Today, we are making new releases and patches available to improve the security and functionality of Magento sites. While there are no confirmed attacks related to the security issues, certain vulnerabilities can potentially be exploited to access customer information or take over administrator sessions. The security issues vary across products and all versions of Magento are affected. Full articles about the Magento 1.x and Magento 2.x issues are posted in the Magento Security Center. Additionally, all new releases and a separate USPS patch support recent USPS changes.
The Magento 2.0.1 releases also contain several important functional updates, including official support for PHP7.0.2, which provides dramatic performance improvements, drastically reduces memory consumption, and supports brand-new PHP language features. More information on these updates is posted in the Community and Enterprise Edition release notes.
We strongly encourage merchants to implement the following patches or upgrades:
Enterprise Editions 220.127.116.11-18.104.22.168: SUPEE-7405 and SUPEE-7616 or upgrade to Enterprise Edition 22.214.171.124
Community Editions 126.96.36.199-188.8.131.52: SUPEE-7405 and SUPEE-7616 or upgrade to Community Edition 184.108.40.206
Enterprise Edition 2.0.0: Upgrade to Enterprise Edition 2.0.1
Community Edition 2.0.0: Upgrade to Community Edition 2.0.1
DOWNLOADING THE UPDATES
To download a patch or release, choose from the following options:
Enterprise Edition Merchants:
Enterprise Edition 220.127.116.11
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Version 18.104.22.168
SUPEE-7405 (Security Enhancements)
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Support Patches / Security Patches > Security Patches – January 2016
SUPEE-7616 (USPS Changes)
My Account > Downloads Tab > Magento Enterprise Edition 1.X > Magento Enterprise Edition 1.x Release > Support Patches / Security Patches > USPS API – January 2016
Enterprise Edition 2.0.1 (New Installations)
My Account > Downloads Tab > Magento Enterprise Edition 2.X > Magento Enterprise Edition 2.x Release > Version 2.0.1
Enterprise Edition 2.0.1 (Upgrade an Existing Installation)
Be sure to install all previous patches, if you haven’t done so already, and use this occasion to do a security assessment of your systems in accordance with our Security Best Practices. Patches should be installed and tested in a development environment before being put into production. All previous USPS patches must be installed for the new patch (SUPEE-7616) to work.
Thank you for your attention and continued support.