CVE-2026-75650, a CVSS 10.0 unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source, was exploited from September 4 and…
One flaw, two editions, two answers
| Version | Adobe Commerce | Magento Open Source | End of standard support (Adobe) | End of extended support (Adobe) | EOL Risk Score |
|---|---|---|---|---|---|
| 2.4.9 | Affected, hotfix | Affected, hotfix | May 31, 2029 | TBD | 30 |
| 2.4.8 | Affected, hotfix | Affected, hotfix | May 31, 2028 | TBD | 30 |
| 2.4.7 | Affected, hotfix | Affected, hotfix | May 31, 2027 | May 31, 2028 | 30 |
| 2.4.6 | Affected, hotfix | Affected, hotfix | August 11, 2026 | August 31, 2027 | 55 |
| 2.4.5 | Affected, hotfix (security-only period) | Not listed | August 2025 | August 11, 2026 | 65 |
| 2.4.4 | Affected, hotfix (security-only period) | Not listed | April 2025 | April 14, 2026 | 65 |
What's covered
- One flaw, two editions, two answers
- Why Adobe patched two versions it had stopped supporting
- What CISA's listing means
- What to do this week
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-magento-cve-2026-75650-support-window
Top comments (0)