Adobe advisory APSB26-92 Published 11 August 2026 Magento Open Source 2.4.6 and below: standard support ended
Magento support checker

Adobe stopped patching Magento 2.4.6 on 11 August.

Adobe offers an extra year of extended support to Adobe Commerce customers. If you run Magento Open Source on 2.4.6 or below, standard support has ended and no further patches are coming — including for the arbitrary code execution and privilege escalation issues covered by APSB26-92, published the same day.

Free check back within one working day. No card, no obligation, and we never ask for production credentials to run it.

Your edition
Your version

The dates, from Adobe's own policy

Nothing here is our opinion.

These are Adobe's published software lifecycle dates. Plenty of agency blog posts have them wrong, and several are still written as though 11 August were in the future.

Version Released Standard support ends Extended support ends Open Source status today
Magento 1 30 June 2020 Critical
2.3 and below 8 September 2022 Critical
2.4.4 12 April 2022 12 April 2025 14 April 2026 Unsupported
2.4.5 9 August 2022 12 August 2025 11 August 2026 Unsupported
2.4.6 14 March 2023 11 August 2026 31 August 2027 Unsupported
2.4.7 9 April 2024 31 May 2027 31 May 2028 Supported
2.4.8 8 April 2025 31 May 2028 Supported
2.4.9 12 May 2026 31 May 2029 Supported

Source: Adobe Commerce software lifecycle policy. The extended support column applies to Adobe Commerce customers; Magento Open Source has no equivalent window.

What unpatched actually costs

Magento stores are not attacked eventually. They are attacked immediately.

When SessionReaper (CVE-2025-54236) went public, the security firm Sansec tracked what happened next across the Magento estate. These are their figures, not ours.

62%

of Magento stores were still unpatched six weeks after the vulnerability was disclosed.

Sansec · Oct 2025
16–18%

of all Magento stores were estimated to be carrying one or more injected backdoors.

Sansec · Oct 2025
250+

stores compromised in a single 24-hour window once mass exploitation began.

Sansec · Oct 2025

A backdoor does not announce itself. It sits quietly, skims card details at checkout, and is usually found by the acquiring bank rather than the merchant.

The audit

A senior engineer reads your store. Not a scanner.

Automated scans are useful for triage and nothing else — Sansec's own testing puts the share of server-side malware they miss at roughly 65%. The audit runs in six stages over five to seven working days.

01

Version and patch position

Your exact release, every patch applied and every one missing, mapped against the current Adobe bulletins and your support status.

02

Extension and custom code review

Third-party modules checked against known CVEs, and your custom code read by hand for injection, cross-site scripting and request forgery.

03

Compromise check

Core file integrity, admin users, scheduled tasks, template directives and database entry points examined for anything already living in your store.

04

Payment page script inventory

Every script loading on checkout, catalogued and authorised — the artefact PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 have demanded since 31 March 2025, and the one most stores cannot produce.

05

Infrastructure and access

Hosting, TLS, file permissions, admin exposure, credential hygiene, backup integrity and whether a restore has ever actually been tested.

06

Remediation roadmap

Findings ranked by real exploitability rather than raw CVSS, each with an effort estimate and a recommended route — patch, upgrade to 2.4.8 or 2.4.9, or move to Mage-OS.

If we find something critical mid-audit, you hear about it that day with a recommended holding fix. We do not save it for the report.

Why Ace21

Your code and your vulnerability report stay in the UK and Ireland.

Most Magento audit work is delivered from India, Vietnam, the UAE or the United States. That means handing a list of your unfixed weaknesses, and often production access, to a vendor outside UK and EU jurisdiction.

  • Named engineers, no subcontracting You know who is doing the work. It is not passed to an offshore delivery queue overnight.
  • UK and Ireland offices Both timezones covered, and a data path that never leaves the UK or EU.
  • Hyvä specialists, not just Magento ones Hyvä replaces the Knockout and RequireJS stack with Tailwind and Alpine.js — far less third-party JavaScript running on your checkout, and a smaller attack surface to defend.
  • 35 years of combined experience We have upgraded, rescued and rebuilt these stores before. The roadmap you get is one we could deliver ourselves.
Fixed price, fixed scope
£950

Normally £1,950 — this rate holds until 31 October 2026. Credited in full against any upgrade or remediation project you commission with us within 90 days. If you decide to fix it yourself, or with someone else, the report is still yours to use.

  • All six stages, delivered in 5–7 working days
  • Written report with reproduction steps and severity
  • Prioritised roadmap with effort estimates
  • A 60-minute walkthrough call with the engineer who did the work
  • 30 days of follow-up questions
Book the audit

The honest version of what this is for.

If you are on 2.4.6 or below, you already know roughly what the answer is: you need to upgrade. The audit exists to tell you how bad it is right now, whether anything is already inside, and what the upgrade will actually cost — before you commit to it.

Plenty of agencies will quote you an upgrade without looking. We would rather look first, and so would your finance director.

Start here

Free patch check, back within one working day.

Give us your store URL and we will tell you the detected version, its support status, the patch level against the latest Adobe bulletin, and how many third-party scripts are loading on your payment page. No card, no call required, no production access.

Prefer to talk first? Call 07368860018

Please enter your store's web address.
Please tell us your name.
Please enter a valid email address.

We reply within one business day. Your details are used to answer this enquiry and nothing else.

Before you ask

The questions everyone asks.

Other agencies offer a free security audit. Why is yours £1,950?

Because a free audit is an automated scan. Scanners are useful for triage, which is why our free patch check is one — but Sansec's testing puts the share of server-side malware automated tools miss at around 65%. The paid audit is a senior engineer reading your extensions, your custom code and your checkout by hand. Those are different products with the same name. Until 31 October the audit is £950.

Do you need access to our production store?

Not for the free check — that runs entirely from the outside. For the full audit we work from a read-only copy of the codebase and database wherever possible, with access scoped to the audit and revoked when it ends. Everything stays within the UK and EU.

We are on Adobe Commerce, not Open Source. Does this apply?

Partly. Adobe gives Commerce customers a further year, so 2.4.6 is covered to 31 August 2027 and 2.4.5 is in a security-only window. You are in a better position than an Open Source merchant, but you are still on a version that has left standard support, and the clock is running.

Should we upgrade, move to Mage-OS, or leave Magento altogether?

It depends on how much custom code you have and what it is worth. If you have invested heavily in bespoke modules, upgrading to 2.4.8 or 2.4.9, or moving to Mage-OS with a Hyvä frontend, usually costs far less than replatforming. If your store is largely standard, a fresh build may be cheaper overall. The audit gives you the numbers to decide rather than a recommendation we happen to profit from.

How long does the upgrade itself take?

Typically six to fourteen weeks, driven almost entirely by how many extensions and how much custom code need reworking. The audit gives you a scoped estimate rather than a range.

We think we may already have been compromised.

Call rather than fill in the form: +44 1843 496 000. Incident work is different from an audit and starts the same day.