Plate 50
Next.js 15 LTS ends 21 Oct 2026: upgrade checklist
Next.js 15.x (released 21 Oct 2024) leaves Maintenance LTS on 21 Oct 2026 per nextjs.org/support-policy. Active LTS is 16.x. Points to September 2026 patches 16.3.8 / 15.5.27. No exploit steps; nothing tested; no affiliate.
Aditya Challa4 min read
Next.js 15 Maintenance LTS ends 21 Oct 2026: what to check before then
Next.js 15.x is in Maintenance LTS and, under Vercel’s published support policy, each major stays in that phase for two years after its initial release. Version 15.x was released on October 21, 2024, so that window closes on October 21, 2026. ShopperCove did not upgrade or patch a production app for this note. The facts below come from the official Next.js Support Policy, the September 2026 security release, and the community version table at endoflife.date/nextjs, all read on 5 October 2026. This is not a migration runbook and not security-exploit guidance.
There is no affiliate link in this article.
Related links
- https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
- https://www.shoppercove.com/blog/nextjs-16-app-router-production-checklist-2026
- https://www.shoppercove.com/blog/react-19-3-view-transitions-fragment-refs-2026
What “Maintenance LTS” means here
From the support policy:
- Active LTS (currently 16.x, released Oct. 21, 2025) gets new features, regular bug fixes, performance work, and security patches.
- Maintenance LTS (currently 15.x, released Oct. 21, 2024) gets only critical bug fixes and essential security updates.
- Each major remains in Maintenance LTS for two years after the initial release.
- For Maintenance LTS, updates can land as semver-minor releases even when they include breaking changes.
- Outside that window, Next.js may still patch in rare, severe cases—but that is the exception, not a plan you should rely on.
So if you are still on 15.x after 21 October 2026, you should assume you are off the normal security-update train unless Vercel says otherwise for a specific emergency.
Where 15.x stands as of late September 2026
The September 2026 security release shipped patches to:
- v16.3.8 (Active LTS)
- v15.5.27 (Maintenance LTS)
Vercel’s post lists several CVEs across image optimization SSRF, cache-poisoning paths for self-hosted SSG/ISR, App Router metadata image routes, Cache Components / 'use cache' issues, and a low-severity next dev MCP endpoint issue. The post also states which setups are not affected for some items (for example, no images.remotePatterns for the image SSRF case; Vercel-hosted apps for one cache-poisoning case; Turbopack builds for the metadata dynamicParams issue).
ShopperCove is not reproducing any of those issues. If you run Next.js, read the advisory, match your hosting and router setup to the impact notes, and patch—do not wait for a walkthrough of the bugs.
As of the endoflife.date snapshot updated 1 October 2026, 15.5.27 (30 Sep 2026) is listed as the latest 15.x build, with security support ending 21 Oct 2026.
Practical checklist before 21 October
- Confirm your version:
npx next --version(or checkpackage.json/ lockfile). - If you are on 15.x: plan the move to 16.x Active LTS (policy table names 16.x as Active). Prefer a current patched line such as 16.3.8+ rather than an older 16.x build.
- If you must stay on 15.x briefly: at least land 15.5.27 (or newer 15.x if one appears) before the window closes, knowing Maintenance LTS ends on the 21st.
- Read the September advisory impact section against your stack: App Router vs Pages Router, self-hosted vs Vercel, webpack vs Turbopack, Cache Components / Draft Mode, and whether
images.remotePatternsis set. - Self-hosted operators: pay extra attention to the SSG/ISR cache-poisoning notes in the September post; Vercel’s write-up calls out self-hosted Pages Router SSG/ISR for one medium issue and says applications on Vercel are not affected for that item.
- Do not treat canary as production. The support policy says canary is for experimentation, not production traffic.
Why ShopperCove is covering this now
Mid-October is late to discover that a client still ships next@15.4 on a VPS. The policy date is fixed and public. Pair this note with the earlier ShopperCove write-up on the 16.3.8 / 15.5.27 security release if you need the CVE list in one place.
Bottom line
21 October 2026 is the scheduled end of Next.js 15.x Maintenance LTS under the published two-year rule. Active LTS is 16.x. Patch first, then upgrade. Primary wording lives on nextjs.org/support-policy and the September 2026 security release.
Sources
Lab evidence
What I found running this
Sources read 5 Oct 2026 via WebFetch: nextjs.org/support-policy, september-2026-security-release, endoflife.date/nextjs. No app upgraded or scanned. Next.js 15.x (released 21 Oct 2024) leaves Maintenance LTS on 21 Oct 2026 per nextjs.org/support-policy. Active LTS is 16.x. Points to September 2026 patches 16.3.8 / 15.5.27. No exploit steps; nothing tested; no affiliate.
Related links
Plate 49
Ready Client Sites: Node.js starter websites for freelancers, not a blank theme
Node.js niche website packs at $97 or $247, sold through ClickBank. Self-install. ShopperCove did not buy or deploy a pack.
4 Oct 2026
Plate 24
SvelteKit 3 Is Here (Oct 1, 2026): Migration Checklist for Teams
3 Oct 2026
Plate 63
TanStack Start XSS: Patch CVE-2026-102989 Now
TanStack Start CVE-2026-102989: patched versions, lockfile checks, and redeploy steps from the official advisory.
1 Oct 2026