Adobe stopped patching Magento 2.4.6 on 11 August.
Adobe offers an extra year of extended support to Adobe Commerce customers. If you run Magento Open Source on 2.4.6 or below, standard support has ended and no further patches are coming — including for the arbitrary code execution and privilege escalation issues covered by APSB26-92, published the same day.
Free check back within one working day. No card, no obligation, and we never ask for production credentials to run it.
Nothing here is our opinion.
These are Adobe's published software lifecycle dates. Plenty of agency blog posts have them wrong, and several are still written as though 11 August were in the future.
| Version | Released | Standard support ends | Extended support ends | Open Source status today |
|---|---|---|---|---|
| Magento 1 | — | 30 June 2020 | — | Critical |
| 2.3 and below | — | 8 September 2022 | — | Critical |
| 2.4.4 | 12 April 2022 | 12 April 2025 | 14 April 2026 | Unsupported |
| 2.4.5 | 9 August 2022 | 12 August 2025 | 11 August 2026 | Unsupported |
| 2.4.6 | 14 March 2023 | 11 August 2026 | 31 August 2027 | Unsupported |
| 2.4.7 | 9 April 2024 | 31 May 2027 | 31 May 2028 | Supported |
| 2.4.8 | 8 April 2025 | 31 May 2028 | — | Supported |
| 2.4.9 | 12 May 2026 | 31 May 2029 | — | Supported |
Source: Adobe Commerce software lifecycle policy. The extended support column applies to Adobe Commerce customers; Magento Open Source has no equivalent window.
Magento stores are not attacked eventually. They are attacked immediately.
When SessionReaper (CVE-2025-54236) went public, the security firm Sansec tracked what happened next across the Magento estate. These are their figures, not ours.
of Magento stores were still unpatched six weeks after the vulnerability was disclosed.
Sansec · Oct 2025of all Magento stores were estimated to be carrying one or more injected backdoors.
Sansec · Oct 2025stores compromised in a single 24-hour window once mass exploitation began.
Sansec · Oct 2025A backdoor does not announce itself. It sits quietly, skims card details at checkout, and is usually found by the acquiring bank rather than the merchant.
A senior engineer reads your store. Not a scanner.
Automated scans are useful for triage and nothing else — Sansec's own testing puts the share of server-side malware they miss at roughly 65%. The audit runs in six stages over five to seven working days.
Version and patch position
Your exact release, every patch applied and every one missing, mapped against the current Adobe bulletins and your support status.
Extension and custom code review
Third-party modules checked against known CVEs, and your custom code read by hand for injection, cross-site scripting and request forgery.
Compromise check
Core file integrity, admin users, scheduled tasks, template directives and database entry points examined for anything already living in your store.
Payment page script inventory
Every script loading on checkout, catalogued and authorised — the artefact PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 have demanded since 31 March 2025, and the one most stores cannot produce.
Infrastructure and access
Hosting, TLS, file permissions, admin exposure, credential hygiene, backup integrity and whether a restore has ever actually been tested.
Remediation roadmap
Findings ranked by real exploitability rather than raw CVSS, each with an effort estimate and a recommended route — patch, upgrade to 2.4.8 or 2.4.9, or move to Mage-OS.
If we find something critical mid-audit, you hear about it that day with a recommended holding fix. We do not save it for the report.
Your code and your vulnerability report stay in the UK and Ireland.
Most Magento audit work is delivered from India, Vietnam, the UAE or the United States. That means handing a list of your unfixed weaknesses, and often production access, to a vendor outside UK and EU jurisdiction.
-
Named engineers, no subcontracting You know who is doing the work. It is not passed to an offshore delivery queue overnight.
-
UK and Ireland offices Both timezones covered, and a data path that never leaves the UK or EU.
-
Hyvä specialists, not just Magento ones Hyvä replaces the Knockout and RequireJS stack with Tailwind and Alpine.js — far less third-party JavaScript running on your checkout, and a smaller attack surface to defend.
-
35 years of combined experience We have upgraded, rescued and rebuilt these stores before. The roadmap you get is one we could deliver ourselves.
Normally £1,950 — this rate holds until 31 October 2026. Credited in full against any upgrade or remediation project you commission with us within 90 days. If you decide to fix it yourself, or with someone else, the report is still yours to use.
- All six stages, delivered in 5–7 working days
- Written report with reproduction steps and severity
- Prioritised roadmap with effort estimates
- A 60-minute walkthrough call with the engineer who did the work
- 30 days of follow-up questions
The honest version of what this is for.
If you are on 2.4.6 or below, you already know roughly what the answer is: you need to upgrade. The audit exists to tell you how bad it is right now, whether anything is already inside, and what the upgrade will actually cost — before you commit to it.
Plenty of agencies will quote you an upgrade without looking. We would rather look first, and so would your finance director.
Free patch check, back within one working day.
Give us your store URL and we will tell you the detected version, its support status, the patch level against the latest Adobe bulletin, and how many third-party scripts are loading on your payment page. No card, no call required, no production access.
Prefer to talk first? Call 07368860018
The questions everyone asks.
Other agencies offer a free security audit. Why is yours £1,950?
Because a free audit is an automated scan. Scanners are useful for triage, which is why our free patch check is one — but Sansec's testing puts the share of server-side malware automated tools miss at around 65%. The paid audit is a senior engineer reading your extensions, your custom code and your checkout by hand. Those are different products with the same name. Until 31 October the audit is £950.
Do you need access to our production store?
Not for the free check — that runs entirely from the outside. For the full audit we work from a read-only copy of the codebase and database wherever possible, with access scoped to the audit and revoked when it ends. Everything stays within the UK and EU.
We are on Adobe Commerce, not Open Source. Does this apply?
Partly. Adobe gives Commerce customers a further year, so 2.4.6 is covered to 31 August 2027 and 2.4.5 is in a security-only window. You are in a better position than an Open Source merchant, but you are still on a version that has left standard support, and the clock is running.
Should we upgrade, move to Mage-OS, or leave Magento altogether?
It depends on how much custom code you have and what it is worth. If you have invested heavily in bespoke modules, upgrading to 2.4.8 or 2.4.9, or moving to Mage-OS with a Hyvä frontend, usually costs far less than replatforming. If your store is largely standard, a fresh build may be cheaper overall. The audit gives you the numbers to decide rather than a recommendation we happen to profit from.
How long does the upgrade itself take?
Typically six to fourteen weeks, driven almost entirely by how many extensions and how much custom code need reworking. The audit gives you a scoped estimate rather than a range.
We think we may already have been compromised.
Call rather than fill in the form: +44 1843 496 000. Incident work is different from an audit and starts the same day.