September 2026 release
7 min
Release: 5.2.2609.386+sts
The following is a list of the release's bug fixes and enhancements. Some bug fixes may address existing support articles. A comprehensive list is at the bottom of this page.
The September 2026 release is now available for developers to download and work with locally or to request deployments.
Release highlights
- Accessible Admin Console reordering – Accelerate daily catalog workflows and align your administration tools with modern accessibility standards without relying on mouse navigation. Merchandising and operations teams can now reorder Admin Console lists entirely with a keyboard, supported by translated screen-reader announcements that confirm every move. Keyboard navigation and screen-reader support cover product images, list columns, export columns, promotion rule groups, multi-value settings, user roles, and product relationships.
- Unified multilingual catalog URLs – Strengthen search engine rankings and simplify buyer navigation across multilingual storefronts with a single, consolidated URL structure. By extending the homepage's language URL segment consistently across catalog, product, brand, and search pages, and removing the duplicate segment previously seen on brand URLs, search engines can index pages cleanly under one URL structure per language. Turn on the Use Home Page Url Segment Across Catalog Pages setting (Catalog → URL Mapping) to apply this structure across catalog, product, brand, and search pages. This setting is enabled automatically for new websites, while existing websites keep their current structure to protect established indexing. See Translate URLsTranslate URLs.
- Self-service .well-known file hosting – Launch third-party tools, mobile apps, and domain verifications immediately by removing developer sprint dependencies and production release cycles. Implementers can upload app-site association, domain verification, and mobile link verification files directly to/userfiles/_system/.well-known, and Spire serves them at /.well-known/<filename> allowing critical integrations to go live without waiting for custom code deployments or scheduled releases. See Media libraryMedia library.
- Content Security Policy (CSP) controls – Harden browser security without risking broken checkout flows or unexpected storefront downtime. The Admin Console now has its own configurable Content-Security-Policy and both the storefront and Admin Console now have dedicated report-only modes available (Content-Security-Policy-Report-Only and Admin Content-Security-Policy-Report-Only) so security teams can safely observe and fine-tune policies against live traffic, flagging blocked scripts and connections in advance, before applying strict enforcement. See Set security headersSet security headers.
- Search v3 Reliability Improvements – Protect the shopper search experience during outages and high-demand periods. If Commerce Search v3 ever experiences downtime, storefront search now automatically fails over to Elasticsearch, so shoppers can keep finding and buying products without requiring emergency manual intervention from your team (see Commerce Search v3Commerce Search v3 for more details). Optimizely has also improved how the Search Service manages its internal resources, keeping memory usage and performance stable during sustained, high-volume shopping periods. This reduces the risk of slowdowns as demand grows.
- Spreedly Checkout SDK migration – Stay ahead of Spreedly's iFrame retirement with a seamless, zero-touch migration. Payment Service card capture has transitioned from Spreedly's legacy iFrame to the Spreedly Web Checkout SDK. Configured Commerce instances using the Payment Service must upgrade to version 5.2.2609+ by December 31, 2026, ahead of Spreedly's retirement of the legacy iFrame in Q1 2027. All existing merchant and gateway configurations, including 3DS/SCA setup, carry over automatically, no manual reconfiguration required. See Payment processPayment process.
Important Configured Commerce instances that use the Payment Service must upgrade to version 5.2.2609+ by December 31, 2026 (end of Q4 2026). If you do not upgrade by this date, card capture and payment processing may stop working.
See [NOTICE] Payment Service customers must upgrade to 5.2.2609 for more details.
Breaking changes
Low risk
- Added several new methods to the Insite.Core.Plugins.Catalog.IPathBuilderUtilities interface:
- GetHomePageUrlSegment(ILanguage)
- CombineWithHomePageUrlSegment(string, ILanguage)
- RemoveHomePageUrlSegment(string, ILanguage)
- RemoveHomePageUrlSegmentForAnyLanguage(string)
- RemoveLeadingContext(string)
Enhancements
- Added the primary languages of the top 30 GDP economies (for example, es-MX) to the Language Tag system list, so more sites can configure locales without a custom tag.
- Reduced Search Service log verbosity to the Warning level in Sandbox, Demo, and Production environments (Development and QA stay verbose), which makes real warnings and errors easier to spot and lowers log storage costs.
- Restricted editing of a website's CMS Type to the ISC_System role, so the CMS type on hosted sites is no longer changed by accident.
- Removed the deprecated SSO Clients code from .NET Core so there is no confusion about it being supported.
- Added server-side use of Cloudflare visitor-location headers to determine user latitude and longitude.
- Added automatic generation of missing page URLs when a website language is created or updated in the Admin Console, and added default-language fallback to the page-links endpoint, so activating a language before its URLs exist no longer takes the storefront down.
- Improved application startup time on installations without a Classic CMS website by loading only the themes in use instead of every available theme.
- Added an Admin Console message and a visual indicator for custom properties that have no stored value. This lets you tell an unset default from a value saved to the database.
- Improved security.
Bug fixes
- Fixed the issue where a serving control in the Commerce Search micro-frontend (MFE) could not be saved after page categories were entered under Browse Categories and the trigger was switched to Search.
- Fixed the issue where the Admin Console translation dialog highlighted Edit Translation as the current step while the user was still on Choose Languages, and updated the dialog's progress bar to the current Optimizely branding.
- Fixed the issue where a product import reported Incorrect date time for field Modified On even for imports that used Ignore modified date.
- Fixed the issue where the storefront stayed on a non-default language whose home page URL segment was blank, and failed to load entirely once that language was turned off. The home page now falls back to the default language's URL.
- Fixed the issue where a wishlist PDF that timed out during generation was still emailed to the shopper as an error file; the failed PDF is no longer sent.
- Fixed the issue where a ShipTo address remained on a website user's default customer after its BillTo customer was unassigned in the Admin Console.
- Fixed the issue where One Page Checkout displayed no error when a shopper entered an invalid eCheck account or routing number, unlike standard checkout.
- *Fixed the issue where integration jobs stayed at InProgress and never finished. This affected .NET Framework 4.8 sites that use Amazon S3 file storage.
- *Fixed the issue where integration job debug logs were missing when the log source was set to Elasticsearch. These logs now appear regardless of the Log Debug Messages setting.
- *Fixed the issue where brand and product names ending in the letter y disappeared from search results and autocomplete. This happened when the name also contained a ®, ™, or © symbol.
- *Fixed the issue where a product recommendations widget kept displaying the previous page's recommendations when the current page returned none, clearing only after a hard refresh.
- *Fixed the issue where the storefront continued to show the OpenID Connect sign-in option after it was disabled. The storefront and Admin Console now honor Allow Sign in With OpenId Connect and Allow Sign in With Windows Account at request time.
- *Fixed the issue where creating a storefront account on .NET Core sites failed when the user name contained a space, displaying Microsoft.AspNetCore.Identity.IdentityError instead of a readable message. Validation messages now show a readable description.
- *Fixed the issue where an integration job never finished on sites that use Azure Storage.
- *Fixed the issue where products from a Product Information Management (PIM) feed did not appear in Retail Search results. Indexing rejected products whose Basic Sale Start Date and Basic Sale End Date held placeholder values.
- *Fixed the issue where Classic CMS storefronts showed the browser's default 404 page instead of the site's error page. This affected .NET Core sites when a visitor requested a URL that does not exist.
- *Fixed the issue where a Spire storefront's internal content API calls returned 401 Unauthorized after a user signed in. Pages loaded normally for anonymous visitors but broke for authenticated users.
Note *These bug fixes were included in hotfixes and are available for 5.2.2608 STS.