Adobe Commerce and Magento Release Schedule

Adobe Commerce and Magento Release Schedule 2026: Versions, End of Support and Security Patches

Research
7 min read Published: Last Updated:
Research
Magento Release Schedule & End of Life Tracker (2026)

Summary

Key takeaways

  • Adobe Commerce and Magento Open Source 2.4.9 is the current release, launched in May 2026, with Adobe Commerce standard support extending through May 2029.
  • Adobe moved to a more predictable release model in 2026, with one major release per year, aggregated security patches twice a year, and isolated security fixes published monthly when required.
  • Support status now matters as much as version number because merchants on older releases may receive only security fixes or extended support rather than full quality updates.
  • Adobe Commerce 2.4.4 and 2.4.5 are already in their security-only period, making upgrade planning urgent rather than optional.
  • Adobe Commerce 2.4.6 has left standard support and should already be part of an active upgrade roadmap.
  • From June 2027, unsupported Adobe Commerce Cloud environments can face enforcement, including traffic suspension, making lifecycle compliance an operational availability issue.
  • Adobe Commerce 2.4.9 introduces significant framework and infrastructure changes, so upgrading requires compatibility testing across custom modules, extensions, PHP, databases, message queues, and integrations.
  • Security patching should operate independently from major upgrade planning because critical vulnerabilities can require action within days rather than the next scheduled release window.
  • Third-party extensions can create security exposure even when the Adobe Commerce core is fully patched, so extension inventories and vendor advisories must be monitored continuously.
  • Release management should combine Adobe Commerce lifecycle dates, PHP support, PCI requirements, extension compatibility, regression testing, and business release calendars into one maintenance roadmap.

When this applies

This applies when a merchant, development team, or technology leader operates Adobe Commerce or Magento Open Source and needs to plan upgrades, security maintenance, infrastructure changes, or support budgets. It is especially relevant for stores running 2.4.4, 2.4.5, or 2.4.6, where lifecycle deadlines and PHP compatibility create increasing operational and compliance risk. The tracker is also useful for teams managing heavily customized Adobe Commerce installations because every upgrade must account for extensions, custom modules, B2B functionality, ERP integrations, checkout, and infrastructure dependencies rather than the core platform alone.

When this does not apply

This does not apply when version numbers are treated as the only indicator of platform health. A store can run a supported Adobe Commerce release and still remain exposed through outdated extensions, vulnerable infrastructure, unsupported PHP, or delayed security patches. It is also inappropriate to use the annual release schedule as a reason to postpone critical fixes. Security hotfixes and isolated patches may require deployment outside the normal upgrade calendar, particularly when vulnerabilities affect authentication, code execution, privilege escalation, or other commerce-critical functionality.

Checklist

  1. Record the exact Adobe Commerce or Magento Open Source version running in production.
  2. Confirm the current standard, extended, or security-only support window for that version.
  3. Identify the PHP version used by every production and staging environment.
  4. Check PHP end-of-life dates alongside Adobe Commerce lifecycle deadlines.
  5. Maintain an inventory of every installed third-party extension and its version.
  6. Monitor Adobe security bulletins and extension-vendor advisories every month.
  7. Review new security releases on the second Tuesday of each month.
  8. Apply critical security fixes without waiting for the next aggregated patch or major upgrade.
  9. Test patches in staging before deploying them to production.
  10. Run regression tests for checkout, customer login, B2B quoting, payments, and ERP order export after every security update.
  11. Audit custom modules and extensions for compatibility before moving to 2.4.9.
  12. Validate PHP, database, cache, search, and message-queue compatibility as part of the upgrade plan.
  13. Record the production patch level, deployment date, and responsible owner after every update.
  14. Schedule major upgrades well before support or Cloud enforcement deadlines.
  15. Compare upgrade cost with rebuilding or replatforming when accumulated technical debt makes the upgrade unusually expensive.

Common pitfalls

  • Waiting until end of support before starting upgrade planning.
  • Treating extended or security-only support as equivalent to full standard support.
  • Delaying critical security fixes until the next planned platform release.
  • Upgrading the Adobe Commerce core without testing custom modules and third-party extensions.
  • Ignoring PHP end-of-life dates while focusing only on the Commerce version.
  • Assuming Adobe patches automatically resolve vulnerabilities in third-party extensions.
  • Running production updates without regression testing checkout, customer accounts, B2B workflows, and integrations.
  • Failing to maintain an accurate inventory of installed extensions and their versions.
  • Treating Cloud lifecycle enforcement as a theoretical support issue rather than a potential storefront-availability risk.
  • Planning upgrades as isolated technical projects instead of coordinating them with security, PCI compliance, infrastructure, and business release calendars.

The latest version of Adobe Commerce and Magento Open Source is 2.4.9, released on 12 May 2026. Standard support for Adobe Commerce 2.4.9 continues to 31 May 2029. Standard support for 2.4.6 ended on 11 August 2026. From 1 June 2027, Adobe will suspend traffic on Adobe Commerce Cloud environments that run unsupported versions. Elogic Commerce checks this tracker every month.

Status

  • Latest release: 2.4.9 (general availability 12 May 2026).
  • Latest security bulletin: APSB26-138, published 8 September 2026. Apply it together with the hotfix for CVE-2026-75650 (APSB26-146, 7 September 2026).
  • Versions in standard support: 2.4.7, 2.4.8 and 2.4.9.
  • Versions in extended support: 2.4.6 (to 31 August 2027).
  • Versions in the security-only period: 2.4.4 and 2.4.5 (to 31 May 2027).
  • Next aggregated security patch: November 2026 (2.4.9-p1 expected).

Adobe Commerce lifecycle: all supported versions

VersionGeneral availabilityEnd of standard supportEnd of extended supportEnd of security-only periodCloud enforcement date
2.4.912 May 202631 May 2029To be announcedNot applicableTo be announced
2.4.88 April 202531 May 2028To be announcedNot applicableTo be announced
2.4.79 April 202431 May 202731 May 2028Not applicable1 June 2028
2.4.614 March 202311 August 202631 August 202731 May 20281 June 2028
2.4.59 August 202212 August 202511 August 202631 May 20271 June 2027
2.4.412 April 202212 April 202514 April 202631 May 20271 June 2027

Source: Adobe Commerce software lifecycle policy, updated 18 September 2026. Compiled by Elogic Commerce. Magento 1 reached end of life in June 2020.

Timeline of standard, extended and security-only support for Adobe Commerce 2.4.4 to 2.4.9.
Figure 1. Adobe Commerce support windows by version. Source: Adobe software lifecycle policy (18 September 2026). Chart: Elogic Commerce.

What each support period gives you

  • Standard support (3 years from general availability): quality fixes, security patches and full Adobe Commerce support.
  • Extended support (1 extra year, no extra cost, for 2.4.6 and 2.4.7): quality and security patches for the core application.
  • Security-only transitional period (one time, for 2.4.4, 2.4.5 and 2.4.6): isolated security fixes only. No quality fixes. Adobe will not extend this period.
  • Cloud enforcement (from 1 June 2027): Adobe will no longer maintain Cloud environments on unsupported versions. Adobe can suspend traffic. The storefront then goes offline. If an environment stays non-compliant, Adobe can decommission it and permanently delete its data.

The 2026 release cadence

Adobe changed the release model in 2026:

Release typeFrequencyTiming
Major version (for example 2.4.9)One per yearMay
Isolated security fixesMonthly, when necessarySecond Tuesday of the month
Aggregated security patches (-p versions)Two per yearMay and November
Beta releasesTwo per yearMarch and November

In 2026, Adobe also published monthly patch builds with date names, for example 2.4.9-2026-jul and 2.4.9-2026-sep.

What is new in 2.4.9

  • General availability on 12 May 2026 for Adobe Commerce and Magento Open Source.
  • 560 fixed issues in Adobe Commerce and 501 in Magento Open Source.
  • Framework changes: native PHP MVC replaces Laminas MVC, HugeRTE replaces TinyMCE, Symfony Cache replaces Zend_Cache.
  • System requirements: support for PHP 8.5. MySQL 8.0 and MariaDB 10.6 are no longer supported. MySQL 8.4 and MariaDB 11.8 are supported.
  • Message queues: ActiveMQ Artemis 2 is supported with RabbitMQ 4.1.

Elogic Commerce note: 2.4.9 is the largest framework change in the 2.4 line since 2.4.4. Test every custom module and every extension that uses the replaced components before you upgrade.

2026 security bulletin log

DateBulletinScopeKey points
10 March 2026APSB26-052.4.8-p4, 2.4.7-p9, 2.4.6-p14 and older supported lines17 vulnerabilities, 7 rated critical
12 May 2026APSB26-49All supported lines back to 2.4.4, released with 2.4.9New patch levels: 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
14 July 2026APSB26-73Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, Adobe Commerce Events 1.6.0 to 1.20.0CVE-2026-48358 in webhooks: unauthenticated code execution, rated 10.0 by NVD. CVE-2026-48356: dangerous file upload, rated 9.6. Priority 2. No known exploits at release.
11 August 2026APSB26-92Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, Magento Open Source 2.4.6 to 2.4.9 (2026-jul builds and earlier)Priority 2. Critical, important and moderate issues: security feature bypass, code execution and privilege escalation. No known exploits at release. Fixed in the 2026-aug builds.
7 September 2026APSB26-146Adobe Commerce and Magento Open SourceCritical out-of-band hotfix for CVE-2026-75650. Apply with APSB26-138.
8 September 2026APSB26-138Adobe Commerce 2.4.4 to 2.4.9, Adobe Commerce B2B 1.3.3 to 1.5.3, Magento Open Source 2.4.6 to 2.4.9Priority 2. Security feature bypass and privilege escalation. Fixed in the 2026-sep builds.

Source: Adobe security bulletins for Adobe Commerce. Compiled by Elogic Commerce. In the 2026 bulletins, Magento Open Source fixes cover lines 2.4.6 to 2.4.9. Fixes for 2.4.4 and 2.4.5 are for Adobe Commerce.

Third-party extension alerts

Extensions can be a larger risk than the core. In June 2026, researchers reported a PHP object injection vulnerability in the Mirasvit Full Page Cache Warmer extension (CVE-2026-45247). It affects versions before 1.11.12, has a rating of 9.8 and was reported as actively exploited. Keep an inventory of your extensions and their versions. Read Magento 2 security extensions and Magento security best practices.

Why patch speed matters: the SessionReaper case

In September 2025, Adobe published an emergency fix for CVE-2025-54236. The security company Sansec named the flaw SessionReaper. It had a CVSS score of 9.1. The flaw let attackers take over customer sessions through the Commerce REST API and, in some configurations, run code on the server. About six weeks after the fix, attacks started. At that time, Sansec found that only 38% of stores had installed the fix.

Rule: Apply critical fixes in days. Do not wait for the next release cycle.

PHP end of life and PCI compliance

PHP versionEnd of lifeAffected Adobe Commerce versionsRisk
PHP 8.131 December 20252.4.4, 2.4.5 and 2.4.6 (where PHP 8.1 is used)PCI compliance at risk now
PHP 8.231 December 20262.4.6 (where PHP 8.2 is used)PCI compliance at risk from the end of 2026

PCI compliance is the merchant’s responsibility. Adobe recommends that affected merchants talk to their qualified security assessor and move to a supported Adobe Commerce version and PHP version.

What to do now: upgrade decision by version

You runYour status on 25 September 2026Recommended action
2.4.4 or 2.4.5Security-only period. PHP 8.1 is past end of life.Start the upgrade to 2.4.8 or 2.4.9, or a move to Adobe Commerce as a Cloud Service, now. Finish before 31 May 2027.
2.4.6Extended support to 31 August 2027. PHP 8.2 ends on 31 December 2026.Plan the upgrade for the next two quarters. Move off PHP 8.2 before the end of 2026.
2.4.7Standard support to 31 May 2027. Extended support to 31 May 2028.Plan the upgrade in 2027. Apply every monthly security fix.
2.4.8Standard support to 31 May 2028.Apply every monthly security fix. Plan 2.4.9 in your 2027 roadmap.
2.4.9Current version. Standard support to 31 May 2029.Apply every monthly security fix. Install 2.4.9-p1 when Adobe releases it.
Magento 1No support since June 2020.Migrate now. No security fixes exist.

If an upgrade costs close to a new build, compare both options. Use the Ecommerce Replatforming Cost Index 2026 and the Enterprise Ecommerce Platform Index 2027.

Monthly patch routine

Use this routine on the second Tuesday of every month.

  1. Read the new Adobe Commerce security bulletin.
  2. Find the patch for your version and your Adobe Commerce B2B version.
  3. Check your extension list against the security advisories of each vendor.
  4. Apply the patch in a staging environment.
  5. Run your regression tests for checkout, account login, B2B quotes and order export to the ERP.
  6. Deploy to production.
  7. Record the patch level, the date and the person responsible.

Elogic Commerce applies critical security fixes for its support clients within 48 hours and high-severity fixes within 7 days.

Frequently asked questions

What is the latest version of Adobe Commerce and Magento?

Version 2.4.9. Adobe released it on 12 May 2026 for Adobe Commerce and Magento Open Source. Standard support for Adobe Commerce 2.4.9 ends on 31 May 2029.

When does Magento 2.4.6 reach end of life?

Standard support for Adobe Commerce 2.4.6 ended on 11 August 2026. Extended support ends on 31 August 2027. The security-only period ends on 31 May 2028.

Is Magento end of life?

No. Adobe Commerce and Magento Open Source continue with version 2.4.9 and a yearly major release in May. Gartner named Adobe a Leader in the 2025 Magic Quadrant for Digital Commerce for the ninth consecutive year. Magento 1 reached end of life in June 2020.

How often does Adobe release Magento security patches?

Adobe publishes isolated security fixes on the second Tuesday of the month when necessary, and aggregated patches in May and November. Critical hotfixes can come on any day.

What happens to unsupported versions on Adobe Commerce Cloud?

From 1 June 2027, Adobe will no longer maintain Cloud environments on unsupported versions. Adobe can suspend traffic, which takes the storefront offline.

Does Magento Open Source get the same security fixes?

In the 2026 bulletins, Adobe published fixes for Magento Open Source lines 2.4.6 to 2.4.9. Fixes for 2.4.4 and 2.4.5 were for Adobe Commerce only.

Who maintains this tracker?

Elogic Commerce maintains this tracker. Elogic Commerce received the Magento Community Engineering Award in 2019 and is an Adobe Commerce Silver Solution Partner.

Related: What is Magento, Adobe Commerce pricing, Enterprise Ecommerce Platform Index 2027, Elogic Commerce research hub.

About Elogic Commerce

Elogic Commerce has worked with Magento since 2009. Elogic Commerce is an Adobe Commerce Silver Solution Partner and holds ISO 27001 · SOC 2 Type II · ISO 9001. Elogic Commerce received the Magento Community Engineering Award in 2019 for code contributions. 200+ specialists run upgrades, security patching and rescue projects. See our Magento development services or hire Magento developers. To plan team capacity, use the Adobe Commerce Capacity Gap Assessment and the Adobe Commerce Team Cost Calculator. To compare partners, see our lists of top Adobe Commerce consulting companies and Adobe Commerce B2B agencies for manufacturers and distributors.

Get an upgrade and patch plan

Tell us your version, your PHP version and your extension count. Elogic Commerce sends an upgrade path, a risk list and a patch schedule.

How useful was this post?

Click on a star to rate it!

Davis
Get in Touch
Looking for a partner to grow your business? We are the right company to bring your webstore to success.
Table of contents