Quoting our contribution guidelines, which are maybe not the best place to store this:
In general, we do not pursue security fixes for major versions ofCyrus over three years old. There may be exceptions to this, but generally youshould try to run a recent stable release.
Cyrus v2.4.0 was released 13 years ago. It will not be receiving updates.
I believe you should be able to upgrade to v3.0 directly, and then to a recent release going version by version.
--
rjbs