June 2023: patching as a rhythm, not a project

APSB23-35 brought 2.4.6-p1, 2.4.5-p3 and 2.4.4-p4, fixing a critical Stored XSS (CVE-2023-29297) and adding Varnish 7.3 and RabbitMQ 3.11 support.

June 2023: patching as a rhythm, not a project

June 2023 made the same point the previous few months had: security and stability come from rhythm, not heroics. Adobe issued patches across supported lines — 2.4.6-p1, 2.4.5-p3 and 2.4.4-p4 — as part of APSB23-35. The standout was a critical Stored XSS (CVE-2023-29297), alongside other fixes.

Adobe also used the cycle to trickle down platform updates. Official compatibility for Varnish 7.3 and RabbitMQ 3.11 arrived with 2.4.6-p1, which gave cautious teams a way to modernise part of the stack without committing to a major version jump.

2.4.6 as the consolidation target

For most estates, June was the month 2.4.6 became the default target, on the strength of its performance work and PHP 8.2 support. The advice did not change: keep lower environments aligned with production and reduce configuration drift, and you will be quicker when a critical patch lands.

How we recommend you operate

  • Cadence. Schedule a monthly maintenance window and stick to it. When the quarter's p-line lands, the team already knows the drill.

  • Automation. Build a lean smoke pack covering checkout, payments, order placement, admin login and key GraphQL flows. Save the exhaustive suite for after the emergency window has closed.

  • Representative data. Refresh staging data and media so cache behaviour, indexes and search facets reflect what production actually does.

  • KPIs. Track mean time to patch and time to detect regressions. They are also the numbers that win the argument for investing in test automation.

What this means for you

June wasn't flashy, but it was consequential. The merchants who come out ahead are the ones treating upgrades as steady, predictable practice rather than a project someone schedules when there is finally time.