---
title: [NOTICE] Configured Commerce Critical Security Patch - Upgrade Recommended
slug: configured-commerce/release-notes/noticeconfigured-commerce-critical-security-patch-upgrade-recommended
docTags: 
createdAt: 2026-10-08T12:00:27.963Z
---

Optimizely released a hotfix for Configured Commerce that includes a critical security patch. The hotfix replaces the current long-term support (LTS) and short-term support (STS) releases. Upgrade to the version that matches your release track.

## What to know

- Optimizely is working directly with affected customers. Upgrade even if Optimizely has not contacted you.
- Cloudflare protections are in place for all versions of Configured Commerce. They reduce risk but do not replace the patch.
- Upgrading is the best way to fully protect your site.

## Upgrade versions

Upgrade to one of the following versions:

- LTS – 5.2.2608.685+lts
- STS – 5.2.2609.401+sts

For details about the hotfix, see Configured Commerce hotfix release notes for [STS](docId\:cI2lPNr2uZDGJiwGjrfhP) and [LTS](docId:6Cqv-ibRa29t2cnzLDyOg).

If you need help planning your upgrade, work directly with your implementation partner and/or submit a ticket with [Optimizely Support](https://support.optimizely.com/hc/en-us).
