Magento has published a software update that covers security issues.
Important New Security Releases and Patches (community.magento.com)
Today, we are making new releases and patches available to improve the security and functionality of Magento sites. While there are no confirmed attacks related to the security issues, certain vulnerabilities can potentially be exploited to access customer information or take over administrator sessions. The security issues vary across products and all versions of Magento are affected. Full articles about the Magento 1.x and Magento 2.x issues are posted in the Magento Security Center. Additionally, all new releases and a separate USPS patch support recent USPS changes.
The Magento 2.0.1 releases also contain several important functional updates, including official support for PHP7.0.2, which provides dramatic performance improvements, drastically reduces memory consumption, and supports brand-new PHP language features. More information on these updates is posted in the Community and Enterprise Edition release notes.
Our Website Maintenance Department will be in contact with our clients regarding this upgrade.
Also, we don't charge this much but I got an email from another company that wants to charge $190 - $390 to get this update done. We're a bit cheaper and we do testing for you.