Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
IT Security NachrichtenBetrüger phishen mit vermeintlicher Reisebestätigung - IT-Markt(24.09.2026 um 23:41 Uhr)
••
Sicherheitslücken (CVE)IT Security News Daily Summary 2026-09-24(24.09.2026 um 23:55 Uhr)
•
Sicherheitslücken (CVE)IT Security News Roundup: 2026-09-24(24.09.2026 um 23:57 Uhr)
•
Sicherheitslücken (CVE)IT Security News Hourly Summary 2026-09-25 00h : 9 posts(25.09.2026 um 00:00 Uhr)
•••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
•••
IT Security NachrichtenBetrüger phishen mit vermeintlicher Reisebestätigung - IT-Markt(24.09.2026 um 23:41 Uhr)
••
Sicherheitslücken (CVE)IT Security News Daily Summary 2026-09-24(24.09.2026 um 23:55 Uhr)
•
Sicherheitslücken (CVE)IT Security News Roundup: 2026-09-24(24.09.2026 um 23:57 Uhr)
•
Sicherheitslücken (CVE)IT Security News Hourly Summary 2026-09-25 00h : 9 posts(25.09.2026 um 00:00 Uhr)
•••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Adobe Commerce 2.4.7 EOL: the upgrade notice lists 2 options. There are 4.

If you run Adobe Commerce on Cloud and got the end-of-life notice for 2.4.7, here's the short version: the upgrade enforcement date is June 1, 2028. After that, Adobe stops maintaining Cloud environments still on 2.4.7 and reserves the…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

If you run Adobe Commerce on Cloud and got the end-of-life notice for 2.4.7, here's the short version: the upgrade enforcement date is June 1, 2028. After that, Adobe stops maintaining Cloud environments still on 2.4.7 and reserves the right to decommission them.



Per Adobe's published lifecycle table, the 2.4.7 timeline is:
























Milestone Date
End of standard support May 31, 2027
End of extended support May 31, 2028
Cloud upgrade enforcement June 1, 2028


The notice is real. But it quietly narrows your options to two when there are four.






Why the deadline exists (and it's a good reason)



2.4.7 runs on PHP 8.2. PHP 8.2 reaches end of life on December 31, 2026 — after that the PHP project ships no more security patches for it. Adobe hosts the infrastructure, so Adobe owns its PCI compliance. Running an EOL PHP runtime on a payment-handling store is a PCI DSS problem, not just a hygiene one. That's the actual logic behind enforcement, not pure commercial pressure.






The four paths



Adobe officially lists two:





  1. Upgrade to the latest Adobe Commerce on Cloud — 2.4.8 (supported to May 2028) or 2.4.9


  2. Migrate to Adobe Commerce as a Cloud Service — SaaS, fully managed, no future enforcement deadlines



Two more exist outside Adobe's scope, fully compatible with the same Magento 2 core, with no license fee:





  1. Magento Open Source 2.4.9 — same core, self-hosted, $0 license


  2. Mage-OS 3.x — community-governed fork, $0 license, ships security patches on a faster community cadence



Adobe's notice will never mention 3 and 4. That doesn't make them less viable.






What changes with each






































Path License Hosting Recurring enforcement?
Adobe Commerce on Cloud Revenue-based (~$40K–$190K+/yr) Adobe-managed Yes
Adobe Commerce Cloud Service SaaS subscription Adobe full-stack No
Magento Open Source 2.4.9 $0 Your own No
Mage-OS 3.x $0 Your own No


All four require the same infrastructure work: 2.4.8/2.4.9 need PHP 8.3+ and OpenSearch 2.19 (Elasticsearch is deprecated). That work happens regardless of path.






The license math



Adobe Commerce is revenue-participation — the bill scales with GMV automatically:




  • Under $1M GMV → ~$40K/yr on Cloud

  • $1M–$5M GMV → ~$55K–80K/yr on Cloud

  • $5M–$25M GMV → up to ~$190K/yr on Cloud



For a $3M GMV store moving to Magento Open Source or Mage-OS, the license line goes to zero. Over three years the difference comfortably exceeds $150K.



(Figures are independent third-party estimates; Adobe doesn't publish official pricing.)






What actually transfers



Because Adobe Commerce and Magento Open Source share the same Magento 2 core, moving between them is not a replatform. The CLI commands are identical, every Marketplace extension installs the same way, and theme/catalog/checkout logic carries over.



What needs planning when you drop the Adobe commercial layer:





  • Native B2B suite — company accounts, shared catalogs, quote-to-order need extensions or custom dev


  • Live Search / Sensei — replaceable with OpenSearch + best-of-breed tools


  • PHP & search engine upgrade — required on all paths anyway






The Mage-OS detail worth knowing



A common stale claim is "Mage-OS only has 2.3 with PHP 8.5." That's already outdated. Mage-OS 3.0 and 3.1 are out, built on Magento Open Source 2.4.9, with PHP 8.5 support alongside 8.3 and 8.4.



One gotcha most write-ups miss: Mage-OS 3 dropped PHP 8.2 support — minimum is now PHP 8.3 (8.4 recommended), and Symfony moved 6.4 → 7.4 LTS, so extensions that extend Symfony CLI command classes may need updates. Worth scoping before you commit.



Fresh install is one command:




composer create-project --repository-url=https://repo.mage-os.org/ \
mage-os/project-community-edition






For an existing Magento 2.4.8+ store, Mage-OS ships an automated migration script (run it in developer mode on staging first). Mage-OS also publishes security updates within days of Adobe's monthly Patch Tuesday, rather than waiting on Adobe's quarterly cadence.






A worked $4M GMV migration



Typical mid-market project:




  • Platform: Adobe Commerce on Cloud 2.4.7 → Magento Open Source 2.4.9 + Hyvä

  • Duration: ~6 weeks (audit, migration, QA, staged cutover)

  • License savings: ~$72K/year

  • Hosting cost reduction: ~38% vs Adobe Cloud

  • Checkout downtime: none via staged cutover



The heaviest lift is not the platform swap — it's replacing Adobe-specific features (B2B workflows, Live Search) and modernising the infra stack.






Who should stay on Adobe Commerce



This isn't anti-Adobe. Stay if you're:





  • Large enterprise B2B relying on native company accounts, shared catalogs, quote-to-order


  • A team that needs Adobe SLAs for procurement or compliance


  • Deep in Adobe Experience Cloud — Analytics, Target, Real-Time CDP


  • High-GMV where Live Search + managed cloud measurably beat the license fee in conversion lift



For those, Options 1 or 2 are rational. The license only looks expensive when you're not using what it buys.






While the stack is open: AI crawler access



One efficiency note, since a 2.4.7 migration means re-deploying robots.txt, schema, and frontend templates anyway. A default Magento 2 install — any edition — blocks AI crawlers in robots.txt, has no llms.txt, and ships incomplete Product JSON-LD. That means it's effectively invisible to ChatGPT, Gemini, and Perplexity, even if it ranks #1 on Google. The fixes touch the same files you're already editing. There's an open-source CLI to check where a store stands if you want to fold it into the same project. Optional, unrelated to the lifecycle decision — just cheaper to do once.






The clock



June 1, 2028 sounds far away. A properly scoped mid-market migration runs 6–10 weeks. The decision comes down to one question: do you need Adobe's commercial layer enough to justify a fee that scales with revenue? If yes → Option 1 or 2. If no → 3 or 4.



Full breakdown of all four paths with a feature matrix and FAQ: angeo.dev/adobe-commerce-2-4-7-end-of-life-options/






Lifecycle dates from Adobe's published policy. License figures are independent third-party estimates — Adobe doesn't publish official pricing. Verify against the Adobe Commerce lifecycle policy and request a direct quote before budget decisions.

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - Adobe Commerce 2.4.7 EOL: the upgrade notice lists 2 options. There are 4.
id: ae41bde8-dfbd-4559-8f53-8c1f14044684
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "Adobe Commerce 2.4.7 EOL: the " ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Adobe Commerce 247 EOL the upgrade notic")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Adobe Commerce 247 EOL the upgrade notic*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Adobe Commerce 247 EOL the upgrade notic"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Adobe Commerce 2.4.7 EOL: the upgrade no.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Adobe Commerce 2.4.7 EOL: the upgrade notice lists 2 options. There are 4.

Thematisch verwandte Begriffe: Adobe, Commerce, upgrade, notice · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-87722 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search q…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle