In short
Since January 2026, Adobe ships one feature release per year in May, full security patch releases at least once a year, and isolated security fixes on Patch Tuesday every month. Standard support for 2.4.7, 2.4.8 and 2.4.9 ends on May 31 of 2027, 2028 and 2029. If you plan one major upgrade per year and budget a small monthly patching routine, you will never be caught on an unsupported version.
For years, Magento teams planned around a quarterly rhythm of patch releases and occasional minor versions. That rhythm is gone. Adobe changed its release model at the start of 2026, and the new schedule is simpler to plan around if you know how the pieces fit together.
This guide explains the current model, lists the support dates that matter for the 2.4.7, 2.4.8 and 2.4.9 release lines, and shows how to turn them into a practical upgrade calendar and budget for 2026 through 2029.
The 2026 release model in three layers
Adobe’s release schedule now has three distinct layers. Each one needs a different process on your side.
1. One feature release per year (May)
Adobe’s release schedule states that a full release for the 2.4.x LTS line, which carries a three-year support period, ships annually in May. Magento Open Source and Adobe Commerce 2.4.9 followed that pattern and became generally available on May 12, 2026. Each annual release is preceded by one alpha and one beta, which gives you a window to test extensions and custom code before general availability.
2. Full security patch releases (-pN)
Adobe commits to releasing full security patches (the familiar 2.4.x-pN versions) for all supported release lines at least once a year, with additional releases when required. In 2026, patch releases shipped on March 10 (for example 2.4.8-p4 and 2.4.7-p9) and again on May 12 alongside 2.4.9 (2.4.8-p5, 2.4.7-p10). Several partners expect a second aggregated window around November, but Adobe describes extra releases as conditional, so treat any November date as tentative until Adobe confirms it.
3. Monthly isolated security patches
Between full releases, Adobe publishes isolated security patches on Patch Tuesday, the second Tuesday of each month, for Adobe Commerce on Cloud, on-premises Adobe Commerce and Magento Open Source. According to Adobe’s policy, these patches are narrowly scoped code diffs, they are not cumulative, and they must be applied in sequence because each one assumes the earlier ones are installed. Every isolated fix is later folded into the next full -pN release.
Cloud customers receive these through Cloud Patches for Commerce. On-premises and Open Source stores need their own process: confirm your baseline -p version, apply the patch files in order, and verify the result.
Out-of-band hotfixes still happen. In September 2026, Adobe released hotfix VULN-39341 for CVE-2026-75650 (bulletin APSB26-146), an unauthenticated code execution flaw affecting 2.4.4 through 2.4.9 that Adobe confirmed was exploited in the wild. Adobe’s guidance went beyond patching: rotate the encryption key and all associated credentials. Your calendar needs room for events like this.
Support dates for 2.4.7, 2.4.8 and 2.4.9
Adobe’s lifecycle policy gives each release line three years of standard support from general availability. Versions 2.4.6 and 2.4.7 also receive one year of extended support at no extra cost for Adobe Commerce customers.
| Release line | General availability | Standard support ends | Extended support ends |
|---|---|---|---|
| 2.4.6 | March 14, 2023 | August 11, 2026 | August 31, 2027 |
| 2.4.7 | April 9, 2024 | May 31, 2027 | May 31, 2028 |
| 2.4.8 | April 8, 2025 | May 31, 2028 | Not yet announced |
| 2.4.9 | May 12, 2026 | May 31, 2029 | Not yet announced |
Two points stand out. First, standard support for 2.4.6 has already ended, so any store still on that line should be planning a move now. Second, support end dates for newer lines are aligned to May 31, which matches the May release month. That alignment makes planning easier: every spring, one line drops out of standard support and a new one arrives.
For Adobe Commerce on Cloud, Adobe’s security enforcement policy adds hard deadlines. Dependency upgrades (PHP, MariaDB, OpenSearch, Redis or Valkey, RabbitMQ) are due from October 30, 2026, with some dependencies due by May 31, 2027. Version upgrade deadlines are June 1, 2027 for 2.4.4 and 2.4.5, and June 1, 2028 for 2.4.6 and 2.4.7. Adobe states that environments that miss these deadlines may have traffic suspended.
What 2.4.9 changes for your planning
2.4.9 is a heavier upgrade than a typical minor release. According to Adobe’s release notes, it adds PHP 8.5 support and drops PHP 8.2, replaces Laminas MVC with a native implementation, moves from TinyMCE to HugeRTE, replaces Zend_Cache with Symfony Cache, and upgrades dependencies to Symfony 7.4 LTS. It also adds support for MariaDB 11.8 and 12.x, OpenSearch 3 and Valkey 9.
Each of these touches custom modules and third-party extensions. Check the official system requirements page for the exact PHP and database versions supported for your upgrade path, and budget extra regression testing for anything that extends the admin WYSIWYG editor, caching layer or MVC internals.
How to build a 2026–2029 upgrade calendar
The simplest approach is to treat the year as a fixed cycle. The table below is a template, and only the dates already published by Adobe are fixed.
| When | Activity |
|---|---|
| Every month (2nd Tuesday) | Review the isolated security patch, apply on staging, deploy within your agreed window |
| Beta period (early in the year) | Run your codebase and extensions against the beta, log incompatibilities, contact extension vendors |
| May | Feature release and security patch release ship; apply the -pN for your current line immediately |
| June to September | Upgrade project to the new release line, outside peak trading |
| October to December | Code freeze for peak season; security patches only |
Choosing your target line
You do not need to upgrade every year. A practical rule is to stay no more than one release line behind the newest, and never let your line fall out of standard support. Applied to today’s dates, that means:
- On 2.4.6 or older: move directly to 2.4.8 or 2.4.9 as soon as possible. 2.4.6 standard support ended on August 11, 2026.
- On 2.4.7: plan to leave before May 31, 2027. Treat extended support to May 2028 as a safety net only.
- On 2.4.8: you have until May 31, 2028. Upgrading to 2.4.9 in a quiet period during 2027 keeps you comfortably ahead.
- On 2.4.9: support runs to May 31, 2029. Focus on monthly patching and plan your next line after the 2027 feature release has been out for a few months.
A cadence that works for most mid-size stores
- Pick a patch owner and a fixed monthly maintenance window.
- Keep staging in parity with production so isolated patches can be tested in hours, not days.
- Upgrade to a new release line every one to two years, always in the June to September window.
- Run an extension audit before each upgrade and remove modules you no longer use.
- Write down your incident process for emergency hotfixes, including credential rotation.
Before every upgrade, capture a clean baseline of what is installed:
bin/magento --version
composer show --direct
bin/magento module:status --enabled
php -vBudgeting the cycle
We cannot give you a universal price, because cost depends on the number of custom modules, third-party extensions, integrations and the state of your test coverage. What you can do is split the budget into predictable lines:
- Monthly patching retainer: a fixed allocation of hours each month to review, test and deploy isolated patches.
- Annual security patch release: a small project each May to apply the
-pNfor your line. - Release line upgrade: a larger project every one to two years. Estimate it from an audit of custom code and extensions, not from a flat rate.
- Infrastructure: PHP, database, search and cache upgrades often arrive with a new line. On Adobe Commerce Cloud, these also have their own enforcement dates.
- Contingency: keep a reserve for emergency hotfixes and incident response, as the September 2026 vulnerability showed.
The new model rewards steady investment. Teams that patch monthly and upgrade on a schedule spend less in total than teams that wait for end of support and then attempt a two-version jump under deadline pressure.
Frequently asked questions
Does Adobe still release quarterly patches?
No. Since January 2026, Adobe uses monthly isolated security patches, a full security patch release at least once a year, and one feature release each May. Additional full patch releases can happen when required.
Are monthly isolated patches cumulative?
No. Adobe’s policy states they contain only the specific fixes and must be applied in sequence. They are later rolled into the next full -pN release.
When does support for 2.4.7 end?
Standard support ends May 31, 2027. Adobe Commerce customers get extended support until May 31, 2028.
Do these dates apply to Magento Open Source too?
The lifecycle policy covers the 2.4.x release lines, and isolated patches are published for Magento Open Source as well. Extended support is described as an Adobe Commerce benefit, so Open Source users should plan around the standard support dates.
Get a Magento upgrade calendar built for your store
We audit your code and extensions, map your support deadlines, and set up a monthly patching routine you can rely on.
Sources
- Adobe: Software lifecycle policy
- Adobe: Release schedule
- Adobe: Monthly isolated security patching policy
- Adobe: Released versions
- Adobe: Adobe Commerce 2.4.9 release notes
- Adobe: System requirements
- Adobe: Required actions and deadlines to secure Commerce environments
- Adobe: Critical security update APSB26-146





