is $ 3.86 million, while the average time spent identifying and containing a breach is 280 days. This slogan has entered our culture so much that today hardly anyone remembers the occasion on which it was created. While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful https://best-adobe-commerce-support-agencies.com/ deserialization sinks that attackers can exploit. Many of the AI tools we interact with take the form of text boxes. As AI reshapes product design, it could give designers greater autonomy or expose the gaps that autonomy makes harder to hide. New EU guidelines, why AI sparkles aren’t enough, when AI labels are required, and what the rules mean for AI-powered features and products.

What continuous scanning catches on an Adobe Commerce store

Staying ahead of these patches is the best way to maintain technical data sovereignty and ensure your store remains a safe environment for your customers. However, it tends to miss some crucial points, like malware in the file system and database. However, don’t miss other available opportunities to secure your store — every extra layer of protection counts. If you choose to set a weekly test using this security scanner, specify the day of the week, time zone, and the exact time of the scan.

Nasdaq Global Indexes offers a comprehensive suite of index solutions, led by the flagship Nasdaq-100, powering benchmarking, product innovation, and global investment strategies. Nasdaq Compliance Questionnaires streamlines board compliance workflows with automated questionnaire collection and management. Nasdaq Boardvantage provides secure board management software for meeting preparation, collaboration, and governance documentation. Nasdaq Board Evaluations delivers structured assessment tools to measure board effectiveness, identify gaps, and strengthen governance. Nasdaq IR Insight provides analytics, ownership data, and engagement tools for investor relations professionals.
Regular monitoring, combined with timely fixes and proper tools, is key to maintaining a secure Magento environment. The tool’s ease-of-use, combined with the amount of protection it offers to your storefront, makes it an indispensable eCommerce security solution. You can access the Magento Security Scan Tool right from your Magento Marketplace Account, so it’s incredibly easy to enable and use. Explore Magento 2 Order Delivery Date Extension, a practical solution to let customers choose their preferred delivery date and streamline order handling. Still, it’s nowhere near the amount of hassle you’ll have to deal with if your site’s security is compromised. Using a service like Magento Security Scan Tool will increase your storefront’s security and prevent costly data breaches that can cost you and your customers a lot of time and money.

Assistant Manager Leeland Croote, hailing from Picton enjoys watching movies like Catch .44 and 3D printing. Took a trip to Yin Xu and drives a Ferrari 330 TRI/LM Spider.

Company Management Adobe Commerce

This flexible model allows you to get full review coverage on every PR without purchasing a full Copilot seat for non-development contributors who may not need Copilot. Usage from non-licensed users is billed directly to your organization as GitHub AI Credits. Organizations can now enable Copilot code review on all pull requests on github.com—including pull requests from users who are not assigned a Copilot license. GitHub Copilot Free users are limited to 2000 completions and 50 chat requests (including Copilot Edits). GitHub Copilot Max is built for heavy Copilot usage, including sustained agent-driven workflows, and includes $100/month in GitHub AI Credits.

Successful B2B marketers combine attribution, MMM, and experimentation instead. No attribution model can answer every business question. Time is serving ads directly to AI crawlers, a strategy that could reshape how brands influence AI-generated answers. Here’s what early campaigns reveal about CPCs, targeting, measurement, and performance.

A longer agent session on a frontier model across many files costs more. A quick question to a lightweight model costs a fraction of a credit. How many credits an interaction uses depends on the model you choose and the complexity of the https://best-adobe-commerce-implementation-partners.com/ task.

GitHub Copilot Enterprise can index an organization’s codebase for a deeper understanding of the customer’s knowledge for more tailored suggestions and will offer customers access to fine-tuned custom, private models for code completion. “The Eight Pillars of User Research” is a comprehensive model with roles, tools and processes to deliver and scale UX research impact. Pro is tailored to multi-property operators and investors, providing next-level support, expertise, and tools to help you operate at scale, improve your performance, and grow your business. Review the tools that customers can use to locate products on the storefront, and configure the search experience according to your product catalog. Overview of using the catalog management features to reflect how you want customers to find products in your store.

This allows us to build more intelligent, context-aware coding assistance for a more diverse set of coding tasks based on real-world development patterns. It has been trained on natural language text and source code from publicly available sources, including code in public repositories on GitHub. GitHub Copilot is powered by generative AI models developed by GitHub, OpenAI, and Microsoft. GitHub Copilot Business primarily features GitHub Copilot in the coding environment – that is the IDE, CLI and GitHub Mobile. The primary differences between the organization offerings and the individual offering are license management, policy management, and IP indemnity.

Documentation to support a collection of merchandising services that help merchants integrate key components of their business with their store. Use the Catalog menu to access multiple features for managing catalogs, categories, and products for your store. It provides detailed information about product catalog features, including the building the navigation structures for a catalog.