A new version of Magento has been released. Since a potential vulnerability was fixed, we’re considering this a security fix and we recommend all Magento website owners have this upgrade done.
SUPEE-9652, Enterprise Edition 126.96.36.199 and Community Edition 188.8.131.52 address the Zend library vulnerability described below.
Zend Framework 1 vulnerability can be remotely exploited to execute code in Magento 1. While the issue is not reproducible in Magento 2, the library code is the same so it was fixed as well.
Note: while the vulnerability is scored as critical, few systems are affected. To be affected by the vulnerability the installation has to:
- use sendmail as the mail transport agent
- have specific, non-default configuration settings as described
Our Website Maintenance Department will be in contact with our clients regarding this upgrade. If you need this upgrade done on your website, please contact us.