Last reviewed 21 September 2026 against Adobe's lifecycle policy

    Magento End of Life: Support Dates, Security & Upgrade Options

    By Simon Bumford, Founder of EveryHost

    The short answer, as of 21 September 2026

    • Magento end of life is the point at which Adobe stops supporting a release line. For Adobe Commerce that happens in stages: three years of standard support, then for some versions a year of extended support and a security-only period. Adobe has not published an equivalent policy for Magento Open Source, and its current Open Source patch downloads cover 2.4.7 and later. The store keeps running after any of these dates; what changes is that you can no longer rely on fixes.
    • Three release lines are inside Adobe's standard support window today: 2.4.7 (ends 31 May 2027), 2.4.8 (ends 31 May 2028) and 2.4.9 (ends 31 May 2029). 2.4.9, released 12 May 2026, is the latest version.
    • 2.4.6 left standard support on 11 August 2026. 2.4.5 left on 12 August 2025 and 2.4.4 on 12 April 2025. Adobe Commerce customers on 2.4.6 have extended support to 31 August 2027 and a security-only period to 31 May 2028; on 2.4.4 and 2.4.5 the security-only period runs to 31 May 2027.
    • Support differs by product. Extended support and the security-only period are described in Adobe's lifecycle policy for Adobe Commerce customers. For Magento Open Source, Adobe's September 2026 patch notes say patches can be downloaded for 2.4.7 or later.
    • What to do: on Open Source 2.4.6 or older, plan an upgrade to 2.4.8 or 2.4.9 now. If you cannot upgrade immediately, apply every patch and hotfix Adobe has issued for your version, harden the hosting layer and monitor for attack while the upgrade is scheduled.

    Is Magento end of life?

    No. Magento itself is not end of life. Individual Magento 2 release lines reach the end of support at different dates.

    Adobe released Magento Open Source and Adobe Commerce 2.4.9 on 12 May 2026 and lists support for it until 31 May 2029, and Adobe's patch release schedule commits to a full 2.4.x release every year in May. 2.4.8 is supported until 31 May 2028 and 2.4.7 until 31 May 2027. The useful question is not "is Magento end of life" but "is my version still supported", and the table below answers it.

    Two older generations are a different matter. Adobe ended support for Magento 1 in June 2020, and the 2.3 line is fully out of support, with 2.3.7-p4 listed by Adobe as its final release. Stores on either need a migration rather than a patch.

    Magento support dates by version

    Source: Adobe's software lifecycle policy (last updated 19 August 2026) and released versions page (12 August 2026). The lifecycle policy is written for Adobe Commerce; extended support and the security-only period are defined for Adobe Commerce customers. The Magento Open Source position is set out in the next section. "TBD" and "N/A" are Adobe's own entries.

    Adobe Commerce 2.4.x support dates as published by Adobe, with status on 21 September 2026
    VersionGeneral availabilityStandard support endsExtended support endsAdobe CommerceSecurity-only period endsAdobe CommerceStatus on 21 September 2026Recommended action
    2.4.912 May 202631 May 2029TBDN/ASupported (latest release)Stay on the latest security patch
    2.4.88 April 202531 May 2028TBDN/ASupportedStay patched; plan 2.4.9 when your extensions allow
    2.4.79 April 202431 May 202731 May 2028N/ASupported, standard support ends in about 8 monthsBook the upgrade for early 2027 at the latest
    2.4.614 March 202311 August 202631 August 202731 May 2028Past standard support. Adobe Commerce: in extended supportOpen Source: upgrade now. Adobe Commerce: plan the upgrade
    2.4.59 August 202212 August 202511 August 202631 May 2027Past standard and extended support. Adobe Commerce: security-only periodUpgrade now
    2.4.412 April 202212 April 202514 April 202631 May 2027Past standard and extended support. Adobe Commerce: security-only periodUpgrade now

    How to read the three support phases

    • Standard support: three years from general availability, with quality fixes and security patches.
    • Extended support: in Adobe's words, "one year of additional support at no additional cost for Adobe Commerce customers on versions 2.4.6 and 2.4.7", covering quality and security patches for the core application. Extended support for 2.4.4 and 2.4.5 ended in April and August 2026.
    • Security-only transitional period: "a one-time, time-limited transitional period available only for versions 2.4.4, 2.4.5, and 2.4.6", providing "limited isolated security fixes only (no quality fixes)". Adobe states it will not be extended and should be treated as migration time, not a support tier.

    Magento Open Source vs Adobe Commerce: what the evidence says

    Adobe's lifecycle policy is an Adobe Commerce document, and Adobe has not published a separate lifecycle policy for Magento Open Source. The Open Source position therefore has to be read from what Adobe actually ships and says:

    • Adobe publishes Magento Open Source release notes for each 2.4.x version, and Open Source security patch releases have shipped alongside Adobe Commerce ones for lines in standard support: 2.4.8-p5, 2.4.7-p10 and 2.4.6-p15 were all released for Open Source on 12 May 2026, while 2.4.6 was still in standard support.
    • Adobe's September 2026 security update notes state: "Open Source merchants can only download patches for version 2.4.7 or later". Those are the lines still in standard support.
    • Extended support and the security-only period appear in Adobe's lifecycle policy for Adobe Commerce customers only. Nothing Adobe has published extends them to Open Source.
    Support provisions by product, from Adobe's lifecycle policy and September 2026 patch notes
    ProvisionAdobe Commerce (licensed)Magento Open Source
    Standard support (3 years)Yes, per Adobe's lifecycle policyNo separate policy published; releases and patches have tracked the same lines during standard support
    Extended supportYes: 2.4.6 to 31 Aug 2027, 2.4.7 to 31 May 2028 (2.4.4 and 2.4.5 ended)Not described by Adobe
    Security-only periodYes: 2.4.4 and 2.4.5 to 31 May 2027, 2.4.6 to 31 May 2028Not described by Adobe
    Regular security patch downloadsAll lines 2.4.4 to 2.4.9 (September 2026 bulletin)2.4.7 or later (Adobe, September 2026)

    In practice: if you run Magento Open Source 2.4.6 today, the 31 August 2027 and 31 May 2028 dates you may have seen quoted are Adobe Commerce dates. Your line left standard support on 11 August 2026, and Adobe has not committed to anything further for it.

    Adobe can still issue an emergency fix for an older line when it chooses to. Its hotfix for the actively exploited CVE-2026-75650 (7 September 2026) was published for Magento Open Source 2.4.6 to 2.4.9 as well as Adobe Commerce 2.4.4 to 2.4.9. That is an exception you cannot plan around, not a sign that 2.4.6 Open Source is supported.

    Adobe Commerce on Cloud has a further deadline. Adobe's version upgrade enforcement policy for Adobe Commerce on Cloud infrastructure (the PaaS product) requires 2.4.4 and 2.4.5 environments to be upgraded by 1 June 2027 and 2.4.6 and 2.4.7 environments by 1 June 2028, with earlier deadlines of 30 October 2026 and 31 May 2027 for third-party dependencies such as PHP, MariaDB and OpenSearch. Non-compliant environments have inbound traffic suspended and may then be decommissioned. This applies to Adobe Commerce on Cloud only, not to on-premises Adobe Commerce or to Magento Open Source.

    What happens when a Magento version reaches end of life

    Nothing visible happens on the day. Pages load, checkout works, orders arrive. What changes is quieter, and it compounds:

    • You can no longer rely on security patches for that line. Routine fixes go to supported lines. Adobe's regular September 2026 update (APSB26-138) is the current example: patches were issued for 2.4.4 to 2.4.9, with Open Source downloads limited to 2.4.7 or later. Adobe may exceptionally patch an older line, as it did for CVE-2026-75650, but it does not commit to doing so.
    • The supporting software ages out too. Adobe does not patch PHP, the database or the search engine. Per Adobe's system requirements, 2.4.6 runs on PHP 8.1 or 8.2. PHP 8.1 reached end of life on 31 December 2025 and PHP 8.2 reaches it on 31 December 2026. MySQL 8.0 reached end of support on 30 April 2026 and Adobe will not validate newer MySQL releases on 2.4.4 to 2.4.7. Elasticsearch 7.17 reached end of support on 15 January 2026.
    • PCI DSS questions follow. Unsupported software that handles cardholder data can create PCI DSS compliance concerns. Adobe's lifecycle page says compliance is the merchant's responsibility to assess and recommends consulting your qualified security assessor; do that rather than assuming either way.
    • Extension vendors move on. New releases of payment, shipping and search extensions are tested against supported lines, so the gap between your store and a current one widens with every vendor release.

    For a detailed account of what this looks like on the line that most recently left standard support, read our Magento 2.4.6 end of life guide.

    Check which Magento version you are running

    The version appears in the footer of most Magento admin pages. From the command line, run this in the Magento root directory:

    bin/magento --version

    Note the patch level as well as the line. 2.4.8-p5 is the latest 2.4.8 patch release; plain 2.4.8 is missing more than a year of security fixes even though the line is supported. Adobe's isolated security patches (named like "2.4.8-p5-2026-aug") sit on top of the patch release and do not change the version number, so check your applied patch list as well.

    Why patch status matters right now: CVE-2026-75650

    On 7 September 2026 Adobe published security bulletin APSB26-146 for CVE-2026-75650, a critical flaw that lets an unauthenticated attacker execute arbitrary code, which Adobe says "has been exploited in the wild targeting Adobe Commerce merchants". It affects Adobe Commerce 2.4.4 to 2.4.9 and Magento Open Source 2.4.6 to 2.4.9, and the fix is the VULN-39341 hotfix plus a rotation of encryption keys and credentials. On a supported, current version that was a hotfix and a key rotation. On an unsupported line it depended on Adobe choosing to issue one, and the routine bulletin the following day did not reach Open Source below 2.4.7. Full detail, and the checks we ran across the stores we host, is in our StyleSmuggler zero-day write-up.

    Magento release schedule: what to expect from Adobe

    Adobe's patch release schedule sets out the cadence for the 2.4.x line: one full release a year in May (2.4.8 arrived 8 April 2025, 2.4.9 on 12 May 2026), one alpha and one beta a year ahead of it, security patches at least annually for every supported line, and isolated security patch files between them. Adobe has not published a general availability date for the next minor release on its lifecycle page. The latest patch release on each line, per Adobe's released-versions page:

    Latest patch release on each 2.4.x line as of 21 September 2026
    LineLatest patch releaseReleased
    2.4.92.4.9 (no 2.4.9-p1 listed yet)12 May 2026
    2.4.82.4.8-p512 May 2026
    2.4.72.4.7-p1012 May 2026
    2.4.62.4.6-p15 (final standard-support release)12 May 2026

    Each of these also needs the September 2026 isolated patch (where Adobe provides it for your product) and the VULN-39341 hotfix. For how Adobe numbers releases, see our guide to Adobe Commerce release types.

    What to do next, by version

    • 2.4.9: nothing to upgrade. Apply the September 2026 isolated patch and the VULN-39341 hotfix if you have not, and keep PHP on 8.5.
    • 2.4.8: supported to 31 May 2028. Be on 2.4.8-p5 plus the September patches. Plan 2.4.9 for when your extensions support PHP 8.5, OpenSearch 3 and Valkey; our 2.4.9 hosting requirements guide lists what changes.
    • 2.4.7: supported to 31 May 2027, about eight months away. Start the extension audit now and book the upgrade for early 2027 at the latest, so it does not collide with peak trading or the deadline.
    • 2.4.6 on Magento Open Source: past standard support since 11 August 2026, with nothing further committed by Adobe. The fix is an upgrade, usually to 2.4.8, or to 2.4.9 where your extensions are ready. Until it lands, reduce exposure as described below.
    • 2.4.6 on Adobe Commerce: extended support to 31 August 2027, security-only to 31 May 2028, Cloud enforcement from 1 June 2028. Plan the upgrade now rather than at the deadline: PHP 8.2 reaches end of life on 31 December 2026.
    • 2.4.4 or 2.4.5: Open Source stores have been past standard support since 2025. Adobe Commerce stores are in the security-only period to 31 May 2027, with Cloud enforcement from 1 June 2027. Upgrade now; every routine Adobe bulletin since your line ended went to newer lines.
    • 2.3 or Magento 1: Adobe has not issued patches for these lines in years and you cannot rely on any. This is a migration project, not an upgrade. Our free zero-downtime migration service covers the hosting side.

    If you cannot upgrade yet: interim protection for an unsupported Magento store

    Honest framing first. Nobody can make an unsupported Magento version fully secure, because fixes for the application itself come only from Adobe, and no amount of monitoring replaces a vendor patch. What the hosting layer can do is reduce the chance an attack succeeds and shorten the time to notice one that does, while the upgrade is planned and delivered. That is the proposition: less exposure, and a dated plan to get supported again.

    For a store on an unsupported version, EveryHost can provide:

    • Environment and security assessment: version, patch level, applied hotfixes, PHP and dependency versions against Adobe's system requirements
    • Patch assessment: every patch and hotfix Adobe did release for your line, applied and verified (VULN-39341 was issued for Open Source 2.4.6, for example)
    • Hosting-layer hardening: firewall, admin path and IP restrictions, PHP-FPM function restrictions, file permissions, rate limiting
    • Attack monitoring: Sentinel watches web server and system logs for exploit attempts, scanners and brute force, and blocks abusive IPs at the firewall
    • Malware and file integrity monitoring: scans for webshells, injected code and core file changes
    • Backup and recovery planning: on-server backups on every plan, with the Bastion off-site vault as an add-on, so a compromise can be rolled back
    • Extension review: which extensions have compatible releases for your target version and which need replacing
    • Upgrade planning: a dated plan to 2.4.8 or 2.4.9, so the interim period has an end

    Sentinel is EveryHost's security monitoring layer, included on every plan. It works at the server level, so it does not depend on the Magento version. It cannot patch the application, and we will not tell you it makes an end-of-life store safe. It gives you visibility and a faster response while you get back onto a supported release. Our security page lists what is included and the recent vulnerabilities we have handled.

    Magento upgrade service: a managed move to 2.4.8 or 2.4.9

    A Magento version upgrade is application work and infrastructure work at the same time, and most upgrades stall on the infrastructure half: the production host cannot run the PHP version, does not offer OpenSearch 3, or will not change the cache backend. EveryHost engineers, who operate Magento infrastructure every day, manage the infrastructure and the overall upgrade project, working with your developer or agency on the application work. A managed upgrade covers:

    • Audit of the existing environment and store
    • Version and dependency assessment against Adobe's system requirements
    • A staging environment on the target stack, built fresh rather than upgraded in place
    • Extension and custom-code compatibility assessment with your development team or agency
    • Move to a production-supported PHP version for the target Magento release
    • Database changes (MariaDB or MySQL version moves)
    • OpenSearch or Elasticsearch changes (OpenSearch 3 for 2.4.9)
    • Redis to Valkey where the target version calls for it
    • Security patching to the latest patch level plus current hotfixes
    • Functional testing: checkout, payment methods, shipping, emails, admin workflows
    • Performance checks on the upgraded staging environment before cutover
    • Deployment and cutover with a tested rollback path (the old environment stays untouched)
    • Post-upgrade monitoring through Sentinel and our engineers

    Upgrading onto fresh infrastructure is the cleanest pattern we know: build the target stack on a new server, upgrade and test the store there as staging, then cut over. It is how our free zero-downtime migration works when paired with an upgrade, and it is what our managed Magento 2 hosting and Adobe Commerce hosting are built around. If you are also choosing a host, our UK Magento hosting comparison sets out the differences. For the cutover itself, see how we use Magento maintenance mode during deployments.

    Magento end of life: frequently asked questions

    There is no single date. Adobe's lifecycle table gives each release line three years of standard support from its general availability date, so lines reach the end of support one at a time. As of 21 September 2026: 2.4.4 ended 12 April 2025, 2.4.5 ended 12 August 2025, 2.4.6 ended 11 August 2026, 2.4.7 ends 31 May 2027, 2.4.8 ends 31 May 2028 and 2.4.9 ends 31 May 2029. Adobe Commerce customers on some lines then have extended support and a security-only period. Adobe continues to release a new 2.4.x version every year, so the platform itself is not end of life.

    Standard support for the 2.4.6 line ended on 11 August 2026. If you are a licensed Adobe Commerce customer, Adobe's lifecycle table gives 2.4.6 extended support until 31 August 2027, followed by a security-only period to 31 May 2028. Adobe describes those extra periods for Adobe Commerce customers. If you run Magento Open Source 2.4.6, Adobe has not published any support beyond the standard window, and Adobe's September 2026 patch notes say Open Source patches can be downloaded for 2.4.7 or later. Treat Open Source 2.4.6 as unsupported and plan the upgrade.

    As of 21 September 2026, three release lines are inside Adobe's standard support window: 2.4.7 (until 31 May 2027), 2.4.8 (until 31 May 2028) and 2.4.9 (until 31 May 2029). Adobe's lifecycle table is written for Adobe Commerce; Magento Open Source releases have tracked the same lines, and Adobe's current Open Source patch downloads cover the same three lines. Being on a supported line is not enough on its own: you also need the latest security patch for it, which as of September 2026 means 2.4.9, 2.4.8-p5 or 2.4.7-p10 plus the September 2026 isolated patch and the APSB26-146 hotfix.

    Nothing visible happens on the day. The store keeps loading pages and taking orders. What changes is that you can no longer rely on Adobe to fix what is found afterwards: routine security patches and quality fixes stop for that line, and any later fix is at Adobe's discretion. Over time the supporting software ages out too (PHP, the database, the search engine), extension vendors stop testing against the old version, and unsupported software can raise PCI DSS compliance concerns that you will need to assess with your PCI assessor.

    Yes, and it is the most misunderstood part of the subject. Adobe's software lifecycle policy, including the three-year standard window, extended support and the security-only period, is written for Adobe Commerce. Adobe has not published an equivalent lifecycle document for Magento Open Source. What Adobe's release and patch notes show is that Open Source releases have tracked the same lines during standard support (2.4.6-p15, 2.4.7-p10 and 2.4.8-p5 all shipped for Open Source on 12 May 2026), and that Open Source merchants can currently download patches for version 2.4.7 or later. If you are unsure which product you run: Adobe Commerce is a paid licence with a contract and account team; if you installed Magento for free, you run Open Source.

    You can continue running it, but you can no longer rely on it being patched. Adobe can issue an emergency fix for older lines, as it did for CVE-2026-75650 in September 2026, but that is an exception rather than something to plan around. What you can do is reduce exposure while you plan the upgrade: apply every patch and hotfix Adobe has released for your version, restrict and harden the admin, keep the hosting layer patched and monitored, and keep tested backups off the server. That lowers the risk without removing it. Unsupported software can also raise PCI DSS compliance concerns, which you should assess with your PCI assessor or QSA.

    If you are on Magento Open Source 2.4.6 or older, you are already past standard support, so the upgrade is a matter of how short you can make the exposure, not whether to do it. If you are on 2.4.7, you have until 31 May 2027 and should schedule the upgrade now so it lands well before that. If you are on 2.4.8 or 2.4.9, you do not need a version upgrade, but you must keep applying Adobe's security patches as they are released.

    Magento Open Source and Adobe Commerce 2.4.9, released on 12 May 2026. It runs on PHP 8.5, OpenSearch 3, MariaDB 11.8 or 12.3 and Valkey 9, and is supported until 31 May 2029. As of 21 September 2026 Adobe's released-versions page lists no 2.4.9-p1; the September 2026 security fixes for 2.4.9 were issued as an isolated patch file rather than a new patch version.

    In our experience most 2.4.x to 2.4.8 or 2.4.9 upgrades take several weeks from audit to cutover, and the single biggest variable is your third-party extensions. A store with a handful of well-maintained extensions is a short project. A store with dozens of extensions from mixed vendors, a heavily customised theme and bespoke integrations is a long one, because every extension without a compatible release has to be replaced, patched or removed. The extension audit is the first thing to do, and it tells you almost everything about the timeline.

    Partly. The hosting layer can be hardened and monitored regardless of the Magento version: firewall rules, admin access restrictions, PHP-FPM restrictions, file integrity monitoring, malware scanning, attack traffic monitoring and off-site backups all work on an unsupported version. That reduces the chance of an attack succeeding and shortens the time to detect one that does. It does not fix vulnerabilities in the Magento application code itself, which only Adobe can patch. Treat interim protection as a way to buy a safer few months, not as an alternative to upgrading.

    Sources

    This page is reviewed against those Adobe pages and updated when they change. Reviewed 21 September 2026.

    Not sure whether your Magento version is still supported?

    Tell us your version and patch level and we will tell you plainly where you stand, what Adobe has issued for your line, and what an upgrade would involve for your store.