ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 50

  1. Blog

Next.js 15 LTS ends 21 Oct 2026: upgrade checklist

Next.js 15.x (released 21 Oct 2024) leaves Maintenance LTS on 21 Oct 2026 per nextjs.org/support-policy. Active LTS is 16.x. Points to September 2026 patches 16.3.8 / 15.5.27. No exploit steps; nothing tested; no affiliate.

Aditya Challa·5 October 2026·4 min read

Summary
On this page
  1. Related links
  2. What “Maintenance LTS” means here
  3. Where 15.x stands as of late September 2026
  4. Practical checklist before 21 October
  5. Why ShopperCove is covering this now
  6. Bottom line
  7. Sources

Next.js 15 Maintenance LTS ends 21 Oct 2026: what to check before then

Next.js 15.x is in Maintenance LTS and, under Vercel’s published support policy, each major stays in that phase for two years after its initial release. Version 15.x was released on October 21, 2024, so that window closes on October 21, 2026. ShopperCove did not upgrade or patch a production app for this note. The facts below come from the official Next.js Support Policy, the September 2026 security release, and the community version table at endoflife.date/nextjs, all read on 5 October 2026. This is not a migration runbook and not security-exploit guidance.

There is no affiliate link in this article.

Related links

  • https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
  • https://www.shoppercove.com/blog/nextjs-16-app-router-production-checklist-2026
  • https://www.shoppercove.com/blog/react-19-3-view-transitions-fragment-refs-2026

What “Maintenance LTS” means here

From the support policy:

  • Active LTS (currently 16.x, released Oct. 21, 2025) gets new features, regular bug fixes, performance work, and security patches.
  • Maintenance LTS (currently 15.x, released Oct. 21, 2024) gets only critical bug fixes and essential security updates.
  • Each major remains in Maintenance LTS for two years after the initial release.
  • For Maintenance LTS, updates can land as semver-minor releases even when they include breaking changes.
  • Outside that window, Next.js may still patch in rare, severe cases—but that is the exception, not a plan you should rely on.

So if you are still on 15.x after 21 October 2026, you should assume you are off the normal security-update train unless Vercel says otherwise for a specific emergency.

Where 15.x stands as of late September 2026

The September 2026 security release shipped patches to:

  • v16.3.8 (Active LTS)
  • v15.5.27 (Maintenance LTS)

Vercel’s post lists several CVEs across image optimization SSRF, cache-poisoning paths for self-hosted SSG/ISR, App Router metadata image routes, Cache Components / 'use cache' issues, and a low-severity next dev MCP endpoint issue. The post also states which setups are not affected for some items (for example, no images.remotePatterns for the image SSRF case; Vercel-hosted apps for one cache-poisoning case; Turbopack builds for the metadata dynamicParams issue).

ShopperCove is not reproducing any of those issues. If you run Next.js, read the advisory, match your hosting and router setup to the impact notes, and patch—do not wait for a walkthrough of the bugs.

As of the endoflife.date snapshot updated 1 October 2026, 15.5.27 (30 Sep 2026) is listed as the latest 15.x build, with security support ending 21 Oct 2026.

Practical checklist before 21 October

  1. Confirm your version: npx next --version (or check package.json / lockfile).
  2. If you are on 15.x: plan the move to 16.x Active LTS (policy table names 16.x as Active). Prefer a current patched line such as 16.3.8+ rather than an older 16.x build.
  3. If you must stay on 15.x briefly: at least land 15.5.27 (or newer 15.x if one appears) before the window closes, knowing Maintenance LTS ends on the 21st.
  4. Read the September advisory impact section against your stack: App Router vs Pages Router, self-hosted vs Vercel, webpack vs Turbopack, Cache Components / Draft Mode, and whether images.remotePatterns is set.
  5. Self-hosted operators: pay extra attention to the SSG/ISR cache-poisoning notes in the September post; Vercel’s write-up calls out self-hosted Pages Router SSG/ISR for one medium issue and says applications on Vercel are not affected for that item.
  6. Do not treat canary as production. The support policy says canary is for experimentation, not production traffic.

Why ShopperCove is covering this now

Mid-October is late to discover that a client still ships next@15.4 on a VPS. The policy date is fixed and public. Pair this note with the earlier ShopperCove write-up on the 16.3.8 / 15.5.27 security release if you need the CVE list in one place.

Bottom line

21 October 2026 is the scheduled end of Next.js 15.x Maintenance LTS under the published two-year rule. Active LTS is 16.x. Patch first, then upgrade. Primary wording lives on nextjs.org/support-policy and the September 2026 security release.

Sources

  • https://nextjs.org/support-policy
  • https://nextjs.org/blog/september-2026-security-release
  • https://endoflife.date/nextjs
next.js 15ltssecurity patchmaintenancenext.js 16upgradevercelweb development

Lab evidence

What I found running this

Sources read 5 Oct 2026 via WebFetch: nextjs.org/support-policy, september-2026-security-release, endoflife.date/nextjs. No app upgraded or scanned. Next.js 15.x (released 21 Oct 2024) leaves Maintenance LTS on 21 Oct 2026 per nextjs.org/support-policy. Active LTS is 16.x. Points to September 2026 patches 16.3.8 / 15.5.27. No exploit steps; nothing tested; no affiliate.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 49

    Ready Client Sites: Node.js starter websites for freelancers, not a blank theme

    Node.js niche website packs at $97 or $247, sold through ClickBank. Self-install. ShopperCove did not buy or deploy a pack.

    4 Oct 2026

  • Plate 24

    SvelteKit 3 Is Here (Oct 1, 2026): Migration Checklist for Teams

    3 Oct 2026

  • Plate 63

    TanStack Start XSS: Patch CVE-2026-102989 Now

    TanStack Start CVE-2026-102989: patched versions, lockfile checks, and redeploy steps from the official advisory.

    1 Oct 2026

On this page

  1. Related links
  2. What “Maintenance LTS” means here
  3. Where 15.x stands as of late September 2026
  4. Practical checklist before 21 October
  5. Why ShopperCove is covering this now
  6. Bottom line
  7. Sources
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove