Adobe’s July and August 2026 security updates covered Magento Open Source 2.4.9 alongside earlier release lines. They arrived as merchants were assessing the infrastructure and compatibility changes introduced in 2.4.9. Regular support for 2.4.6 also ended in August, making upgrade planning particularly relevant for stores on that line.
For Magento merchants and agencies, the path forward requires careful planning and a clear understanding of what has changed.
The big picture: supported release lines
Adobe’s August security bulletin provided updates for Magento Open Source 2.4.6, 2.4.7, 2.4.8 and 2.4.9. An update for an older line does not, by itself, extend that line’s regular support period. Adobe also provided August updates for older Adobe Commerce lines, so these four versions should not be read as the complete list of Commerce versions covered by the bulletin.
When 2.4.9 reached general availability on 12 May 2026, it brought changes to several underlying components, PHP and service compatibility, and the Admin content editor. Those changes warrant a review of each store’s hosting, custom code, and third-party modules before upgrading.
Adobe’s version documentation records that regular support for 2.4.6 ended on 11 August 2026. Its lifecycle policy also sets out extended support and additional security-fix provisions for Adobe Commerce 2.4.6. Merchants should check which provisions apply to their product and contract rather than assume that all security coverage ended with regular support. Standard support for Adobe Commerce 2.4.7, 2.4.8 and 2.4.9 is listed through 31 May 2027, 31 May 2028 and 31 May 2029 respectively.
What changed in 2.4.9 and why it matters
The 2.4.9 release notes describe several changes that merchants and their technical teams should account for:
-
Laminas MVC: Magento introduces a native MVC implementation in place of the legacy Laminas MVC component. Teams should identify custom code or third-party modules that depend on the affected classes and test them against 2.4.9.
-
Caching: Symfony Cache replaces the deprecated Zend_Cache component. Adobe says existing cache backends and cache-management commands remain supported, but direct dependencies on the replaced component still merit review.
-
Admin content editing: HugeRTE replaces TinyMCE as the WYSIWYG editor. Merchants with editor customisations should test their Admin content workflows.
-
Infrastructure: 2.4.9 adds support for Valkey 9.x as a Redis-compatible cache option and supports Apache ActiveMQ Artemis as a message broker. These are compatibility and migration options; the release does not require every merchant to replace Redis or RabbitMQ as part of the upgrade.
-
Third-party modules: Check each module vendor’s stated 2.4.9 compatibility and test the store’s actual configuration. On Tap’s Magento version guide also discusses the importance of extension compatibility testing.
PHP 8.5 support. Adobe lists PHP 8.5 as fully supported for 2.4.9 and says PHP 8.2 and 8.3 are no longer supported. Its Adobe Commerce release notes describe PHP 8.4 as allowed for upgrade purposes but not recommended for production. Confirm the applicable system requirements, hosting setup and module support before scheduling the move. This is a coordinated application and infrastructure upgrade.
The security patch cascade
The version numbers below were the base or conventional patch releases listed in Adobe’s version history when this article was published:
-
2.4.9 reached general availability on 12 May 2026.
-
2.4.8-p5 was released on 12 May 2026.
-
2.4.7-p10 was released on 12 May 2026.
-
2.4.6-p15 was released on 12 May 2026.
Adobe subsequently issued July APSB26-73 and August APSB26-92 security updates using date-based version labels, including 2.4.9-2026-aug and corresponding August builds for earlier lines. Merchants should use the relevant bulletin and installation notes to identify the update for their installed version, rather than infer patch status from the -p number alone.
For stores on 2.4.6, the end of regular support makes a documented upgrade decision important. Adobe’s support terms and the store’s current security updates should inform the timing. The 2.4.9 changes add compatibility work to that decision, but the amount depends on each store’s modules and customisations.
Practical guidance: Planning your upgrade
If you are on 2.4.6 or 2.4.7, one decision is whether to move first to 2.4.8 or plan a direct upgrade to 2.4.9. Apply the security updates relevant to your current version while that larger project is assessed; an upgrade plan is not a substitute for current patching.
The case for stopping at 2.4.8. This can give teams a nearer-term upgrade route while they assess 2.4.9 compatibility. It still requires full testing of customisations and third-party modules. Adobe lists standard support for 2.4.8 through 31 May 2028.
The case for going straight to 2.4.9. A direct move can avoid a second version upgrade. It also brings the new platform components and PHP 8.5 support into the same project. If a Hyvä implementation or major redesign is already planned, the work can be coordinated, provided the combined testing and release plan is manageable. Adobe issued security updates for 2.4.9 in both July and August 2026.
On Tap’s recommendation: Choose the route after auditing your current version, hosting, custom code, third-party modules, and business change calendar. A stable store may benefit from moving to a supported intermediate version while 2.4.9 dependencies are resolved. A store with confirmed 2.4.9 compatibility may be able to move directly. Do not assume that all third-party modules will be ready by a particular date.
The Hyvä factor
Hyvä’s Theme Module changelog records version 1.5.1 on 1 July 2026. Hyvä has also published Magento 2.4.9 compatibility updates across parts of its product range. That provides a basis for planning, but compatibility of a complete store depends on its precise Hyvä packages, third-party modules and custom work.
If you run Hyvä or plan to adopt it, confirm the supported versions of every component, including Checkout and any ElasticSuite integration discussed in our earlier analysis, before committing to a 2.4.9 release date.
The bigger picture
Magento 2.4.9 updates several underlying components and supported technologies. For merchants, the practical consequence is an upgrade that deserves a clear inventory of dependencies, representative testing and coordination with the hosting team. The changes offer a path to newer supported infrastructure, while the effort required will vary considerably by store.
Regular support for 2.4.6 ended on 11 August 2026, and 2.4.7 has a later standard-support deadline. Merchants should check their applicable lifecycle terms, keep eligible installations updated and set an upgrade timetable that reflects their own technical dependencies.
About On Tap
On Tap is a growth-focused eCommerce consultancy specialising in Magento and Adobe Commerce implementations for mid-market and enterprise merchants. From 2.4.9 upgrade planning and third-party module compatibility audits to Hyvä migrations and ongoing technical maintenance, On Tap helps merchants plan platform changes with confidence.
If you need guidance on your 2.4.9 upgrade path, get in touch.


