Security Center

Get the latest patches, security updates, and best practices for your Magento sites

New Security Update

Install critical updates for Magento 1.x and Magento 2.x versions

Tagged:

Open Source

Jun 22, 2020

Magento has released updates for Magento Commerce 1 and Magento Open Source 1. For more information on security updates available for Magento 1. Please see Security updates available for Magento | APSB20-41.

Apr 28, 2020

Magento is making Content Security Policy available for Magento Open Source and Commerce  v2.3.5-p1. The release of Magento  2.3.5-p1 marks the first phase of our implementation and makes CSP available in report-only mode by default. 

Apr 28, 2020

Magento has released updates for Magento Commerce and Open Source editions. For more information on security updates available for Magento, please see APSB20-22 for details.

Jan 28, 2020

With the release of Magento 2.3.4, we’ve changed how we describe security issues. Individual issues are no longer described here in the Magento Security Center. Instead, these issues are documented in an Adobe Security bulletin. Please see Security updates available for Magento | APSB20-02.

Jan 28, 2020

With the release of Magento 2.3.4, we’ve changed how we describe security issues. Individual issues are no longer described here in the Magento Security Center. Instead, these issues are documented in an Adobe Security bulletin. Please see Security updates available for Magento | APSB20-02.

Oct 8, 2019

Magento Commerce and Open Source 2.3.3, 2.3.2-p1 and 2.2.10 contain tens of security enhancements that help close Remote Code Execution (RCE), Cross-Site Scripting (XSS) and other vulnerabilities.

Merchants who have not previously downloaded a Magento 2 release should go straight to Magento Commerce or Open Source 2.3.3.

Oct 8, 2019

SUPEE-11219, Magento Commerce 1.14.4.3 and Open Source 1.9.4.3 contain multiple security enhancements that help close remote code execution (RCE), cross-site scripting (XSS), cross-site request forgery (CSRF) and other vulnerabilities.

Sep 13, 2019

On September 3, Multi-State Information Sharing and Analysis Center (MS-ISAC) has issued an alert related to multiple vulnerabilities that could allow for arbitrary code execution and a recommendation that all sites using PHP should update to the latest PHP version ASAP. Read on for impacts and steps for Magento Commerce sites.

Jun 25, 2019

Magento 2.3.2, 2.2.9, and 2.1.18 contain 75 critical security enhancements. These enhancements are described in three related blog posts — the post you’re currently reading plus these two separate posts, which you can find here: Part 1 and Part 2.

Jun 25, 2019

Magento 2.3.2, 2.2.9, and 2.1.18 contain 75 critical security enhancements. These enhancements are described in three related blog posts — the post you’re currently reading plus these two separate posts, which you can find here: Part 1 and Part 3.