Why Teams Should Plan Their Upgrade Now
Your Umbraco 13 site has a December 2026 problem.
Stakeholders may say, "Our Umbraco site is on 13, it's an LTS (Long Term Support) release, we'll deal with the upgrade next year."
That’s a fair instinct. LTS sounds stable. The site is loading, editors are publishing, nobody is screaming, and there is always something more urgent on the board. Why panic about a date that's seven months out?
The catch is that "Long-Term Support" and "supported forever" are not the same thing.
But “Long-Term Support” and “supported forever” are not the same thing.
Umbraco 13 reaches the end of life on December 14, 2026. After that date, Umbraco 13 is no longer supported under the standard lifecycle. . That means no more security patches, no standard bug fixes and no more "Umbraco HQ has us covered." Worse yet, , you´ll be running an unsupported content management system (CMS) in production, and that's a position no marketing director, security lead, or finance owner wants to defend in a meeting.
The deadline isn't a surprise either. Umbraco 13 shipped as an LTS release back in late 2023, and the official LTS/EOL schedule has had December 2026 pinned to it from day one. What's changed in 2026 is the runway. Roughly seven months left. Enough to plan and execute a clean Umbraco Version Upgrade, but only if you start now.
What "end of life" actually means
End of life is not a server shutdown.
Your Umbraco 13 site will keep running on 15 December 2026 exactly the way it ran the day before.
The problem is what disappears behind the scenes.
Once Umbraco 13 reaches EOL, the standard support pipeline ends. In practical terms, that means:
- No more security advisories. Umbraco shipped two CMS-wide security patches in the last twelve months alone, one in June 2025 and another in December 2025. After December 2026 that pipeline closes for v13. New CVEs in shared dependencies (and there will be some) won't get backported.
- No more bug fixes. If a regression, compatibility issue, or platform problem affects a v13 installation after EOL, the answer is unlikely to be “wait for a patch.” The answer becomes “upgrade.”
- No more compatibility guarantees. Umbraco 13 is tied to .NET 8. As the broader .NET and hosting ecosystem moves forward, older runtime versions become harder to support cleanly. Cloud providers, hosting partners, deployment pipelines, and third-party packages eventually shift toward newer versions.
That is why EOL is not a cliff. It is more like a slow leak. The site may keep running, but the longer it stays on an unsupported version, the more operational risk builds around it.
Why This Is Not Just a Developer Issue
It is easy to treat an Umbraco 13 upgrade as a purely technical task. Developers will need to do the work, but the risk does not stay inside the codebase.
Once a CMS version reaches end of life, the issue starts showing up in other places: security reviews, compliance conversations, hosting decisions, campaign planning, vendor assessments, and budget discussions.
For marketing leaders, this can affect how confidently the team can launch new campaigns or make improvements to the website. For IT and security teams, it affects whether the platform can be defended as part of a supported technology stack. For finance and operations leaders, it affects whether the organization is planning ahead or waiting until the work becomes more expensive under pressure.
That is the real problem with waiting.
The upgrade itself may be manageable. The rushed upgrade, the audit finding, the emergency budget request, or the forced migration window is what makes the situation harder.
The security and compliance bill
Security teams have been making this argument for a decade. It's worth saying again because this is the part that gets sites breached. Arroact's 2026 vulnerabilities review puts it plainly: running an outdated Umbraco install is one of the most widespread and dangerous security postures out there, because the vulnerabilities are publicly documented and exploitable in minutes.
Once a CMS goes out of support, attackers don't need zero-days. They've got a published CVE list, a known-vulnerable version banner returned by the server, and a public release that fixed the issue in a version you are not running. That's the easiest reconnaissance in the business.
For regulated industries, the picture sharpens. Umbraco's own Compliance FAQ lay out where Umbraco fits in PCI, GDPR, ISO 27001, and similar frameworks. Most of those frameworks include a single-line clause that is poison for unsupported software: systems must receive timely security updates from the vendor. After December 14, 2026, that is not something you can credibly claim about Umbraco 13.
If your site processes payments, handles personal data, or sits inside a controls audit, "we're on the EOL version" turns a routine review into a finding. That's a cost, sometimes a contractual one, that lands well before any actual breach. In that context, the upgrade is not just about getting new editor features. It is about keeping a defensible answer when someone asks, “Is this platform still supported?”
The XLTS escape hatch
There is a fallback. Umbraco offers Extended Long-term Support (XLTS) for v13, and the official XLTS page pitches it as continued access to critical security patches and compliance assurance for teams that can't make the deadline.
It works. It is also not a strategy.
XLTS is priced as a sales conversation, not a published rate, which means you're absorbing a recurring line item that didn't exist on your roadmap a year ago. And you're paying it to not get the new stuff: the load-balanced backoffice, the timezone-aware scheduling, the WCAG-improved editor, the .NET 10 runtime that the rest of the Umbraco world is already using. Every month you spend on XLTS is a month your editorial team falls further behind a CMS that is, today, actively shipping. The 17.4.0 release candidate landed at the end of April 2026 with 75 issues closed.
Treat XLTS as a parachute, not a plan. Buy it if a Q4 cutover is genuinely impossible. Don't buy it because nobody got around to scoping the upgrade.
What to do this week
If you've read this far and your site is on v13, three actions land before the next sprint planning:
- Confirm your version. Check your `.csproj` and confirm whether you're on 13.x and which patch level. The specific version determines your migration path.
- Inventory your custom code. Backoffice extensions, custom property editors, Delivery API integrations, and any AngularJS-era frontend bits in the admin UI. Those are the items that need work, not the content itself.
- Block out the calendar. A clean 13 to 17 upgrade is a project, not a ticket. The official LTS guidance confirms a one-year overlap of v13 and v17 support, which is generous, but only if you start while there's runway left.
In other words, December 2026 isn't the date your site breaks. It's the date your safety net gets cut. The site will keep running. What goes away is the patch pipeline, the audit-friendly answer, and the chance to do this upgrade on your own schedule.
Next post in this series: why v17 is worth the effort, not just the upgrade you have to do.
Ready to talk about your Umbraco website?
If you are running an older Umbraco version and this all feels a bit close to home, you are not alone. The important thing is to move from “we know we should do something” to a concrete plan.