Skip to content

Expert Answers to Your Magento, Shopify & Shopware Questions

Vendor-neutral, engineer-written explanations. Clear definitions first, then practical steps with real examples — no fluff.

Stagebit builds and maintains stores on Magento, Adobe Commerce, Shopify, Shopware, and Laravel, and this library holds the questions our own engineers get asked most often on each platform.

Which Magento versions still receive security patches?

SB
Written by Stagebit Engineering Team
Updated September 2026 3 min read Verified by engineers

As of September 2026, Adobe issues security patches for Adobe Commerce versions 2.4.7, 2.4.8, and 2.4.9 under standard support. Magento Open Source is the free, self-hosted edition of Magento, while Adobe Commerce is the paid, licensed edition that shares the same core. Only Adobe Commerce qualifies for the extended and security-only patch phases below. Versions 2.4.5 and 2.4.6 still get limited security fixes for Adobe Commerce customers specifically, under those extended or security-only terms. However, everything on 2.4.3 or earlier is past its support window and gets nothing, on either edition.

Quick answer

  • Full support (quality + security), all editions: 2.4.7 through May 31, 2027; 2.4.8 through May 31, 2028; 2.4.9 through May 31, 2029.
  • Extended support, Adobe Commerce only: 2.4.6, security and quality patches through August 31, 2027.
  • Security-only period, Adobe Commerce only: 2.4.4 and 2.4.5, isolated security fixes only, through May 31, 2027.
  • Magento Open Source: no extended or security-only phase on any version. Patches stop once standard support ends.
  • Right now: a critical vulnerability (APSB26-146), patched September 8, 2026, affected every version above, including 2.4.9.

Magento version support status: which releases still get security patches

Every end-of-life date below comes directly from Adobe’s own lifecycle policy.

VersionStandard support ends (all editions)Extended support ends (Commerce only)Security-only period ends (Commerce only)Still receiving security patches?
2.4.9May 31, 2029N/AN/AYes
2.4.8May 31, 2028N/AN/AYes
2.4.7May 31, 2027May 31, 2028N/AYes
2.4.6Aug 11, 2026 (passed)Aug 31, 2027May 31, 2028Yes, Commerce only
2.4.5Aug 12, 2025 (passed)Aug 11, 2026 (passed)May 31, 2027Yes, Commerce only
2.4.4Apr 12, 2025 (passed)Apr 14, 2026 (passed)May 31, 2027Yes, Commerce only
2.4.3 and earlierEnded Nov 2022 or earlierN/AN/ANo

September 2026: a critical bug hit every supported version, including 2.4.9

On September 8, 2026, Adobe released APSB26-146, an emergency fix for a critical vulnerability called StyleSmuggler (CVE-2026-75650, CVSS 10.0). The flaw let an unauthenticated attacker inject code through Magento’s template engine and execute it on the server. It affected every currently supported release line, including 2.4.9. In some cases, attackers compromised stores even after teams applied earlier patches. If your store runs any version in the table above, check specifically for APSB26-146. A supported release number by itself doesn’t confirm you’ve installed that patch.

What happens once a version stops getting patched

In fact, there’s precedent for this. When Adobe ended Magento 1 support in June 2020, attackers compromised thousands of stores still running it within months, because the vulnerabilities were public and permanent. A store past its support window carries the same exposure: the issues are on record, and no fix is coming.

PHP versions add a second clock on top of the Magento one. Version 8.1, used by 2.4.4 through 2.4.6, reached its own end of life on December 31, 2025, per the PHP project’s own end-of-life schedule. Version 8.2, also used by 2.4.6, follows on December 31, 2026. As a result, running Commerce on end-of-life PHP puts PCI compliance at risk even when Adobe’s own patches are current.

What to do if you’re on an unsupported or soon-to-expire version

Adobe has said it won’t extend the security-only period, so treat it as migration time. If you’re already on 2.4.4 or earlier, there’s no patch coming at all. Confirm which Magento version and edition you’re actually running, then scope the upgrade path before the next cutoff date arrives. Our Magento development team can map that path against your current version and hosting setup.

If you’re on 2.4.6, the extended-support clock is already running. Treat August 2027 as the real deadline for planning, not the date to start planning. If you’re on 2.4.4 or 2.4.5, security-only patches cover known CVEs but nothing else, so Adobe simply won’t fix a bug that isn’t a security hole from here on. Check your PHP version alongside your Magento version before anything else: a supported Magento release on unsupported PHP still fails a PCI review.

Was this answer helpful?

Your feedback helps us improve our answers.

Still need help?

Not sure where your Magento version actually stands?

We'll check your current release, edition, and patch level against Adobe's support dates, including the September 2026 emergency fix, and map out what an upgrade would involve.

Talk to Magento / Adobe Commerce Experts