Which Magento versions still receive security patches?
As of September 2026, Adobe issues security patches for Adobe Commerce versions 2.4.7, 2.4.8, and 2.4.9 under standard support. Magento Open Source is the free, self-hosted edition of Magento, while Adobe Commerce is the paid, licensed edition that shares the same core. Only Adobe Commerce qualifies for the extended and security-only patch phases below. Versions 2.4.5 and 2.4.6 still get limited security fixes for Adobe Commerce customers specifically, under those extended or security-only terms. However, everything on 2.4.3 or earlier is past its support window and gets nothing, on either edition.
Quick answer
- Full support (quality + security), all editions: 2.4.7 through May 31, 2027; 2.4.8 through May 31, 2028; 2.4.9 through May 31, 2029.
- Extended support, Adobe Commerce only: 2.4.6, security and quality patches through August 31, 2027.
- Security-only period, Adobe Commerce only: 2.4.4 and 2.4.5, isolated security fixes only, through May 31, 2027.
- Magento Open Source: no extended or security-only phase on any version. Patches stop once standard support ends.
- Right now: a critical vulnerability (APSB26-146), patched September 8, 2026, affected every version above, including 2.4.9.
Magento version support status: which releases still get security patches
Every end-of-life date below comes directly from Adobe’s own lifecycle policy.
| Version | Standard support ends (all editions) | Extended support ends (Commerce only) | Security-only period ends (Commerce only) | Still receiving security patches? |
|---|---|---|---|---|
| 2.4.9 | May 31, 2029 | N/A | N/A | Yes |
| 2.4.8 | May 31, 2028 | N/A | N/A | Yes |
| 2.4.7 | May 31, 2027 | May 31, 2028 | N/A | Yes |
| 2.4.6 | Aug 11, 2026 (passed) | Aug 31, 2027 | May 31, 2028 | Yes, Commerce only |
| 2.4.5 | Aug 12, 2025 (passed) | Aug 11, 2026 (passed) | May 31, 2027 | Yes, Commerce only |
| 2.4.4 | Apr 12, 2025 (passed) | Apr 14, 2026 (passed) | May 31, 2027 | Yes, Commerce only |
| 2.4.3 and earlier | Ended Nov 2022 or earlier | N/A | N/A | No |
September 2026: a critical bug hit every supported version, including 2.4.9
On September 8, 2026, Adobe released APSB26-146, an emergency fix for a critical vulnerability called StyleSmuggler (CVE-2026-75650, CVSS 10.0). The flaw let an unauthenticated attacker inject code through Magento’s template engine and execute it on the server. It affected every currently supported release line, including 2.4.9. In some cases, attackers compromised stores even after teams applied earlier patches. If your store runs any version in the table above, check specifically for APSB26-146. A supported release number by itself doesn’t confirm you’ve installed that patch.
What happens once a version stops getting patched
In fact, there’s precedent for this. When Adobe ended Magento 1 support in June 2020, attackers compromised thousands of stores still running it within months, because the vulnerabilities were public and permanent. A store past its support window carries the same exposure: the issues are on record, and no fix is coming.
PHP versions add a second clock on top of the Magento one. Version 8.1, used by 2.4.4 through 2.4.6, reached its own end of life on December 31, 2025, per the PHP project’s own end-of-life schedule. Version 8.2, also used by 2.4.6, follows on December 31, 2026. As a result, running Commerce on end-of-life PHP puts PCI compliance at risk even when Adobe’s own patches are current.
What to do if you’re on an unsupported or soon-to-expire version
Adobe has said it won’t extend the security-only period, so treat it as migration time. If you’re already on 2.4.4 or earlier, there’s no patch coming at all. Confirm which Magento version and edition you’re actually running, then scope the upgrade path before the next cutoff date arrives. Our Magento development team can map that path against your current version and hosting setup.
If you’re on 2.4.6, the extended-support clock is already running. Treat August 2027 as the real deadline for planning, not the date to start planning. If you’re on 2.4.4 or 2.4.5, security-only patches cover known CVEs but nothing else, so Adobe simply won’t fix a bug that isn’t a security hole from here on. Check your PHP version alongside your Magento version before anything else: a supported Magento release on unsupported PHP still fails a PCI review.
Related Answers
Still need help?
Not sure where your Magento version actually stands?
We'll check your current release, edition, and patch level against Adobe's support dates, including the September 2026 emergency fix, and map out what an upgrade would involve.