Today, we are making new releases and patches available to improve the security and functionality of Magento sites. While there are no confirmed attacks related to the security issues, certain vulnerabilities can potentially be exploited to access customer information or take over administrator sessions. The security issues vary across products and all versions of Magento are affected. Full articles about the Magento 1.x and Magento 2.x issues are posted in the Magento Security Center. Additionally, all new releases and a separate USPS patch support recent USPS changes.
The Magento 2.0.1 releases also contain several important functional updates, including official support for PHP7.0.2, which provides dramatic performance improvements, drastically reduces memory consumption, and supports brand-new PHP language features. More information on these updates is posted in the Community and Enterprise Edition release notes.
We strongly encourage merchants to implement the following patches or upgrades:
DOWNLOADING THE UPDATES
To download a patch or release, choose from the following options:
Enterprise Edition 1.14.2.3 |
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Version 1.14.2.3 |
SUPEE-7405 (Security Enhancements) |
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Support Patches / Security Patches > Security Patches – January 2016 |
SUPEE-7616 (USPS Changes) |
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Support Patches / Security Patches > USPS API – January 2016 |
Enterprise Edition 2.0.1 (New Installations) |
My Account > Downloads Tab > Magento Enterprise Edition 2.X > Magento Enterprise Edition 2.x Release > Version 2.0.1 |
Enterprise Edition 2.0.1 (Upgrade an Existing Installation) |
http://devdocs.magento.com/guides/v2.0/comp-mgr/bk-compman-upgrade-guide.html |
Community Edition 1.9.2.3 |
Community Edition Download Page > Release Archive Tab |
SUPEE-7405 (Security Enhancements) |
Community Edition Download Page > Release Archive Tab > Magento Community Edition Patches - 1.x Section |
SUPEE-7616 (USPS Changes) |
Community Edition Download Page > Release Archive Tab > Magento Community Edition Patches - 1.x Section |
Community Edition 2.0.1 (New Installations) |
Community Edition Download Page > Download Tab
|
Community Edition 2.0.1 (Upgrade an Existing Installation) |
http://devdocs.magento.com/guides/v2.0/comp-mgr/bk-compman-upgrade-guide.html |
Community Edition 2.0.1 (Developers Contributing Code to the CE Code Base) |
http://devdocs.magento.com/guides/v2.0/install-gde/install/cli/dev_options.html |
Be sure to install all previous patches, if you haven’t done so already, and use this occasion to do a security assessment of your systems in accordance with our Security Best Practices. Patches should be installed and tested in a development environment before being put into production. All previous USPS patches must be installed for the new patch (SUPEE-7616) to work.
Thank you for your attention and continued support.