Magento and Adobe Commerce

Enterprise software, without the enterprise team

Adobe’s own requirements for running a Magento store list seven separate services, each with a supported version to track and patch1. That is not a flaw. It is what the platform is: a system built for merchants with an operations team, being run by a great many businesses that do not have one.

The licence is free, which is how most small stores end up here. Everything after the licence is where the money and the risk actually live.

What it takes to run

Seven services to keep one shop open

Required for version 2.4.9, as Adobe lists them1. Each has its own release cycle and its own end-of-life dates, independent of Magento’s.

PHP 8.5
Runs the application
MariaDB or MySQL 12.3 / 8.4
Stores everything
OpenSearch 3
Powers catalogue search
Valkey 9
Cache and sessions
RabbitMQ 4.3
Message queue
nginx 1.30
Web server
Varnish 8
Page cache

Shopify requires none of them. That is the entire trade: a monthly fee against a stack somebody has to own. For a merchant with a platform team that trade is often worth making, because the stack is also where the flexibility comes from. For a merchant without one, it is a bill that arrives as an emergency.

What it takes to keep safe

Two incidents, and what each one actually showed

A large self-hosted PHP application that takes card payments is a target in a way a hosted platform is not. These are the two clearest recent examples rather than a general warning.

10.0

September 2026 — StyleSmuggler

An unauthenticated remote code execution flaw scoring the maximum on the severity scale, affecting every supported version including the newest. Exploited from 4 September; Adobe shipped a fix on the 7th. Three days with no patch available2.

The detail that matters: Sansec documented a store running 2.4.6-p15 — current patches applied — being successfully breached. Being up to date was not a defence2.

1 in 20

2024 — CosmicSting

Roughly five percent of all Adobe Commerce and Magento stores ended up with a payment skimmer on their checkout page. 4,275 breached stores, seven competing threat groups, some victims hit by three at once3.

A week after the fix shipped, three quarters of stores had still not applied it4. That number is the real finding: the patch existed and most merchants had nobody to apply it.

In fairness to Adobe, the September fix landed in about seventy-two hours, which is fast for a flaw of that severity. The problem this leaves a small merchant is not Adobe’s responsiveness. It is that staying safe requires somebody who reads security advisories and can apply a composer patch and redeploy the same day, including at a weekend. That is a role, and most small stores have quietly decided not to fill it.

What it takes to stay current

Find your version in this table

Every release has a date after which it stops receiving security fixes. If you do not know which version you are on, finding out is the most useful thing you can do this week.

Magento 2.4.5 and earlierEnded
Magento 2.4.6Ended 11 August 2026
Magento 2.4.731 May 2027
Magento 2.4.831 May 2028
Magento 2.4.931 May 2029

Dates from the published lifecycle5. Two things follow. Anything at 2.4.6 or below is receiving no security fixes today, which is a decision being made by default rather than on purpose. And every supported version has a cliff a year or two out, so a Magento store is permanently partway through an upgrade project — each one a proper piece of work with extension compatibility to check, not a button to press.

Which is why the base keeps shrinking

Live Magento storefronts fell about 14% over a year to roughly 102,000, down from a peak near 162,000 in late 2021 — a contraction of about a third. Over a recent ninety-day window 1,128 stores arrived and 1,824 left6.

Where they went is the interesting part. The largest group moved to custom-built carts and Shopify was second, which is what you would expect if the merchants leaving are the ones who concluded they were running more platform than they needed. The stores that remain skew towards the businesses Magento was designed for in the first place.

Against this argument

When Magento is the right answer

You have the team, and you use the power. Complex B2B pricing, multiple storefronts off one catalogue, deep ERP integration, rules Shopify cannot express without an app for each one. Magento does these properly and Shopify does some of them awkwardly. If that describes you, the stack is the price of capability you are actually using.

Adobe is responsive, and the community is active. The September zero-day was patched in roughly seventy-two hours. Independent developers backported the fix to dozens of older releases within days. This is not a neglected platform and nothing on this page should be read as saying it is.

You have real money in custom modules. Extensions written against Magento’s APIs do not port, so a heavily customised store is paying to rebuild logic it already owns. Where that investment is large and still earning, staying and upgrading is usually the cheaper path.

The honest trigger for moving is narrow: you are running enterprise software on a small-business budget, nobody owns the security question, and you are not using the capability you are paying for in complexity. If two of those three are true, it is worth doing the arithmetic.

If you do move

Five things a Magento store carries

The catalogue moves; the attribute model needs deciding

Magento's EAV model lets a catalogue carry attribute sets, custom attributes and configurable products with far more structure than Shopify's variants. Most of it maps. The part that does not is where someone has to decide what the data was actually for, and that conversation is the migration.

Extensions do not come with you

Every module installed over the years is PHP written against Magento's APIs, and none of it ports. The useful exercise before quoting anything is listing what is installed and marking each one: replaced by a Shopify app, replaced by something native, or genuinely lost. That list is usually shorter than people fear.

Customer accounts survive, passwords do not

Records, addresses and order history export cleanly. Password hashes do not move between platforms, so every customer resets on first login. Ordinary, and worth a well-written email before launch rather than a support queue after it.

The URL structure is unusually worth crawling

Magento sites accumulate layered-navigation URLs, category paths, and often several years of rewrites in the url_rewrite table. A redirect map built from an export misses what Google actually holds; one built from a crawl does not.

You will stop paying for infrastructure

The hosting, the managed services, the monitoring and whoever applies the patches all stop being line items. For most small Magento stores that saving is the largest single number in the comparison, and it is worth working out before deciding anything.

The method is the crawl, redirect map and rebuild set out on the migration page, and what the destination involves is on the Shopify page.

The other way to run a store on your own server is WooCommerce, which trades Magento’s required services for a plugin layer that has to be maintained instead. That comparison is on the WooCommerce page. And if you landed on Magento after outgrowing a hosted platform that then moved upmarket itself, that is the same story one rung down, on the BigCommerce page.

Worth asking

Questions from people mid-decision

The licence is free; the platform is not. Adobe's own requirements list seven services you must run and keep current — PHP, a database, OpenSearch, Valkey, RabbitMQ, a web server and Varnish — which in practice means managed hosting and somebody technical on call. Add security patching that cannot wait for a convenient week, and an upgrade project every year or two. Shopify's monthly fee replaces all of it. For a small store the comparison is rarely close, and it is worth doing with your real numbers rather than taking either vendor's word.

Same codebase, different support. Adobe Commerce is the licensed product with a support contract, extended security patches and cloud infrastructure; Magento Open Source is the free edition without any of that. The distinction matters most in an emergency: when the September 2026 zero-day was patched, the Adobe Commerce hotfix covered versions 2.4.4 and up while the Open Source hotfix started at 2.4.6. If you are unsure which you have, you are almost certainly on Open Source.

It is a large, self-hosted PHP application with a payments function, which makes it a target in a way hosted platforms are not. Two data points rather than an opinion. In September 2026 a CVSS 10.0 remote code execution flaw was exploited for three days before a patch existed, and Sansec documented a store running the current patch level being breached anyway. In 2024, CosmicSting left 75% of stores unpatched a week after the fix shipped, and roughly one store in twenty ended up with a payment skimmer on its checkout. Adobe patches quickly when it can; the exposure is structural rather than negligent.

You should, and it is not sufficient. The September 2026 case is the clearest illustration: a store on 2.4.6-p15 with current patches was compromised, because the flaw was unknown when the patch level was set. Staying safe on this platform means somebody watching security bulletins, able to apply a composer patch and redeploy within hours of an advisory, on a weekend if that is when it lands. That is a real job. If nobody currently has it, that is the finding.

Yes, on net. Live Magento stores fell about 14% year over year to roughly 102,000, down from a peak near 162,000 in late 2021. Over a recent ninety-day window 1,128 stores arrived and 1,824 left. The largest group of leavers went to custom-built carts, with Shopify second. That is a platform consolidating around the larger merchants it was designed for, which is the whole argument of this page rather than a scare story.

Six to twelve weeks is typical, and the variable is the catalogue rather than the design — attribute sets, configurable products and whatever the extensions were doing. Cost sits in the $5,000 to $15,000 Shopify range for a straightforward store, more where there is real B2B logic or an ERP in the loop. Nothing is quoted before the store has been crawled and the extension list looked at.

Sources

The evidence behind this page

Requirements and support dates are Adobe’s. The two vulnerabilities are documented by Sansec, who found and disclosed them — not by anyone selling migrations. Where a number could only be had second hand, it is not on this page.

  1. 1
    Adobe Commerce system requirements

    Adobe · Current documentation, version 2.4.9 · The vendor's own list of required services and versions

  2. 2
    StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack

    Sansec · 5 September 2026 · Security research; Sansec discovered and disclosed the vulnerability

  3. 3
    Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns

    Sansec · 1 October 2024 · 4,275 breached stores across seven threat groups

  4. 4
    CosmicSting attack threatens 75% of Adobe Commerce stores

    Sansec · 2024 · Patch adoption measured across the installed base

  5. 5
    Magento release and support lifecycle

    endoflife.date · Checked September 2026 · Release and security-support dates per version

  6. 6
    The state of Magento

    Store Leads · Updated 18 September 2026 · Independent tracking of live storefronts and platform switching

Version requirements and support dates move with each release, and the security picture changes weekly. Everything above was read off the linked pages in September 2026. The September zero-day described here has been patched; check the links before treating any of it as current.

Work out what staying actually costs

Send your store URL, your Magento version, and what you pay for hosting and developer time in a normal year. You will get back the two numbers side by side — including when staying is the cheaper one.