Every report prints the vault version that produced it. This is what those versions mean —
new advisories, corrected remediation, lifecycle updates. Without it the version stamp is a
number nobody can look up, which is worse than no stamp at all.
One short email when the dataset changes, which is a few times a month at most. We send a
confirmation link first and nothing else until you click it.
2026.09.6
current
The extension dataset doubles, and learns to say that an advisory has no fix.
Added Fastly CDN for Magento 2 (CVE-2017-13761, GHSA-vpq9-c67q-23fq, fixed 1.2.26) — the entry 2026.09.2 deliberately left out. That exclusion was wrong: the module IS public, at github.com/fastly/fastly-magento2, which is not the name the advisory gives for the Packagist package (fastly/magento2). The module name reads Fastly_Cdn, and the module ships view/frontend/web/js, so a storefront can carry the name.
Added Mageplaza Blog for Magento 2 (CVE-2026-79322, CVSS 8.6): the related-products block concatenates the post id from the request straight into a SQL WHERE clause. Unauthenticated, reachable from any blog post, and NOT FIXED — the line is identical in 4.3.2, in 4.3.3 and on master as of today, which was checked by reading Block/Post/RelatedProduct.php at all three.
Added Cart2Quote Quotation for Magento 2 (GHSA-pgj4-g5j4-cmfx): unserialize on GET data in the custom-option download controller, which is remote code execution on any store with a file option on a product. Two rows, because 4.4.6 closed the 4.x line and 5.0.0 reopened it — a store on 4.5.0 is clear and a store on 5.2.0 is not. The module name was read from the package's own published dist at a pinned commit.
The dataset can now express an advisory WITH NO FIX, and the report changes shape when it meets one: no upgrade command, an explicit 'no fixed release' in the title and the evidence, and steps that are actually available — confirm it is installed, apply the interim control, decide whether the module stays. A `composer require` against a version that was never published fails at the command line, and a merchant who hits that concludes the finding was wrong and stops reading.
The bar for an entry gained a fourth clause: the module must ship a STOREFRONT asset carrying its name. Two otherwise-qualifying advisories are excluded under it and recorded in the dataset with the reason — Magefan Blog GraphQL (CVE-2026-79323, fixed in 2.2.2) ships no view directory at all, and Mageplaza GDPR (CVE-2026-79324, unauthenticated address deletion, still unfixed) ships only a LESS source that compiles into the theme bundle. An entry this probe can never match grows the dataset without growing what a scan can say.
Recorded the coverage arithmetic rather than leaving the dataset's size unexplained: the GitHub Advisory Database holds exactly five advisories against a package Packagist types as a Magento 2 module or theme, checked against all 11,489 of them, and NVD's 291 Magento CVEs leave 52 non-core, most of which are OpenMage LTS and MAGMI — Magento 1 platform code rather than modules. The commercial extensions among the rest (Wyomind, Amasty, Mirasvit, MageMe) are named as an explicit gap: their module names are not citable because the code is not public.
vault-verify now fails an entry that has no fixed version and no upper bound, one that has no fixed version and no mitigation, and one that claims both a fixed and a last-affected version.
Copy corrections across the datasets, from the new engine copy gate: the CISA catalogue is spelled the way the rest of the product spells it, and five substituted-clause constructions are gone from the repair sheets in cve.json, the lifecycle note and the two provenance notes. The gate flagged this very line on its first run, because it cannot tell quoting the banned shape from using it. No intelligence changed, which is why this is a line here and not a version of its own — a vault bump emails every subscriber, and a spelling fix is not news.
2026.09.5
Magento 1 stores are now identified to an exact release by the checksum of a file they serve.
Vendored the gwillem/magento-version-identification checksum map verbatim: 144 md5 sums across 12 paths, covering 58 Magento 1 releases from CE 1.0 to EE 1.14.4.4. The sha256 of the file as retrieved is recorded alongside it, so a future re-fetch can be diffed rather than trusted.
Magento 1 serves its admin JavaScript and skin CSS byte-for-byte as the release shipped them, so hashing one names the release outright — the upstream project measured 91.7% accuracy across 220,000 installations. The map is ordered most-discriminating first (boxes.css tells 36 releases apart), so a store is usually identified on the first request, and the probe gives up after four.
Still INFERRED, deliberately. An exact checksum match proves one file is what a release shipped; it does not prove the whole install is, and a store patched in place will match on a file the patch did not touch. The finding says so.
Magento 2 stores are never asked for these paths: the technique is Magento 1 only, and all twelve would 404. Magento 2 uses the release signatures added in 2026.09.4 instead.
vault-verify now fails a checksum map with an unrooted path, an entry that is not an md5, or a checksum mapped to no release.
2026.09.4
Release fingerprinting from the libraries Magento bundles, and the August authorisation flaw now that CISA has listed it.
Added CVE-2026-71362 (Adobe APSB26-92): an incorrect-authorisation flaw that lets an unauthenticated attacker escalate privileges, CVSS 9.1, affecting Adobe Commerce up to 2.4.4, Magento Open Source up to 2.4.6 and Adobe Commerce B2B up to 1.3.3. Adobe published the fix on 11 August 2026, exploitation began within days, and CISA added it to the Known Exploited Vulnerabilities catalogue on 24 September. The repair sheet takes the August release or the isolated patch, and then goes looking at admin accounts and integration tokens — this one escalates privileges rather than running code, so that is where the evidence would be.
That CVE was found by the coverage gate rather than by reading the news: the nightly sync pulled the new KEV flag, and vault-verify and the engine suite went red the same morning naming the CVE. The mechanism added after StyleSmuggler worked on its first real test.
Added release signatures: the combination of jQuery, RequireJS and Knockout versions a storefront serves, mapped to the Magento releases that ship exactly that combination. Read from nine magento/magento2 release tags rather than derived, with the tags recorded per row. It pins 2.4.3, 2.4.7 and the 2.4.8/2.4.9 pair exactly and narrows the rest to a three-release window — the difference between telling a merchant they are on "2.4" and telling them they are on 2.4.7.
This is the Magento 2 answer to the gwillem md5 technique, which does not transfer. That dataset is real and complete but covers Magento 1 only (144 hashes, 58 versions, CE 1.0 to EE 1.14.4.4), because Magento 2 compiles static content per store and per deployment mode: the BYTES of a served file differ between two installs of the same release. The version each library declares about itself does not.
vault-verify now fails a release signature that cites no tag, names no libraries, or claims an exact release from more than one tag.
2026.09.3
StyleSmuggler (CVE-2026-75650), and a gate so the next one cannot sit in the index unreported.
Added CVE-2026-75650 (StyleSmuggler), Adobe APSB26-146: an unauthenticated remote code execution flaw reached through the email template engine, CVSS 10.0, affecting Adobe Commerce 2.4.4–2.4.9, Adobe Commerce B2B 1.3.3–1.5.3 and Magento Open Source 2.4.6–2.4.9 including the August 2026 releases. On the CISA KEV catalogue and exploited in the wild since at least 4 September 2026. The repair sheet applies Adobe’s VULN-39341 hotfix, then goes looking for what a patch does not remove — exploitation predates the patch, so a clean patch status says nothing about the days before it.
It had been in the synced advisory index since 7 September and in no report at all, because a finding comes from a hand-written repair sheet in cve.json and the index is only reference data. The sync was green the whole time. Sansec published it; we did not report it.
vault-verify now FAILS when an advisory on the CISA KEV catalogue has no entry in cve.json, and vault:check-freshness raises the same alarm to the maintainer’s inbox on its daily run. Freshness and coverage are two different failures and only the first was being watched.
The vault page now states coverage as well as currency: how many actively-exploited advisories are tracked, and how many of those can actually be reported on.
2026.09.2
Supply chain: JavaScript library advisories, a third-party extension dataset, the PCI 6.4.3 script inventory, security.txt, Mage-OS and Hyvä-specific CSP guidance.
Added a JavaScript library dataset covering the six libraries Magento bundles (jQuery, jQuery UI, RequireJS, Knockout, Underscore, Moment), with the published advisories against each transcribed from OSV. The version is read from the served file’s own banner, and a file with no readable banner produces nothing rather than a guess.
Added a vulnerable-extension dataset keyed on the Vendor_Module string a static asset path exposes. An entry ships only when the advisory, the affected range AND the module name can each be cited; the module name is read from the extension’s own registration.php in its public repository.
Left fastly/magento2 (CVE-2017-13761) out of that dataset deliberately: the advisory is real, but the repository it names is no longer public and the module name could not be confirmed. The dataset is keyed on that string, so guessing it would mis-flag stores.
Added the third-party script inventory: every external script origin on the homepage and the cart, reported as the PCI DSS 6.4.3 starting point rather than as a weakness.
Added an extension inventory: the third-party modules a storefront publishes in its asset paths, with the point that the list is public whether or not you keep one.
Added a /.well-known/security.txt check, including the mandatory Expires field — an expired file is one RFC 9116 says a finder may ignore, while still looking answered.
Mage-OS is now recognised. Its fork of the version controller serves the endpoint under the distribution name (Mage-OS/2.4), so matching only "Magento/" made a Mage-OS store’s version endpoint invisible; the markup cannot tell them apart because Mage-OS keeps Magento’s module names.
Hyvä storefronts now get CSP guidance written for Hyvä. A Luma-shaped policy breaks an Alpine theme, and a merchant who breaks their storefront rolls the whole policy back.
2026.09.1
Per-release Adobe lifecycle dates, corrected remediation for every tracked CVE, owner-facing copy for all 49 checks, and EPSS enrichment.
Replaced the branch-level end-of-life matrix with per-minor-release lifecycle dates (2.4.0-2.4.9), transcribed from Adobe's released-versions table with its source URL and retrieval date. Rows Adobe states no end date for are marked unverified and print no date.
Corrected the SessionReaper, CosmicSting and TrojanOrder remediation: patches now apply through the Quality Patches Tool or a patch file, with setup:upgrade shown as the rebuild step it is.
Replaced admin:user:unlock in the session-invalidation step with flushing the session store, forcing admin password resets, revoking integration tokens and rotating the encryption key.
Removed the last admin:user:unlock, from the malware-signature compromise playbook. It unlocks an admin account rather than auditing one, which in a compromise is the wrong direction; the step now names the three places persistence survives a code restore and gives the queries that list them.
Corrected the GraphQL introspection fix to the graphql/disable_introspection setting in app/etc/env.php, verified against Adobe's documentation. Production mode does not disable introspection.
HSTS guidance now starts at max-age alone; includeSubDomains and preload are a separate, warned step.
DMARC guidance starts at p=quarantine for a domain already publishing p=none.
Added owner-facing copy for all 49 named checks: the consequence, the business impact, an effort estimate and a fix-by bucket.
Added a Subresource Integrity check for third-party scripts loading without an integrity hash.
Advisory index now records the CISA KEV date separately from publication, and carries FIRST EPSS exploitation-probability scores.
2026.08.2
Static-asset version fingerprinting and the synced NVD + CISA KEV advisory index.
Added static-asset discriminators that narrow the inferred Magento version without asking the server.
Advisory index synced from NVD and the CISA Known Exploited Vulnerabilities catalogue.