06.06.17

MAGENTO 2 and 1 Security update: SUPEE-9767

On May, 31st, Magento team released its last security patch and an upgrade for both Enterprise and Community version of Magento 1 and 2. The SUPEE-9767 patch and the upgrade fix 16 security issues. 7 issues are flagged as High Severity. Read more on Magento Patches.

Majority of these issues need admin access, however, we have seen multiple attacks from hackers to get access to admin accounts (brute force attacks, vulnerable extensions and modules, phishing, etc…).

We strongly encourage you to upgrade your sites immediately from Magento 1 to 1.9.3.3 ASAP. We do prefer to upgrade Magento VS. patching, even if the process takes more time.

As always, we advise you to change URL to admin dashboard (do not use default address /admin/), change admin user login and use strong password.

These security issues are also for Magento 2, so we also encourage you to upgrade to 2.1.7+ ASAP.

Need a Magento team to support you? Contact our Magento developers.

About Tanguy R

Tanguy leads Sutunam with a simple conviction: most digital projects fail before a line of code gets written, because nobody took the time to understand the business first. With 15 years spent connecting systems, building eCommerce platforms and untangling ERP integrations across Lyon and Hanoï, he's as comfortable diagnosing a messy workflow as he is scoping an AI opportunity nobody knew to ask for. These days, he's just as focused on what's next, data sovereignty, cybersecurity, and where blockchain goes beyond crypto.