Skip to content
Adobe Commerce Ecommerce Platform Guides

Magento 2.4 End of Life Dates: Every Version From 2.4.4 to 2.4.9

Shakewell ·

Adobe publishes end of support dates for Magento Open Source and Adobe Commerce in its software lifecycle policy. Each 2.4.x line now carries up to three of them. Here they are in one place, checked against Adobe’s pages as of 1 October 2026.

Magento 2.4.x end of life dates

Version Released Regular support ends Extended support ends Security-only fixes end
2.4.4 12 April 2022 12 April 2025 14 April 2026 31 May 2027
2.4.5 9 August 2022 12 August 2025 11 August 2026 31 May 2027
2.4.6 14 March 2023 11 August 2026 31 August 2027 31 May 2028
2.4.7 9 April 2024 31 May 2027 31 May 2028 Not offered
2.4.8 8 April 2025 31 May 2028 Not announced Not offered
2.4.9 12 May 2026 31 May 2029 Not announced Not offered

The release and regular support dates apply to both Magento Open Source and Adobe Commerce. The extended and security-only columns are for Adobe Commerce. More on that below.

As of today, 1 October 2026:

  • 2.4.4, 2.4.5 and 2.4.6 are past the end of regular support. 2.4.4 and 2.4.5 are past extended support as well.
  • 2.4.7 has eight months of regular support left. It ends on 31 May 2027.
  • 2.4.8 and 2.4.9 are fully supported.

What each kind of support means

Regular support is the three years from release. Adobe calls it standard support and says it “includes quality fixes, security patches, and full Adobe Commerce on-call support.”

Extended support is one more year. Adobe offers it “at no additional cost for Adobe Commerce customers on versions 2.4.6 and 2.4.7”, and it “includes quality and security patches for the core application.” 2.4.4 and 2.4.5 had the same extension, and both have now run out.

The security-only period is new. Adobe describes it as “a one-time, time-limited transitional period available only for versions 2.4.4, 2.4.5, and 2.4.6”, with “limited isolated security fixes only (no quality fixes)”. It says the period “will not be extended beyond the published dates”, and to “treat the security-only period as migration time, not as a long-term support tier.”

So “end of life” for a Magento version means the end of patches. The store keeps trading. What stops is the flow of security patches and quality fixes, so any vulnerability disclosed after that date stays open on your store.

None of this covers the software underneath. Adobe does not patch third-party dependencies such as PHP or MySQL, even inside a support window. Its lifecycle page lists PHP 8.1 as end of life on 31 December 2025 and PHP 8.2 on 31 December 2026. That reaches any store still running them, including 2.4.7 stores on PHP 8.2, five months before 2.4.7’s own regular support ends.

Magento Open Source versus Adobe Commerce

The release and regular support dates are the same for both. The difference is what comes after. Adobe’s security patch notes say: “Extended support security patches are available to Adobe Commerce customers only. They are not available for the Magento Open Source code base.”

Adobe has still published some isolated fixes that list Open Source on older lines, such as the September 2026 bulletin, APSB26-138. That is not a commitment. If you run Magento Open Source, plan on the end of regular support as your real deadline. For 2.4.6, that date has passed.

Adobe Commerce on Cloud has a harder deadline

On Adobe Commerce on Cloud, there is also an enforcement date. Adobe says that from 1 June 2027 it “will no longer maintain Cloud environments running unsupported Commerce versions”, and that this “includes suspending traffic to the affected infrastructure.”

The upgrade deadline is 1 June 2027 for 2.4.4 and 2.4.5, and 1 June 2028 for 2.4.6 and 2.4.7. Separate deadlines for PHP, MariaDB, OpenSearch, Redis and RabbitMQ start on 30 October 2026. These apply to Cloud environments, not on-premises stores.

What it means for PCI DSS

If your store takes card payments, PCI DSS applies. Requirement 6.3.3 of PCI DSS v4.0 says system components are protected from known vulnerabilities by installing applicable security patches, with “critical or high-security patches/updates” installed “within one month of release.” Version 4.0.1, the only current version since 31 December 2024, narrowed the one-month rule to critical vulnerabilities.

Either way, the requirement assumes a patch exists. On a version Adobe no longer patches, a critical Magento vulnerability can be disclosed with no patch for you to install, within a month or at all.

Adobe’s lifecycle page says PCI compliance “is the merchant’s responsibility to assess”, and recommends that merchants on affected versions talk to their qualified security assessor.

Your options

Get to the current patch level. If your line is still supported, run the latest security patch release for it (the -p version) and apply the monthly isolated patches. Adobe says you must be on that latest -p release to apply them, and apply them in order. This is the minimum for 2.4.7 today, and for Adobe Commerce on 2.4.4 to 2.4.6, where the isolated security fixes from the extended and security-only periods only apply on the latest -p release. It buys time, not a later end date.

Upgrade to a supported line. Adobe currently names 2.4.8, 2.4.9 or the latest release as fully supported, and 2.4.9 gives the longest runway, to 31 May 2029. The version jump is rarely the hard part. Extensions and custom code are. See Magento upgrades for how we approach it, and what Adobe Commerce upgrades cost for budgeting.

Move platforms. If this is the third upgrade you have paid for, it is fair to ask whether Magento is still the right fit. For Cloud customers, Adobe’s own recommended path is Adobe Commerce as a Cloud Service, where Adobe runs the upgrades. Shopify is another option. We wrote up how to decide whether to stay on Magento or move, and what a Magento to Shopify migration involves.

What we would do this month

Check your version. It shows in the bottom right corner of any Admin page, or run bin/magento --version. Then find it in the table above.

  • On 2.4.4 or 2.4.5: plan the upgrade or the move now. On Adobe Commerce, stay on the latest -p release and keep applying the isolated security fixes until you do.
  • On 2.4.6: if you run Open Source, treat it as unsupported. On Adobe Commerce, use the extended year to upgrade, not to wait.
  • On 2.4.7: get to the latest patch and plan your upgrade before 31 May 2027.
  • On 2.4.8 or 2.4.9: keep patching.

If you think the store may already be exposed, start with a Magento security review. Two of our developers hold Adobe Commerce certifications.


Sources: Adobe Commerce lifecycle policy, Adobe Commerce released versions, Adobe Commerce security patch release notes, Required actions and deadlines to secure Commerce environments, Security update APSB26-138 (Adobe), PCI DSS v4.0 SAQ D for Merchants and Just Published: PCI DSS v4.0.1 (PCI Security Standards Council).

Common questions

Is Magento 2.4.6 end of life?

Regular support for 2.4.6 ended on 11 August 2026. Adobe Commerce customers get extended support, with quality and security patches, until 31 August 2027, then isolated security fixes only until 31 May 2028. Adobe says extended support security patches are not available for the Magento Open Source code base, so an Open Source store on 2.4.6 should plan as if support ended in August 2026.

When does Magento 2.4.7 reach end of life?

Regular support for 2.4.7 ends on 31 May 2027. Adobe Commerce customers then get a year of extended support, to 31 May 2028. On Adobe Commerce on Cloud, Adobe's enforcement date for 2.4.7 is 1 June 2028, after which it says it will suspend traffic to environments still on an unsupported version.

Is Magento 2.4.5 still supported?

No. Regular support ended on 12 August 2025 and extended support ended on 11 August 2026. Adobe Commerce customers can get limited isolated security fixes until 31 May 2027 under a one-time transitional period, with no quality fixes. Adobe describes that period as migration time, not a support tier.

Does Magento Open Source get extended support?

No. Release dates and regular support dates are the same for Magento Open Source and Adobe Commerce, but Adobe states that extended support security patches are available to Adobe Commerce customers only and not to the Magento Open Source code base.

Start a conversation

Start a conversation

Tell us what you want to build, fix or scale, we’ll come back with a clear way forward.