Magento 2.4.6 Lost Security Support in August, Leaving Stores Exposed

Magento Open Source 2.4.6 stopped receiving security patches on 11 August 2026, while Adobe Commerce customers get one additional year of coverage. The underlying PHP versions — 8.1 and 8.2 — have also lost or are losing security support, compounding the risk even for paid-licence holders. Recent vulnerabilities illustrate the danger: the CosmicSting flaw in 2024 led to payment skimmers on over 4,000 stores, and in 2025 some 62% of Magento sites remained unpatched six weeks after an emergency fix for a critical remote code execution bug. Stores still on 2.4.6 cannot meet PCI DSS patch requirements in the standard way, as no new fixes will be issued for the version. Upgrading to a supported release requires updating the hosting stack and auditing third-party extensions, but security experts warn that delaying further increases exposure with no remediation path available.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in