Magento Open Source and Adobe Commerce 2.4.9 were released in May 2026. It is a platform and security release rather than a feature release: newer PHP and Symfony versions, stricter API behaviour, more security hardening for PCI DSS 4.0 and hundreds of fixes. This guide summarises what changed, what it means for your store and how to plan the upgrade.

Always check Adobe's official release notes and system requirements for your exact edition before upgrading. Extension vendors also publish their own 2.4.9 compatibility notes.

Platform Changes

  • PHP 8.5 support — 2.4.9 adds official PHP 8.5 support alongside PHP 8.3 and 8.4.
  • Symfony 7.4 LTS — Symfony components move to 7.4. Custom code that extends Symfony classes, such as console commands, must use the correct typed signatures.
  • Composer 2.4 — supported Composer versions now extend beyond the 2.2 line.
  • Databases and services — check the official requirements for supported MySQL, MariaDB, OpenSearch, Valkey or Redis, and RabbitMQ versions, and align your hosting before the code upgrade.
  • Frontend libraries — several bundled JavaScript libraries were upgraded, including jQuery UI, jQuery Validate, Underscore and Chart.js. Luma customisations that depend on old library behaviour should be tested.

Security and Compliance

  • Admin users only need to configure one of the enabled two-factor authentication providers, simplifying 2FA for teams.
  • The minimum admin password length is configurable, helping stores meet PCI DSS 4.0 password rules.
  • CAPTCHA is enforced for customer account creation through REST and GraphQL, closing a gap used by bots.
  • reCAPTCHA support was added to more GraphQL mutations, including customer updates and the contact form.
  • Subresource Integrity hashes are now stored per area, theme and locale instead of one large file, which matters for multi-theme and multi-language stores.
  • The file upload library (Uppy) was upgraded to address file-handling vulnerabilities.

Behaviour Changes Developers Should Know

ChangeWhat to check
Malformed REST requests now return 400 Bad RequestIntegrations that relied on generic error responses or sent sloppy payloads.
Orders without a billing address are rejectedCustom order creation code, marketplace imports and POS integrations.
Bulk API endpoints require an array bodyMiddleware that posts single objects to bulk endpoints.
Deprecated getEscaper() removedOld templates and blocks; use the $escaper template variable or constructor injection.
Native OAuth replaces a third-party libraryIntegrations using OAuth 1.0a signatures — test them on staging.
Symfony 7.4 type declarationsCustom console commands and classes extending Symfony components.

Support Dates: When Should You Upgrade?

According to Adobe's lifecycle policy for Adobe Commerce:

VersionEnd of standard support
2.4.611 August 2026 (extended support to 31 August 2027)
2.4.731 May 2027
2.4.831 May 2028
2.4.931 May 2029

If you are on 2.4.6 or earlier, upgrade now. If you are on 2.4.7, plan the upgrade within the next few months. Stores on 2.4.8 are supported for longer, but moving to 2.4.9 also brings PHP 8.5 readiness and the latest security work.

Upgrade Checklist

  1. Inventory — list every third-party module and its version, and check vendor compatibility with 2.4.9.
  2. Audit custom code — run PHPStan and the Upgrade Compatibility Tool (Adobe Commerce) or a static analysis pass against 2.4.9.
  3. Prepare infrastructure — PHP 8.3 or 8.4 (or 8.5), supported database, OpenSearch and cache versions on staging.
  4. Update with Composer — change the magento/product-community-edition or magento/product-enterprise-edition constraint and run composer update with all dependencies.
  5. Fix and test — resolve compilation errors, run setup:upgrade, setup:di:compile and static content deploy, then test checkout, payments, integrations and admin flows.
  6. Release — deploy in a low-traffic window with a backup and rollback plan, then monitor logs and conversion.
# Example for Magento Open Source (run on staging first)
composer require-commerce magento/product-community-edition 2.4.9 --no-update
composer update --with-all-dependencies
bin/magento setup:upgrade
bin/magento setup:di:compile
bin/magento setup:static-content:deploy -f
bin/magento cache:flush

The require-commerce command comes from Magento's Composer root update plugin, which also updates related root composer.json entries. If your project does not have it, update the version constraint manually.

Hyvä Stores

If you run Hyvä, update Hyvä Theme and your Hyvä compatibility modules alongside Magento, rebuild the Tailwind CSS with npm run build in your theme's web/tailwind folder, and re-test checkout — particularly if you use Hyvä Checkout with payment provider modules.

Frequently Asked Questions

Is Magento 2.4.9 stable for production?

It is a general-availability release. As with any upgrade, test it thoroughly on staging with your extensions and integrations before going live.

Which PHP version should I use with Magento 2.4.9?

PHP 8.4 is a safe default today. PHP 8.5 is supported, but confirm that all your extensions support it first.

Can I upgrade directly from 2.4.4 or 2.4.5 to 2.4.9?

Yes, you can upgrade directly between 2.4.x versions with Composer, but the bigger the gap, the more compatibility work and testing you should plan for.

🚀

Planning your 2.4.9 upgrade?

We rehearse every upgrade on staging and handle PHP, OpenSearch and extension compatibility.

Magento 2 Upgrade Service
MS
About the author

Written by the Magento Services engineering team — Magento 2, Adobe Commerce and Hyvä specialists since 2014. We write about problems we solve on real client stores.