Professional and Enterprise Versions 10.0.2, 9.0.4, and 8.0.7 Now Available

SugarCRM has released versions 10.0.2, 9.0.4, and 8.0.7 for all editions and these versions are now available for download to on-site customers.

At SugarCRM, we consider data security and the protection of your private information our highest priority. This latest release includes important security updates. As part of our ongoing security review process, we have recently detected security vulnerabilities and, to minimize potential risks, those issues have been investigated and addressed in this updated release.

For more information regarding the specific advisories, please refer to the following Security Advisory announcements:

Following our investigations, we have no indication that the vulnerabilities were exploited. However, administrators are strongly encouraged to upgrade their Sugar instances running the 10.0.1, 9.0.3, and 8.0.6 versions of Sugar or prior, to 10.0.2, 9.0.4, and 8.0.7 to prevent potential exploitation of these weaknesses.

If you host your instance on-site (in any environment outside of the SugarCloud environment), please carefully review the following instructions and take the actions outlined below at the earliest opportunity. Failure to take these actions could leave you exposed to malicious attacks. No action is needed for instances hosted on SugarCloud as these vulnerabilities have already been remedied per Sugar Cloud policy.

Please visit the Download Manager to download the latest patch for your release, 10.0.2, 9.0.4, or 8.0.7, which address these vulnerabilities. Our Installation and Upgrade Guide contains the appropriate guidance to apply these patches to your instance.

If upgrading now is not an option, please open a case with our support team to request a hotfix for the security vulnerabilities. We will then supply a module loadable package that can be applied to your current version and edition of Sugar. Please note that we will only supply hotfixes for supported versions. Support tickets can be opened via our portal or by emailing support@sugarcrm.com. If you are not familiar with the support process, please review our knowledge base article on Working With Sugar Support.

This update also addresses issues identified in prior releases. Please review the release notes pertaining to your version of Sugar below to learn more about this release:

Release Notes

More information on the updates in this release can be found at the following links:

Customers hosting Sugar on their own servers can review the following installation and upgrade instructions:

Please review the Supported Platforms prior to installing or upgrading.

To ensure you are up-to-date on the latest information about Sugar Enterprise & Professional, please join the Enterprise & Sell group in SugarClub, or the other product-specific groups in Explore for additional updates.