Magento security patches arrive on a known cadence, fix real vulnerabilities, and still get deferred for months on most stores - usually from fear of breakage, not laziness. A store running unpatched e-commerce software is a breach waiting for a date. The fix is process: a patching rhythm that makes each patch small, tested and routine.
Adobe’s Release Pattern
Adobe ships security fixes two ways:
- Security-only patch releases (e.g. 2.4.7-p3): the security fixes without feature changes - lower risk, designed for fast adoption
- Full patch releases: security plus functional fixes and improvements
For staying current with minimal risk, the security-only line is your friend: track your minor version’s -pN releases promptly, and schedule the minor-version upgrades (2.4.6 to 2.4.7) separately, quarterly.
The Patching SLA That Works
Set expectations as policy, not aspiration:
- Critical/RCE-level patches: applied to staging within days, production within two weeks
- Regular security releases: inside four weeks
- Minor version upgrades: quarterly, absorbing the accumulated patches
The SLA exists so “when do we patch?” is never a fresh decision - decisions made fresh tend to slip.
The Process
- Read the security bulletin: Adobe’s bulletin describes each CVE’s severity and vector - it tells you whether you are being actively targeted class-wide (payment skimming flaws) or carrying theoretical risk
- Staging first: apply, run the smoke suite (checkout, payment, admin), check custom modules against changed classes in the patch notes
- Production in a window: low-traffic period, backup first, cache flush after, smoke test immediately
- Monitor: error logs and order flow for 24 hours
The Objections, Answered
“It might break customisations” - true, which is why staging exists; but the known cost of testing beats the unknown cost of a breach. “We’re too busy” - patching windows are short precisely when patches are small; six months of deferred patches is where the week-long remediations come from. “We have a WAF” - a WAF is a layer, not a substitute; it buys time, not immunity.
The Compounding Argument
Patching discipline is compound interest in reverse: each skipped patch makes the next one bigger and scarier. Quarterly rhythm keeps every patch small enough to be boring. Boring is the goal - the stores that treat security releases as routine maintenance are the ones that never appear in breach notifications.