← Back to all sparks
P

Pimcore

MKT AUTO
Velocity5.0

Open-source data and experience management platform (PIM, MDM, DAM, CMS)

Pimcore 2026.2 continues weekly security and bugfix patches across its DXP platform.

cmsdxpenterprise-cmssecurity-patchesself-hosted
Current state
Pimcore is shipping weekly maintenance releases on its 2026.2 branch with a mix of security hardening, bug fixes, and edge-case corrections. Recent releases address ImageGallery hotspot deserialization (security), asset folder move reliability on object-storage backends, workflow rollback correctness, and race conditions in housekeeping jobs. A parallel 12.3.x branch handles legacy major version fixes.
Where it's heading
The volume and nature of fixes suggests the platform is in a stabilization phase following a major release cycle. Security patches appearing in consecutive releases (Custom Report field allowlist, ImageGallery unserialize, context route matching) indicate the team is actively hardening a large attack surface. No new product direction is visible in recent entries.
Prediction
Maintenance releases will continue at weekly cadence; watch for a 2026.3 or next major announcement if the team signals a new Studio UI cycle or headless/composable architecture push.

Recent moves

  1. 7h ago
  2. 7d ago

    2026.2.12

    2026.2.12 patches an asset folder move bug that stranded files on object-storage backends, fixes areabrick name translation in editmode, and closes a context-matching security issue. Standard maintenance — no feature additions.

    View source ↗
  3. 14d ago

    2026.2.11

    2026.2.11 fixes undefined array key errors in workflow note submission, normalizes empty language permission strings, and improves thumbnail error logging. All internal correctness fixes.

    View source ↗
  4. 21d ago

    2026.2.10

    2026.2.10 fixes Imagick colorspace preservation in compositing, prevents circular parent/child reference in data objects, and allows symlinked class definition files. Edge-case correctness patches.

    View source ↗
  5. 28d ago

    2026.2.9

    2026.2.9 fixes workflow marking rollback when post-transition saves fail and addresses a housekeeping race condition — important reliability fixes for workflow-heavy deployments, but invisible otherwise.

    View source ↗
  6. 1mo ago

    2026.2.8

    2026.2.8 patches a security vulnerability in ImageGallery hotspot deserialization (GHSA-8h86-9g29-q362) and fixes user session refresh errors. Security patch release — mandatory to apply.

    View source ↗