diff --git a/doc/source/releases/17.09_announce.rst b/doc/source/releases/17.09_announce.rst
index 2a536dad649..8fc81c94461 100644
--- a/doc/source/releases/17.09_announce.rst
+++ b/doc/source/releases/17.09_announce.rst
@@ -45,10 +45,33 @@ See `the community hub `__ for a
Security
========
-Together with the 17.09 Galaxy version we release the following three security patches. Per our `Security Policy `__ these has been already applied to all Galaxy releases in the last 12 months.
+The 17.09 Galaxy version includes four security patches. Per our `Security Policy `__ these has been already applied to all Galaxy releases in the last 12 months.
+
+For the best security we recommend all deployers to update to the latest release.
If you maintain a publicly accessible Galaxy please consider signing up for this [mailing list](https://lists.galaxyproject.org/listinfo/galaxy-public-servers) to receive the future security patches in advance of the public disclosure.
+Details of the patched vulnerabilities can be found in the `Security patch details`_ section of these release notes.
+
+Deprecation Notices
+===================
+
+* The Galaxy Sample Tracking and External Services functionality is now considered deprecated. In future releases we will strip down the related
+ user interface and introduce configuration option to keep relevant API controllers active if desired. `Related PR `__.
+* The deprecated admin-only interface for Galaxy Data Libraries is staged to be removed in the next release.
+* Workflows API: When exposing WorkflowInvocationSteps ``state`` will no longer be available.
+* The ``refresh_on_change`` attribute of a ```` tag in the tool syntax can no longer be set to a value of another parameter. Use boolean instead (e.g.``refresh_on_change="True"``). `Details `__
+
+
+Release Notes
+===========================================================
+
+.. include:: 17.09.rst
+ :start-after: announce_start
+
+Security patch details
+======================
+
Limited Galaxy Data Library unauthorized filesystem access
----------------------------------------------------------
@@ -110,20 +133,16 @@ access to read on the host(s) where jobs run.
The fix for this issue has been applied to Galaxy releases back to 16.07 and can be found in this `commit `__
-Deprecation Notices
-===================
+Cross site scripting and session fixation
+-----------------------------------------
-* The Galaxy Sample Tracking and External Services functionality is now considered deprecated. In future releases we will strip down the related
- user interface and introduce configuration option to keep relevant API controllers active if desired. `Related PR `__.
-* The deprecated admin-only interface for Galaxy Data Libraries is staged to be removed in the next release.
-* Workflows API: When exposing WorkflowInvocationSteps ``state`` will no longer be available.
-* The ``refresh_on_change`` attribute of a ```` tag in the tool syntax can no longer be set to a value of another parameter. Use boolean instead (e.g.``refresh_on_change="True"``). `Details `__
+Disclosed on the `mailing list `__ in August 2017.
+Vulnerabilities were found by Eric Rasche and Manabu Ishii respectively. Detailed descriptions of these categories of vulnerabilities can be found at:
-Release Notes
-===========================================================
+- https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
+- https://www.owasp.org/index.php/Session_fixation
-.. include:: 17.09.rst
- :start-after: announce_start
+The fix for these issues has been applied to Galaxy releases back to 16.10 and can be found in this `diff `__
.. include:: _thanks.rst