Is Magento end of life?
No. Magento itself is not end of life. Individual Magento 2 release lines reach the end of support at different dates.
Adobe released Magento Open Source and Adobe Commerce 2.4.9 on 12 May 2026 and lists support for it until 31 May 2029, and Adobe's patch release schedule commits to a full 2.4.x release every year in May. 2.4.8 is supported until 31 May 2028 and 2.4.7 until 31 May 2027. The useful question is not "is Magento end of life" but "is my version still supported", and the table below answers it.
Two older generations are a different matter. Adobe ended support for Magento 1 in June 2020, and the 2.3 line is fully out of support, with 2.3.7-p4 listed by Adobe as its final release. Stores on either need a migration rather than a patch.
Magento support dates by version
Source: Adobe's software lifecycle policy (last updated 19 August 2026) and released versions page (12 August 2026). The lifecycle policy is written for Adobe Commerce; extended support and the security-only period are defined for Adobe Commerce customers. The Magento Open Source position is set out in the next section. "TBD" and "N/A" are Adobe's own entries.
| Version | General availability | Standard support ends | Extended support endsAdobe Commerce | Security-only period endsAdobe Commerce | Status on 21 September 2026 | Recommended action |
|---|---|---|---|---|---|---|
| 2.4.9 | 12 May 2026 | 31 May 2029 | TBD | N/A | Supported (latest release) | Stay on the latest security patch |
| 2.4.8 | 8 April 2025 | 31 May 2028 | TBD | N/A | Supported | Stay patched; plan 2.4.9 when your extensions allow |
| 2.4.7 | 9 April 2024 | 31 May 2027 | 31 May 2028 | N/A | Supported, standard support ends in about 8 months | Book the upgrade for early 2027 at the latest |
| 2.4.6 | 14 March 2023 | 11 August 2026 | 31 August 2027 | 31 May 2028 | Past standard support. Adobe Commerce: in extended support | Open Source: upgrade now. Adobe Commerce: plan the upgrade |
| 2.4.5 | 9 August 2022 | 12 August 2025 | 11 August 2026 | 31 May 2027 | Past standard and extended support. Adobe Commerce: security-only period | Upgrade now |
| 2.4.4 | 12 April 2022 | 12 April 2025 | 14 April 2026 | 31 May 2027 | Past standard and extended support. Adobe Commerce: security-only period | Upgrade now |
How to read the three support phases
- Standard support: three years from general availability, with quality fixes and security patches.
- Extended support: in Adobe's words, "one year of additional support at no additional cost for Adobe Commerce customers on versions 2.4.6 and 2.4.7", covering quality and security patches for the core application. Extended support for 2.4.4 and 2.4.5 ended in April and August 2026.
- Security-only transitional period: "a one-time, time-limited transitional period available only for versions 2.4.4, 2.4.5, and 2.4.6", providing "limited isolated security fixes only (no quality fixes)". Adobe states it will not be extended and should be treated as migration time, not a support tier.
Magento Open Source vs Adobe Commerce: what the evidence says
Adobe's lifecycle policy is an Adobe Commerce document, and Adobe has not published a separate lifecycle policy for Magento Open Source. The Open Source position therefore has to be read from what Adobe actually ships and says:
- Adobe publishes Magento Open Source release notes for each 2.4.x version, and Open Source security patch releases have shipped alongside Adobe Commerce ones for lines in standard support: 2.4.8-p5, 2.4.7-p10 and 2.4.6-p15 were all released for Open Source on 12 May 2026, while 2.4.6 was still in standard support.
- Adobe's September 2026 security update notes state: "Open Source merchants can only download patches for version 2.4.7 or later". Those are the lines still in standard support.
- Extended support and the security-only period appear in Adobe's lifecycle policy for Adobe Commerce customers only. Nothing Adobe has published extends them to Open Source.
| Provision | Adobe Commerce (licensed) | Magento Open Source |
|---|---|---|
| Standard support (3 years) | Yes, per Adobe's lifecycle policy | No separate policy published; releases and patches have tracked the same lines during standard support |
| Extended support | Yes: 2.4.6 to 31 Aug 2027, 2.4.7 to 31 May 2028 (2.4.4 and 2.4.5 ended) | Not described by Adobe |
| Security-only period | Yes: 2.4.4 and 2.4.5 to 31 May 2027, 2.4.6 to 31 May 2028 | Not described by Adobe |
| Regular security patch downloads | All lines 2.4.4 to 2.4.9 (September 2026 bulletin) | 2.4.7 or later (Adobe, September 2026) |
In practice: if you run Magento Open Source 2.4.6 today, the 31 August 2027 and 31 May 2028 dates you may have seen quoted are Adobe Commerce dates. Your line left standard support on 11 August 2026, and Adobe has not committed to anything further for it.
Adobe can still issue an emergency fix for an older line when it chooses to. Its hotfix for the actively exploited CVE-2026-75650 (7 September 2026) was published for Magento Open Source 2.4.6 to 2.4.9 as well as Adobe Commerce 2.4.4 to 2.4.9. That is an exception you cannot plan around, not a sign that 2.4.6 Open Source is supported.
Adobe Commerce on Cloud has a further deadline. Adobe's version upgrade enforcement policy for Adobe Commerce on Cloud infrastructure (the PaaS product) requires 2.4.4 and 2.4.5 environments to be upgraded by 1 June 2027 and 2.4.6 and 2.4.7 environments by 1 June 2028, with earlier deadlines of 30 October 2026 and 31 May 2027 for third-party dependencies such as PHP, MariaDB and OpenSearch. Non-compliant environments have inbound traffic suspended and may then be decommissioned. This applies to Adobe Commerce on Cloud only, not to on-premises Adobe Commerce or to Magento Open Source.
What happens when a Magento version reaches end of life
Nothing visible happens on the day. Pages load, checkout works, orders arrive. What changes is quieter, and it compounds:
- You can no longer rely on security patches for that line. Routine fixes go to supported lines. Adobe's regular September 2026 update (APSB26-138) is the current example: patches were issued for 2.4.4 to 2.4.9, with Open Source downloads limited to 2.4.7 or later. Adobe may exceptionally patch an older line, as it did for CVE-2026-75650, but it does not commit to doing so.
- The supporting software ages out too. Adobe does not patch PHP, the database or the search engine. Per Adobe's system requirements, 2.4.6 runs on PHP 8.1 or 8.2. PHP 8.1 reached end of life on 31 December 2025 and PHP 8.2 reaches it on 31 December 2026. MySQL 8.0 reached end of support on 30 April 2026 and Adobe will not validate newer MySQL releases on 2.4.4 to 2.4.7. Elasticsearch 7.17 reached end of support on 15 January 2026.
- PCI DSS questions follow. Unsupported software that handles cardholder data can create PCI DSS compliance concerns. Adobe's lifecycle page says compliance is the merchant's responsibility to assess and recommends consulting your qualified security assessor; do that rather than assuming either way.
- Extension vendors move on. New releases of payment, shipping and search extensions are tested against supported lines, so the gap between your store and a current one widens with every vendor release.
For a detailed account of what this looks like on the line that most recently left standard support, read our Magento 2.4.6 end of life guide.
Check which Magento version you are running
The version appears in the footer of most Magento admin pages. From the command line, run this in the Magento root directory:
bin/magento --versionNote the patch level as well as the line. 2.4.8-p5 is the latest 2.4.8 patch release; plain 2.4.8 is missing more than a year of security fixes even though the line is supported. Adobe's isolated security patches (named like "2.4.8-p5-2026-aug") sit on top of the patch release and do not change the version number, so check your applied patch list as well.
Why patch status matters right now: CVE-2026-75650
On 7 September 2026 Adobe published security bulletin APSB26-146 for CVE-2026-75650, a critical flaw that lets an unauthenticated attacker execute arbitrary code, which Adobe says "has been exploited in the wild targeting Adobe Commerce merchants". It affects Adobe Commerce 2.4.4 to 2.4.9 and Magento Open Source 2.4.6 to 2.4.9, and the fix is the VULN-39341 hotfix plus a rotation of encryption keys and credentials. On a supported, current version that was a hotfix and a key rotation. On an unsupported line it depended on Adobe choosing to issue one, and the routine bulletin the following day did not reach Open Source below 2.4.7. Full detail, and the checks we ran across the stores we host, is in our StyleSmuggler zero-day write-up.
Magento release schedule: what to expect from Adobe
Adobe's patch release schedule sets out the cadence for the 2.4.x line: one full release a year in May (2.4.8 arrived 8 April 2025, 2.4.9 on 12 May 2026), one alpha and one beta a year ahead of it, security patches at least annually for every supported line, and isolated security patch files between them. Adobe has not published a general availability date for the next minor release on its lifecycle page. The latest patch release on each line, per Adobe's released-versions page:
| Line | Latest patch release | Released |
|---|---|---|
| 2.4.9 | 2.4.9 (no 2.4.9-p1 listed yet) | 12 May 2026 |
| 2.4.8 | 2.4.8-p5 | 12 May 2026 |
| 2.4.7 | 2.4.7-p10 | 12 May 2026 |
| 2.4.6 | 2.4.6-p15 (final standard-support release) | 12 May 2026 |
Each of these also needs the September 2026 isolated patch (where Adobe provides it for your product) and the VULN-39341 hotfix. For how Adobe numbers releases, see our guide to Adobe Commerce release types.
What to do next, by version
- 2.4.9: nothing to upgrade. Apply the September 2026 isolated patch and the VULN-39341 hotfix if you have not, and keep PHP on 8.5.
- 2.4.8: supported to 31 May 2028. Be on 2.4.8-p5 plus the September patches. Plan 2.4.9 for when your extensions support PHP 8.5, OpenSearch 3 and Valkey; our 2.4.9 hosting requirements guide lists what changes.
- 2.4.7: supported to 31 May 2027, about eight months away. Start the extension audit now and book the upgrade for early 2027 at the latest, so it does not collide with peak trading or the deadline.
- 2.4.6 on Magento Open Source: past standard support since 11 August 2026, with nothing further committed by Adobe. The fix is an upgrade, usually to 2.4.8, or to 2.4.9 where your extensions are ready. Until it lands, reduce exposure as described below.
- 2.4.6 on Adobe Commerce: extended support to 31 August 2027, security-only to 31 May 2028, Cloud enforcement from 1 June 2028. Plan the upgrade now rather than at the deadline: PHP 8.2 reaches end of life on 31 December 2026.
- 2.4.4 or 2.4.5: Open Source stores have been past standard support since 2025. Adobe Commerce stores are in the security-only period to 31 May 2027, with Cloud enforcement from 1 June 2027. Upgrade now; every routine Adobe bulletin since your line ended went to newer lines.
- 2.3 or Magento 1: Adobe has not issued patches for these lines in years and you cannot rely on any. This is a migration project, not an upgrade. Our free zero-downtime migration service covers the hosting side.
If you cannot upgrade yet: interim protection for an unsupported Magento store
Honest framing first. Nobody can make an unsupported Magento version fully secure, because fixes for the application itself come only from Adobe, and no amount of monitoring replaces a vendor patch. What the hosting layer can do is reduce the chance an attack succeeds and shorten the time to notice one that does, while the upgrade is planned and delivered. That is the proposition: less exposure, and a dated plan to get supported again.
For a store on an unsupported version, EveryHost can provide:
- Environment and security assessment: version, patch level, applied hotfixes, PHP and dependency versions against Adobe's system requirements
- Patch assessment: every patch and hotfix Adobe did release for your line, applied and verified (VULN-39341 was issued for Open Source 2.4.6, for example)
- Hosting-layer hardening: firewall, admin path and IP restrictions, PHP-FPM function restrictions, file permissions, rate limiting
- Attack monitoring: Sentinel watches web server and system logs for exploit attempts, scanners and brute force, and blocks abusive IPs at the firewall
- Malware and file integrity monitoring: scans for webshells, injected code and core file changes
- Backup and recovery planning: on-server backups on every plan, with the Bastion off-site vault as an add-on, so a compromise can be rolled back
- Extension review: which extensions have compatible releases for your target version and which need replacing
- Upgrade planning: a dated plan to 2.4.8 or 2.4.9, so the interim period has an end
Sentinel is EveryHost's security monitoring layer, included on every plan. It works at the server level, so it does not depend on the Magento version. It cannot patch the application, and we will not tell you it makes an end-of-life store safe. It gives you visibility and a faster response while you get back onto a supported release. Our security page lists what is included and the recent vulnerabilities we have handled.
Magento upgrade service: a managed move to 2.4.8 or 2.4.9
A Magento version upgrade is application work and infrastructure work at the same time, and most upgrades stall on the infrastructure half: the production host cannot run the PHP version, does not offer OpenSearch 3, or will not change the cache backend. EveryHost engineers, who operate Magento infrastructure every day, manage the infrastructure and the overall upgrade project, working with your developer or agency on the application work. A managed upgrade covers:
- Audit of the existing environment and store
- Version and dependency assessment against Adobe's system requirements
- A staging environment on the target stack, built fresh rather than upgraded in place
- Extension and custom-code compatibility assessment with your development team or agency
- Move to a production-supported PHP version for the target Magento release
- Database changes (MariaDB or MySQL version moves)
- OpenSearch or Elasticsearch changes (OpenSearch 3 for 2.4.9)
- Redis to Valkey where the target version calls for it
- Security patching to the latest patch level plus current hotfixes
- Functional testing: checkout, payment methods, shipping, emails, admin workflows
- Performance checks on the upgraded staging environment before cutover
- Deployment and cutover with a tested rollback path (the old environment stays untouched)
- Post-upgrade monitoring through Sentinel and our engineers
Upgrading onto fresh infrastructure is the cleanest pattern we know: build the target stack on a new server, upgrade and test the store there as staging, then cut over. It is how our free zero-downtime migration works when paired with an upgrade, and it is what our managed Magento 2 hosting and Adobe Commerce hosting are built around. If you are also choosing a host, our UK Magento hosting comparison sets out the differences. For the cutover itself, see how we use Magento maintenance mode during deployments.
Magento end of life: frequently asked questions
Sources
- Adobe Commerce software lifecycle policy (updated 19 August 2026): support phases, dates, PHP end-of-life table, Cloud enforcement summary.
- Adobe Commerce released versions (updated 12 August 2026): release and patch dates, end of regular support per line.
- Magento Open Source 2.4.9 release notes (updated 22 May 2026): evidence that Open Source releases track the same lines.
- Adobe Commerce patch release schedule (updated 19 August 2026): release cadence and patch types.
- Adobe Commerce system requirements (updated 11 August 2026): PHP, database, search and cache versions per release; MySQL 8.0 and Elasticsearch 7.17 end-of-support notes.
- Required actions and deadlines to secure Commerce environments (updated 18 September 2026): Adobe Commerce on Cloud enforcement deadlines.
- Adobe knowledge base: APSB26-146 / CVE-2026-75650 (updated 21 September 2026): affected versions, hotfix VULN-39341, exploitation statement.
- Adobe knowledge base: APSB26-138 September 2026 security update (updated 16 September 2026): isolated patches per line, Open Source download note.
This page is reviewed against those Adobe pages and updated when they change. Reviewed 21 September 2026.
Not sure whether your Magento version is still supported?
Tell us your version and patch level and we will tell you plainly where you stand, what Adobe has issued for your line, and what an upgrade would involve for your store.