On 11 August 2026, Adobe will end regular support for two of its most widely deployed release lines: Adobe Commerce 2.4.5 and 2.4.6. After that date, neither version will receive new security patches, bug fixes, or quality updates through the standard release process.
For Adobe Commerce customers on 2.4.6, Adobe's lifecycle policy includes one year of additional support at no additional cost, extended through August 2027 for quality and security patches, followed by a security-only transitional period through May 2028. But for merchants running Magento Open Source on either version, 11 August is the hard stop. No more patches. No more fixes. No more support.
Six days is not enough time to complete a major version upgrade. But it is enough time to make the decision, and more importantly, to understand what you are accepting if you do not.
What "end of support" actually means
When a release line exits regular support, Adobe stops releasing security patches, bug fixes, and compatibility updates for that version. As Codilar's analysis makes clear, the store keeps running, but "responsibility for its security shifts entirely from Adobe to the merchant. Every vulnerability discovered after 11 August becomes a permanent exposure with no official patch available."
The historical precedent is sobering. When Adobe ended Magento 1 support in June 2020, as Codilar documents, "over 7,500 Magento stores were compromised in a single coordinated attack campaign in the months that followed. Attackers specifically targeted stores on unsupported versions because the vulnerabilities were publicly documented and permanently unpatched."
The same conditions will apply after 11 August 2026 for every store still running 2.4.5 or 2.4.6.
Note the nuance on 2.4.5: Bemeir's upgrade planning guide clarifies that 2.4.5 reaches August 2026 only because Adobe granted it a free one-year extension, and that extension applies to Adobe Commerce customers only. If you run Magento Open Source on 2.4.5, your real end-of-support date has already passed.
The PCI compliance question
Every eCommerce merchant that processes card payments must comply with PCI DSS requirements, which include maintaining systems with current security patches. Running an unsupported platform version does not automatically mean you are out of compliance, but it creates a gap that becomes increasingly difficult to defend during an audit or, worse, after a breach.
PCI DSS Requirement 6.3.3 specifically addresses the need to install critical security patches within a defined timeframe. When your platform vendor is no longer issuing those patches, your compliance posture depends entirely on compensating controls, custom patches, or third-party security monitoring. None of these are as clean or defensible as simply running a supported version.
The merchants most exposed are those on Magento Open Source 2.4.6 who assume that because the platform is open source, the community will continue to provide security coverage. In practice, community patches are inconsistent, uncoordinated, and rarely meet the documentation and testing standards required for PCI audit trails.
Why this upgrade is different
If you have been through a Magento version upgrade before, you know the challenges: dependency conflicts, extension incompatibilities, theme regressions. Previous upgrade cycles were painful enough that many merchants rationally chose to stay put and accept the risk.
This time, two factors have changed the equation.
First, Adobe released version 2.4.9 in May 2026, representing the current long-term supported release line with support into 2029. Version 2.4.8 is the more commonly adopted upgrade target for merchants coming from 2.4.6, and it includes PHP 8.4 compatibility, MariaDB 11.4 support, enhanced GraphQL APIs, and significant performance improvements. As Raulji Technologies' analysis notes, "a full upgrade is typically a 6 to 14 week project depending on how much custom code and how many extensions you carry."
Second, the monthly isolated security patch model that Adobe introduced this year fundamentally changes the ongoing maintenance burden. Adobe shipped five security patches for the 2.4.6 line alone in the last 14 months, ending at 2.4.6-p15 in May 2026, as Bemeir documents. Once you reach a supported version, staying current requires less effort and carries less risk than at any previous point in the platform's history.
What extended support does and does not cover
For Adobe Commerce merchants who cannot upgrade before 11 August, extended support is the logical interim step. Extended support for 2.4.6 runs through August 2027, providing continued security patches. After that, a security-only transitional period through May 2028 offers an even narrower scope of coverage.
What extended support does not provide is functional updates, compatibility with new PHP or database versions, or guaranteed support for third-party extensions that move to newer release lines. As Echidna's honest assessment puts it: "Extended support is a bridge, not a destination. Merchants should treat it as funded migration time, not permission to stop planning."
What to do this week
Even if 11 August is too soon for a production upgrade, there are concrete steps every merchant on 2.4.5 or 2.4.6 should take immediately.
-
Audit your current version and patch level: Confirm exactly which version and patch level you are running. If you have fallen behind on the security patches released for your current version, applying those is a first priority. The July 2026 APSB26-73 isolated security patch addressed critical vulnerabilities affecting all supported release lines.
-
Confirm your support status: If you are on Adobe Commerce, verify whether your contract includes extended support coverage. If you are on Magento Open Source, understand that 11 August is your hard deadline with no fallback.
-
Begin the upgrade assessment: Have your development team or agency evaluate the upgrade path from your current version to 2.4.8 or 2.4.9. The key areas to assess are PHP compatibility, database compatibility, extension compatibility, and theme compatibility. For merchants running Hyvä, the theme maintains parallel release lines with clear version compatibility matrices, which simplifies this evaluation considerably.
-
Set a deadline: An upgrade without a target date is an upgrade that never happens. Even if the realistic timeline is Q4 2026, committing to a date creates the organisational urgency that vague plans do not.
The bigger picture
11 August is not a surprise. Adobe's lifecycle policy page has had this date published for well over a year. But there is a meaningful difference between knowing a deadline exists and actually acting on it.
The merchants who upgrade now benefit from the most straightforward upgrade path Adobe Commerce has offered in years, a monthly security patch cadence that reduces ongoing maintenance friction, and the peace of mind that comes from running a fully supported platform.
The merchants who delay accept increasing security exposure, potential PCI compliance gaps, and an upgrade that only gets harder as the ecosystem moves further ahead.
About On Tap
On Tap is a growth-focused eCommerce consultancy specialising in Magento and Adobe Commerce implementations for mid-market and enterprise merchants. From upgrade planning and extension compatibility audits to security patch application and ongoing technical maintenance, On Tap helps merchants move from unsupported versions to fully supported platforms with minimal disruption.
If you are on 2.4.5 or 2.4.6 and need help scoping your upgrade path, get in touch.


