Posted by Aaron on September 28, 2026
Comments (0)
Here is the complete list of new features, enhancements, security improvements, and bug fixes in BV Commerce 2026 Service Pack 1 (SP1). This list is relative to the previous release, BV Commerce 2026.
Note that this release also includes the previously released critical security vulnerability from July to ensure that every BVC 2026 store receives this update.
Enhancements
- Google Maps address control to link order addresses to Google Maps
Security & Privacy
- Image resizer security update
- File Upload product input security update
- Audit Log page security update
Bug Fixes
- Tracking scripts (e.g. Google Analytics) did not run when the new privacy compliance functionality was disabled
- Privacy compliance pop-up did not always display depending on the configuration settings
- Authenticated users could sometimes alter or delete their most recently placed order from another device or browser
- Credit card form on checkout not visible when credit card was the only payment method enabled
- Authenticated users received a 'shipping address changed' error on the Review step of checkout
- Checkout payment method validation messages were blank
- Users were unable to change their password if they had a username from prior versions of BVC that was not an email address
- SiteWarmUp failed when using Cloudflare (and likely other WAFs)
- BS4 Turbo category templates displayed two sets of product (item) counts when the category paging mode was set to "Bottom"
- Faceted search facet collapsed (hid) when clearing a facet or clearing all facets
- Horizontal scrollbar was visible on all pages in the BS4 Turbo theme
- Logout link on My Account pages in BS4 and BS4 Turbo themes did not have a space between the user's name and the Logout text
Developers
- Added support for async calls and cancellation tokens to BvcHttpClient class