Maropost experienced a major incident on July 27, 2026 affecting Control Panel, lasting 1h 28m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Jul 27, 2026, 01:48 AM UTC
We are receiving reports of control panels receiving "We will be back online shortly". Our Development Team are investigating now.
- identified Jul 27, 2026, 02:35 AM UTC
We have identified the issue and our Development Team is working to resolve it as soon as possible.
- monitoring Jul 27, 2026, 02:55 AM UTC
Our team has deployed a fix and is closely monitoring the situation to ensure services return to normal.
- resolved Jul 27, 2026, 03:17 AM UTC
The issue has been resolved and services are operating as normal.
- postmortem Jul 27, 2026, 05:18 AM UTC
On 27 July 2026, a subset of merchants experienced an issue accessing their control panels. Affected users were shown a “We will be back online shortly” message after attempting to log in. The incident began at **11:48 AM AEST** and was resolved at **1:17 PM AEST**, for a total duration of **1 hour and 29 minutes**. ## What happened During a production software release, a change affecting a security-related control panel configuration caused authenticated requests to fail for a subset of control panels. The issue only affected control panels where the relevant security feature was enabled. Users could reach the login page, but after authentication they were unable to access the control panel. ## Impact Some merchants were temporarily unable to access their control panels and complete administrative tasks. The disruption was limited to a subset of control panels. Services returned to normal once the affected configuration was disabled. ## Timeline * **11:48 AM AEST** – Reports were received of control panels displaying “We will be back online shortly,” and the Development Team began investigating. * **12:35 PM AEST** – The cause of the issue was identified and remediation work began. * **12:55 PM AEST** – A fix was deployed and the service was placed under monitoring. * **1:17 PM AEST** – The issue was confirmed as resolved and services were operating normally. ## Root cause A change included in the production release caused an incorrect security reporting configuration to be generated for affected control panels. This produced a response header that exceeded the supported size limit, causing authenticated control panel requests to fail. ## Resolution The affected security feature was disabled, immediately restoring access to impacted control panels. A permanent code correction is also being implemented so the feature can operate without generating the invalid configuration. ## Preventive actions To reduce the likelihood of a similar incident, we are: * Adding regression coverage for authenticated control panel access when security-reporting features are enabled. * Expanding staging validation for response-header size and security configuration changes. * Improving release checks for feature-toggle combinations before production deployment. * Implementing the permanent code correction and validating it before re-enabling the affected feature. We apologise for the disruption and appreciate the patience of affected merchants while our teams worked to restore access.