Releases: SamJUK/m2-meta-security-patches
Release list
2026.08.11 (Aug Isolated Patches)
🎉 Introduces the second iteration of Adobe's new Isolated patches ( APSB26-92).
NOTE: These patches ONLY apply to the latest -p releases. If you are out of date, they will skip.
What's Changed
- add: august isolated security patches by @SamJUK in #5
- fix: repoint root files in patches at
magento2-baseto work on fresh installations @SamJUK in #6 - fix: re-add nginx.conf.sample with repointed base @SamJUK in #6
- fix: drop vendor/bin/patch-status to prevent
patches:redofailures @SamJUK in #6
Full Changelog: 2026.07.14-p1...2026.08.11
Isolated Patch Refs
https://helpx.adobe.com/security/products/magento/apsb26-92.html
https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380
2026.07.14-p1
🐛 Fixes broken composer install on fresh CI installs
The official distributed patch files bundled in release 2026.07.14
Attempts to patch nginx.conf.sample before the composer plugin
deploys it from the magento-base package, breaking clean/CI installs.
What's Changed
Full Changelog: 2026.07.14...2026.07.14-p1
2026.07.14 (July Isolated Patches)
⚠️ Known issue: this release breakscomposer installin CI
A patch hunk targetsnginx.conf.samplebefore Magento deploys it (composer plugin).
Existing installs will patch fine; new/CI installs will fail.
Fixed in2026.07.14-p1— upgrade to that instead.
🎉 Introduces the first of Adobe's new Isolated patches ( APSB26-73).
NOTE: These patches ONLY apply to the latest -p releases. If you are out of date, they will skip.
What's Changed
Full Changelog: 2026.03.19...2026.07.14
2026.03.19
Introduce a Emergency patch for the Polyshell vulnerability (APSB25-94) - #2
Patch content is derived from Mark's module https://github.com/markshust/magento-polyshell-patch/
Allowing for a single Patch file for all versions, due to the official commit not applying cleanly to older versions
Full Changelog: 2026.02.01...2026.03.19
2026.02.01
Release 2026.02.01
Initial release
New Patches
- CVE-2024-34102 - CosmicSting vulnerability affecting Magento 2.4.7 and earlier
- CVE-2025-54236 - Session security vulnerability