Release date, end-of-life schedule and full PHP, MySQL, OpenSearch and Redis system requirements for Adobe Commerce 2.4.8-p4.
Adobe Commerce 2.4.8-p4 was released on .
Its end of life is .
Its current support status is supported.
Release date
Mar 10, 2026
End of life
Apr 11, 2028
Status
supported
Distribution
Adobe Commerce
2.4.8-p5 is the current release of the
2.4.8 line, published on
May 12, 2026. Requirements below are the ones documented for
2.4.8-p4 — for the stack to deploy today, see
Adobe Commerce 2.4.8-p5.
Improper input validation in the Web API's service input processor (CVE-2025-54236), publicly known as SessionReaper. An unauthenticated attacker can hijack customer sessions through the REST API and, depending on configuration, reach remote code execution. Adobe shipped the out-of-band hotfix VULN-32437 before the regular patch release; it was the first emergency patch since CosmicSting.
Improper access control (CVE-2025-49557) and related flaws that let an attacker bypass security features and reach functionality that should require authorization. Shipped with the regular August 2025 patch set for the 2.4.4 to 2.4.8 lines.
Stored cross-site scripting in the admin panel (CVE-2025-47110) that can be chained into arbitrary code execution when an administrator views the injected content. Fixed in the June 2025 patch set, including 2.4.8-p1.
Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.