[Adobe Commerce on Cloud only]{class="badge informative" title="Applies to Adobe Commerce on Cloud version 2.4.4 through 2.4.9 only"}

Security and compliance notice: Required actions and deadlines

NOTE
Applies to: Adobe Commerce on Cloud (PaaS) environments running Adobe Commerce versions 2.4.4 through 2.4.9.
This guidance does not apply to Adobe Commerce as a Cloud Service (SaaS) environments or Adobe Commerce on-premises deployments.

The cybersecurity landscape is fundamentally changing, and the defensive mechanisms enterprises have in place need to rapidly evolve. Security is critical for ecommerce businesses because online transactions require them to handle sensitive personal and business data, exposing them to financial and identity risks in the event of a breach. PaaS ecommerce environments have a shared security responsibility model between Adobe and our customers, where customers are responsible for the maintenance of application layer dependencies, integrations with third-party software, and deployment pipelines.

At Adobe, we proactively address the evolving risks and ensure that we set up our Adobe Commerce on Cloud customers to the highest security standards. This includes:

  • Monthly and isolated security fixes for faster and predictable protection against critical vulnerabilities
  • Annual patch releases with long term support
  • Streamlined lifecycle policies for each release with a 3-year support window

While Adobe takes the necessary steps to keep our customers secure, the shared responsibility model for Adobe Commerce on Cloud requires that our customers always be on a supported version of Adobe Commerce on Cloud and third-party software, apply application patches, audit third-party extensions, and secure custom code. Software that has passed end of vendor support no longer receives security patches, leaving security issues in the software unaddressed. Continuing to run your ecommerce storefront on unsupported software creates a real and growing security risk.

This page outlines the actions all customers on Adobe Commerce on Cloud (version 2.4.4 through 2.4.9) need to take to ensure that their ecommerce environments remain secure, along with the enforcement dates, and what to expect when the security requirements are not met.

Actions required to maintain a secure, compliant environment

To keep your ecommerce environment secure and compliant, all customers on Adobe Commerce on Cloud are required to use:

  1. Supported versions of all third-party software dependencies: PHP, MariaDB, Elasticsearch/OpenSearch, Redis, and RabbitMQ

  2. A secure and supported version of Adobe Commerce on Cloud

Follow the guidelines below to check if you need to take action to secure your Adobe Commerce on Cloud environments. Environments that do not meet the security requirements by the deadlines outlined in Table 1 below will have inbound traffic suspended, taking the storefront offline. If you have concerns about meeting the deadline and need a short extension, please contact your account team or Adobe Support.

Table 1: Security requirements and deadlines

Your Adobe Commerce on Cloud version
Upgrade to supported third-party software dependencies
Upgrade to latest Adobe Commerce on Cloud version, or migrate to Adobe Commerce as a Cloud Service
2.4.4 or 2.4.5
Required by October 30, 2026.
Required by June 1, 2027
2.4.6 or 2.4.7
Required by October 30, 2026, or May 31, 2027, depending on the software.
Required by June 1, 2028
2.4.8 or 2.4.9
Required by October 30, 2026, or May 31, 2027, depending on the software.
Not required at this time

Detailed steps to secure your environment

Action 1: Verify and upgrade third-party software dependencies

Check that your environment is running vendor-supported versions of the following third-party software dependencies: PHP, MariaDB, Elasticsearch/OpenSearch, Redis, RabbitMQ. If not, upgrade the software dependency to a supported version.

Step 1: Check your third-party software dependency versions

  1. Sign in to the Cloud Console.
  2. Open the relevant project, then select the environment you want to review.
  3. Check the service configuration for that environment in the .magento/services.yaml file, which defines the supported service names and versions used by Adobe Commerce on Cloud.

For detailed instructions, see Configure Services.

All unsupported software dependencies must be upgraded to the versions outlined by the timelines in Table 2 below.

Table 2: Required dependency upgrades

Dependency
Version
Must upgrade to
Deadline
PHP
8.1 and below
8.2 or higher
May 31, 2027
MariaDB/Galera
10.5 and below
10.6 or higher
October 30, 2026
MariaDB/Galera
Greater than 10.5 but lower than 10.11
Version 10.11 or higher
May 31, 2027
Elasticsearch
any version
OpenSearch: version 2.19 for 2.4.4 and 2.4.5 customers. Version 3 for 2.4.6 and above customers.
October 30, 2026
OpenSearch
1.x
Version 2.19 for 2.4.4 and 2.4.5 customers. Version 3 for 2.4.6 and above customers.
May 31, 2027
Redis
5 and below
Valkey version 8 or higher
May 31, 2027
RabbitMQ
3.9 and below
Version 3.13 or higher
October 30, 2026
RabbitMQ
Greater than 3.9 but lower than 3.13
4.3 or higher
May 31, 2027

Step 2: Prepare for a third-party software dependency upgrade

Adobe will help you upgrade these software dependencies directly.

  • Get started: Open a support ticket listing the environments you need upgraded and the dependencies involved. Open your ticket at least 30 days before your enforcement date so Adobe can schedule the work.

  • Downtime: Adobe confirms the expected window with you when scheduling.

  • Testing: Upgrade and validate a non-production environment before production. At minimum, validate checkout, search, cart, and any custom integrations. Requirements apply to all your environments, so plan to upgrade every environment rather than production alone.

  • Compatibility: Most of these changes are version upgrades within the same software and carry low risk. The following changes warrant closer attention:

    • Elasticsearch to OpenSearch and Redis to Valkey are migrations to different software rather than version upgrades. Custom code, extensions, or configuration referencing the original service may need updating.
    • Upgrading from PHP 8.1 to 8.2 can surface deprecation warnings in custom code and third-party extensions.

If you use third-party extensions, confirm with your vendors that their current releases support your target software versions. If you work with a solution integrator, involve them early in upgrade planning, testing, and validation.

Action 2: Check Commerce on Cloud version and upgrade to a supported version

Check which Adobe Commerce on Cloud version your environments run. If any environment is not on a supported version, you can upgrade to version 2.4.9 or the latest supported version, or migrate to Adobe Commerce as a Cloud Service.

Step 1: Check your Adobe Commerce on Cloud version and required action

  1. Sign in to your Adobe Commerce Admin panel.

    The current version displays in the bottom-right corner of any Admin page.

  2. If the version is hidden from the Admin panel:

Check required actions for your Adobe Commerce version in the table below.

Table 3: Adobe Commerce on Cloud version upgrade requirements

Current version of Adobe Commerce on Cloud
Required action
Deadline
Version 2.4.4 or 2.4.5
Upgrade to Adobe Commerce on Cloud version 2.4.9 (or the latest version) or migrate to Adobe Commerce as a Cloud Service.
Reason: v2.4.4 and 2.4.5 receive only limited, isolated security fixes for the core application until May 31, 2027 — this does not include quality fixes, compatibility support for application dependencies (for example, PHP), or platform dependency updates. See Adobe’s Lifecycle Policy.
June 1, 2027
Version 2.4.6 or 2.4.7
Upgrade to Adobe Commerce on Cloud version 2.4.9 (or the latest version) or migrate to Adobe Commerce as a Cloud Service.
Reason: version 2.4.6 receives extended support through August 30, 2027, and receives only limited, isolated security fixes for the core application until May 31, 2028. Version 2.4.7 receives standard support through May 31, 2027, and extended support through May 31, 2028. See Adobe’s Lifecycle Policy.
June 1, 2028
Version 2.4.8 or 2.4.9
No Adobe Commerce on Cloud version upgrade action is needed. The third-party software dependency deadlines in Action 1 still apply.
Reason: No deadline has been set.
Not required at this time

Step 2: Determine the upgrade or migration path

If you need to upgrade your Adobe Commerce on Cloud version, then you have two options:

  1. Upgrade to a supported Adobe Commerce on Cloud version
  2. Migrate to Adobe Commerce as a Cloud Service (SaaS)

To help you decide the best path, use the following table to compare your options:

Table 4: Adobe Commerce on Cloud compared to Adobe Commerce as a Cloud Service

Adobe Commerce on Cloud version 2.4.9
Adobe Commerce as a Cloud Service
What it is
The latest Adobe Commerce release with full security coverage, quality fixes, and platform dependency updates.
Adobe’s fully managed commerce platform, built for continuous innovation without the upgrade overhead. Learn more.
Best for you if
You want to keep managing your own infrastructure, upgrades, and patches.
You want to leave upgrade cycles behind for good, lower your total cost of ownership, and get Adobe’s newest capabilities automatically, with no extra effort.
Key benefit
Meets the security requirements while preserving your existing setup.
A lightning-fast, edge-delivery storefront, a highly scalable catalog, native digital asset management, and built-in generative AI, all on an infrastructure managed by Adobe.

What happens if no action is taken by the deadline?

Adobe remains committed to helping you take the necessary steps to upgrade to supported versions of Adobe Commerce on Cloud and third-party software.

If an environment has not met the security requirements by the enforcement dates shared above, Adobe will be forced to take appropriate action to guarantee security for the larger install base. This includes suspending traffic to the affected infrastructure, and as a result your ecommerce storefront will go offline.

If an environment continues to remain non-compliant following traffic suspension, Adobe may terminate cloud services, initiating the decommissioning process. As a result of decommissioning, all data and assets within the hosted ecommerce environment, including all instances, environments, and branches, will be permanently deleted and cannot be restored.

Resources to support upgrade or migration

If you choose to upgrade to Adobe Commerce on Cloud version 2.4.9:

  • Upgrade Compatibility Report: Adobe provides a detailed report identifying exactly what your upgrade to Adobe Commerce version 2.4.9 requires, including the cost scope. Generate your Upgrade Compatibility Report.

  • Software dependency upgrade: Since you cannot upgrade software dependencies directly, open a support ticket for Adobe to handle the upgrade for you. For details, see Configure services.

If you choose to migrate to Adobe Commerce as a Cloud Service:

Adobe provides tools that reduce the cost and time of migrating to Adobe Commerce as a Cloud Service. They are available at no cost to you. These tools apply to migration only. They are not used for Adobe Commerce on Cloud version upgrades. See the migration overview for the full migration guide, including migration paths and phases.

  • Migration assessment: Rates the migration complexity of your customizations. See the Migration Assessment Tool overview.

  • Data migration: The bulk and incremental data migration tool moves your data to your new Adobe Commerce as a Cloud Service environment.

  • AI-assisted migration and developer tools: Adobe Developer App Builder and Commerce Storefront powered by Edge Delivery Services help accelerate storefront modernization and extension re-platforming.

If you have questions, get in touch with your account team or contact Support Services.

recommendation-more-help
commerce-operations-help-release