The short answer
On 28 September 2026, Adobe provides security patches for Magento 2.4.7, 2.4.8 and 2.4.9, in both Magento Open Source and Adobe Commerce. 2.4.6 is covered for Adobe Commerce customers only, on extended support until 31 August 2027. Everything older, 2.4.5 and before, gets nothing. The dates below are from Adobe's lifecycle policy.
| Version | Released | Standard support ends | Adobe Commerce extended support | Status today |
|---|---|---|---|---|
| 2.4.9 | 12 May 2026 | 31 May 2029 | To be announced | Supported |
| 2.4.8 | 8 April 2025 | 31 May 2028 | To be announced | Supported |
| 2.4.7 | 9 April 2024 | 31 May 2027 | 31 May 2028 | Supported |
| 2.4.6 | 14 March 2023 | 11 August 2026 | 31 August 2027 | Adobe Commerce only. Open Source: unsupported |
| 2.4.5 | 9 August 2022 | 12 August 2025 | 11 August 2026 | Unsupported |
| 2.4.4 | 12 April 2022 | 12 April 2025 | 14 April 2026 | Unsupported |
Every 2.4 release gets three years of standard support from its release date, covering quality fixes and security patches. Anything older than 2.4.4, including the whole of Magento 2.3 and Magento 1, has been out of support for years.
The Open Source trap
Extended support is the extra year Adobe gives after standard support ends. Adobe's own notes are explicit that it is for Adobe Commerce customers only. Magento Open Source, the free edition most small and mid-sized stores run, does not get it.
That is why the table matters more for Open Source stores than it first appears. A store on Adobe Commerce 2.4.6 is still receiving patches today. The same store on Magento Open Source 2.4.6 stopped receiving them on 11 August 2026, and many owners don’t know which edition they run. If you don’t pay Adobe a licence fee, you are on Open Source.
What unsupported actually means
An unsupported store doesn’t stop taking orders. It stops getting fixes. Every vulnerability found from that day on stays open on your site, and attackers read the same security bulletins you do. Card-skimming attacks on Magento are routine, and the StyleSmuggler zero-day in September 2026 showed how quickly one becomes a live attack.
- Card payments. If you take card payments, PCI DSS expects security patches to be applied. An unpatchable platform is hard to defend in an assessment.
- Adobe Commerce Cloud. Adobe states that from 1 June 2027 it will no longer maintain Cloud environments running unsupported versions, including suspending traffic to them.
- Extensions and hosting. Extension vendors and hosts move on too. The longer a store stays behind, the fewer compatible releases there are to upgrade to, and the bigger the eventual jump.
How to check which version you are on
Three quick ways. The Magento admin shows the version in its footer. On the server, bin/magento --version prints it. And the version constraint for magento/product-community-edition (Open Source) or magento/product-enterprise-edition (Adobe Commerce) in composer.json tells you the edition as well as the version.
What to do from each version
From where you are now
- On 2.4.8 or 2.4.9. Keep applying the patch releases as they come out. Plan 2.4.9 if you are on 2.4.8, once your extensions support it.
- On 2.4.7. Supported until May 2027 on Open Source. Start planning the upgrade now: 2.4.8 is the smaller step, 2.4.9 buys the longest support.
- On Open Source 2.4.6. Unsupported since August 2026. Upgrade to 2.4.8 as a priority, and until then keep a web application firewall in front of the store and watch for skimming code.
- On Adobe Commerce 2.4.6. Covered by extended support until August 2027, so there is time, but not much. Plan the upgrade this year.
- On 2.4.5 or older. Unsupported, and the jump grows every release. Start with a read of the extensions and custom code, then upgrade in one planned project rather than piece by piece. If the store has drifted a long way, consider whether upgrading or moving platform is the better spend.
The detail of what the move to 2.4.8 changes is in Magento 2.4.8: what breaks, and what to check first.
See Magento development for upgrades, and the health check for the outside read.
◆ Glossary
- Magento Open Source
- The free edition of Magento, formerly Community Edition. Gets security patches during standard support only.
- Adobe Commerce
- The licensed edition, formerly Magento Commerce or Enterprise. Adds B2B features, optional Adobe hosting and, for some versions, an extra year of extended support.
- Standard support
- The three years after a release when Adobe ships quality fixes and security patches for it.
- Extended support
- An extra period of patches after standard support ends, for Adobe Commerce customers only.
- End of life
- The point after which a version gets no fixes of any kind.
- Security patch
- A release that closes known vulnerabilities, such as 2.4.8-p5.
- PCI DSS
- The card industry's security standard for any business that takes card payments.
◆ Sources



