Security and compliance notice: Required actions and deadlines
The cybersecurity landscape is fundamentally changing, and the defensive mechanisms enterprises have in place need to rapidly evolve. Security is critical for ecommerce businesses because online transactions require them to handle sensitive personal and business data, exposing them to financial and identity risks in the event of a breach. PaaS ecommerce environments have a shared security responsibility model between Adobe and our customers, where customers are responsible for the maintenance of application layer dependencies, integrations with third-party software, and deployment pipelines.
At Adobe, we proactively address the evolving risks and ensure that we set up our Adobe Commerce on Cloud customers to the highest security standards. This includes:
- Monthly and isolated security fixes for faster and predictable protection against critical vulnerabilities
- Annual patch releases with long term support
- Streamlined lifecycle policies for each release with a 3-year support window
While Adobe takes the necessary steps to keep our customers secure, the shared responsibility model for Adobe Commerce on Cloud requires that our customers always be on a supported version of Adobe Commerce on Cloud and third-party software, apply application patches, audit third-party extensions, and secure custom code. Software that has passed end of vendor support no longer receives security patches, leaving security issues in the software unaddressed. Continuing to run your ecommerce storefront on unsupported software creates a real and growing security risk.
This page outlines the actions all customers on Adobe Commerce on Cloud (version 2.4.4 through 2.4.9) need to take to ensure that their ecommerce environments remain secure, along with the enforcement dates, and what to expect when the security requirements are not met.
Actions required to maintain a secure, compliant environment
To keep your ecommerce environment secure and compliant, all customers on Adobe Commerce on Cloud are required to use:
-
Supported versions of all third-party software dependencies: PHP, MariaDB, Elasticsearch/OpenSearch, Redis, and RabbitMQ
-
A secure and supported version of Adobe Commerce on Cloud
Follow the guidelines below to check if you need to take action to secure your Adobe Commerce on Cloud environments. Environments that do not meet the security requirements by the deadlines outlined in Table 1 below will have inbound traffic suspended, taking the storefront offline. If you have concerns about meeting the deadline and need a short extension, please contact your account team or Adobe Support.
Table 1: Security requirements and deadlines
Detailed steps to secure your environment
Action 1: Verify and upgrade third-party software dependencies
Check that your environment is running vendor-supported versions of the following third-party software dependencies: PHP, MariaDB, Elasticsearch/OpenSearch, Redis, RabbitMQ. If not, upgrade the software dependency to a supported version.
Step 1: Check your third-party software dependency versions
- Sign in to the Cloud Console.
- Open the relevant project, then select the environment you want to review.
- Check the service configuration for that environment in the
.magento/services.yamlfile, which defines the supported service names and versions used by Adobe Commerce on Cloud.
For detailed instructions, see Configure Services.
All unsupported software dependencies must be upgraded to the versions outlined by the timelines in Table 2 below.
Table 2: Required dependency upgrades
Step 2: Prepare for a third-party software dependency upgrade
Adobe will help you upgrade these software dependencies directly.
-
Get started: Open a support ticket listing the environments you need upgraded and the dependencies involved. Open your ticket at least 30 days before your enforcement date so Adobe can schedule the work.
-
Downtime: Adobe confirms the expected window with you when scheduling.
-
Testing: Upgrade and validate a non-production environment before production. At minimum, validate checkout, search, cart, and any custom integrations. Requirements apply to all your environments, so plan to upgrade every environment rather than production alone.
-
Compatibility: Most of these changes are version upgrades within the same software and carry low risk. The following changes warrant closer attention:
- Elasticsearch to OpenSearch and Redis to Valkey are migrations to different software rather than version upgrades. Custom code, extensions, or configuration referencing the original service may need updating.
- Upgrading from PHP 8.1 to 8.2 can surface deprecation warnings in custom code and third-party extensions.
If you use third-party extensions, confirm with your vendors that their current releases support your target software versions. If you work with a solution integrator, involve them early in upgrade planning, testing, and validation.
Action 2: Check Commerce on Cloud version and upgrade to a supported version
Check which Adobe Commerce on Cloud version your environments run. If any environment is not on a supported version, you can upgrade to version 2.4.9 or the latest supported version, or migrate to Adobe Commerce as a Cloud Service.
Step 1: Check your Adobe Commerce on Cloud version and required action
-
Sign in to your Adobe Commerce Admin panel.
The current version displays in the bottom-right corner of any Admin page.
-
If the version is hidden from the Admin panel:
-
Connect to the remote environment.
-
Use the Adobe Commerce Command-line tool to check the version.
code language-shell bin/magento --version
-
Check required actions for your Adobe Commerce version in the table below.
Table 3: Adobe Commerce on Cloud version upgrade requirements
Reason: v2.4.4 and 2.4.5 receive only limited, isolated security fixes for the core application until May 31, 2027 — this does not include quality fixes, compatibility support for application dependencies (for example, PHP), or platform dependency updates. See Adobe’s Lifecycle Policy.
Reason: version 2.4.6 receives extended support through August 30, 2027, and receives only limited, isolated security fixes for the core application until May 31, 2028. Version 2.4.7 receives standard support through May 31, 2027, and extended support through May 31, 2028. See Adobe’s Lifecycle Policy.
Reason: No deadline has been set.
Step 2: Determine the upgrade or migration path
If you need to upgrade your Adobe Commerce on Cloud version, then you have two options:
- Upgrade to a supported Adobe Commerce on Cloud version
- Migrate to Adobe Commerce as a Cloud Service (SaaS)
To help you decide the best path, use the following table to compare your options:
Table 4: Adobe Commerce on Cloud compared to Adobe Commerce as a Cloud Service
What happens if no action is taken by the deadline?
Adobe remains committed to helping you take the necessary steps to upgrade to supported versions of Adobe Commerce on Cloud and third-party software.
If an environment has not met the security requirements by the enforcement dates shared above, Adobe will be forced to take appropriate action to guarantee security for the larger install base. This includes suspending traffic to the affected infrastructure, and as a result your ecommerce storefront will go offline.
If an environment continues to remain non-compliant following traffic suspension, Adobe may terminate cloud services, initiating the decommissioning process. As a result of decommissioning, all data and assets within the hosted ecommerce environment, including all instances, environments, and branches, will be permanently deleted and cannot be restored.
Resources to support upgrade or migration
If you choose to upgrade to Adobe Commerce on Cloud version 2.4.9:
-
Upgrade Compatibility Report: Adobe provides a detailed report identifying exactly what your upgrade to Adobe Commerce version 2.4.9 requires, including the cost scope. Generate your Upgrade Compatibility Report.
-
Software dependency upgrade: Since you cannot upgrade software dependencies directly, open a support ticket for Adobe to handle the upgrade for you. For details, see Configure services.
If you choose to migrate to Adobe Commerce as a Cloud Service:
Adobe provides tools that reduce the cost and time of migrating to Adobe Commerce as a Cloud Service. They are available at no cost to you. These tools apply to migration only. They are not used for Adobe Commerce on Cloud version upgrades. See the migration overview for the full migration guide, including migration paths and phases.
-
Migration assessment: Rates the migration complexity of your customizations. See the Migration Assessment Tool overview.
-
Data migration: The bulk and incremental data migration tool moves your data to your new Adobe Commerce as a Cloud Service environment.
-
AI-assisted migration and developer tools: Adobe Developer App Builder and Commerce Storefront powered by Edge Delivery Services help accelerate storefront modernization and extension re-platforming.
If you have questions, get in touch with your account team or contact Support Services.