Next.js 15 has been in Maintenance LTS since Next.js 16 shipped on October 21, 2025. Under Vercel's support policy, each major stays in Maintenance LTS for two years after its initial release. That clock runs out on October 21, 2026 — twelve days from today. After that date, the project no longer promises critical bug fixes or security updates for the 15.x line. That deadline matters more this month because the September 2026 security release already shipped fixes that many production apps still need. The patched floors are clear: 15.5.27 for Maintenance LTS and 16.3.8 for Active LTS. If you are still on anything older in either line, you are behind the published advisories before you even discuss the LTS cliff.
What Maintenance LTS ending actually means
During Maintenance LTS, Next.js commits only to critical bug fixes and essential security updates. After October 21, 2026, 15.x moves into the unsupported set alongside 14.x and earlier. Unsupported does not mean your app stops running. It means the next image SSRF, cache poisoning, or Draft Mode leak may never get an official 15.x patch. For B2B SaaS that sells security reviews and SOC 2 evidence, that is an unacceptable dependency posture.
The September/October advisory set you must close first
The September 2026 security release (with postponed fixes that landed afterward) covers several issues you should inventory by deployment shape: Image Optimization SSRF (High) — CVE-2026-94483 / GHSA-cjq9-62q9-8jv4. An attacker-controlled allow-listed remote URL can reach private IP ranges during image optimization. If you never configured images.remotePatterns , you are not affected by this path. If you did, tighten patterns and patch. SSG/ISR cache poisoning (Medium) — GHSA-4jqv-mc3x-m676 / CVE-2026-94543. Self-hosted Pages Router apps using SSG or ISR can have a cache entry replaced with content from a different route. Vercel-hosted apps are called out as not affected. Self-hosted teams must patch and review CDN/cache keys. Draft Mode + pending use cache fill (Medium) — CVE-2026-94544 / GHSA-3w37-wq28-93x7. Pending cache fills shared across Draft Mode and regular requests can leak unpublished content into regular responses and persisted pages when Cache Components (or experimental.useCache ) is enabled. Metadata image dynamicParams bypass (Medium) — CVE-2026-94485. App Router metadata image routes built with webpack can ignore dynamicParams , exposing segments you meant to exclude from generateStaticParams() . Turbopack builds are not affected. Related advisories in the same wave cover root catch-all cache poisoning and nested use cache root-param keying. Read the official blog post once with your platform owners in the room; do not rely on a dependency bot summary.
A two-week plan that finishes before October 21
Day 0–1: inventory. List every Next.js service by major/minor, hosting (Vercel vs self-hosted), router (App vs Pages), whether Image Optimization is on, whether Draft Mode and Cache Components are enabled, and who owns the deploy. Day 1–3: patch floor. Move every 15.x production app to 15.5.27 (or jump straight to 16.3.8 if the upgrade is already staged). Rebuild images, regenerate lockfiles, and deploy through the normal pipeline. Day 3–10: Active LTS migration for anything that will still run after October 21. Maintenance LTS ending is not a suggestion to linger on 15.5.27 forever. Use the patched 15 line only as a bridge if you need days, not months. Day 10–12: verify. Confirm remotePatterns, Draft Mode preview auth, metadata routes, and cache headers. Re-run security regression tests that cover unauthenticated cache busting and draft preview isolation.
# Confirm installed next versions across the monorepo
npm ls next --all
# Patch floor for remaining 15.x apps
npm install next@15.5.27
# Active LTS target
npm install next@16.3.8
# After deploy, grep config for risk flags
rg -n "remotePatterns|draftMode|use cache|dynamicParams|images" next.config.* app/ pages/Self-hosted vs Vercel changes your urgency queue
If you self-host behind a CDN, prioritize the SSG/ISR poisoning advisories and any shared response cache in front of Next.js. If you are on Vercel, still patch for Image Optimization, Draft Mode leaks, and metadata routes — the hosting carve-outs in the advisories are specific, not universal. Either way, pin versions explicitly. Floating next@15 ranges are how teams discover they never landed 15.5.27.
Founder takeaway
October 21, 2026 is a calendar fact, not a marketing date. Patch every production Next.js app to at least 15.5.27 this week, schedule Active LTS 16.3.8 before the Maintenance window closes, and walk the September advisory list against your actual deployment shape. Teams that treat LTS end-of-life as optional end up explaining unpatched CVEs in customer security questionnaires.
How to talk about this with customers and auditors
Security questionnaires increasingly ask whether dependencies are within vendor support windows. Answering "we are on Next.js 15" after October 21, 2026 without a documented exception will fail diligence at some buyers. Prepare a one-page note that lists current versions, the 15.5.27 / 16.3.8 floors, the September advisory IDs you closed, and your Active LTS migration date. Share it with customer success before someone asks in a deal room. Internally, add a CI check that fails when next resolves below your floor, and a calendar reminder two weeks before any future Maintenance LTS end date. The expensive part of this cycle is not the npm install — it is discovering the cliff during an incident or a procurement block.
If you maintain marketing sites and product apps on different majors, do not let the brochure site lag. Attackers do not only target authenticated APIs; cache poisoning and image SSRF land on public surfaces too. Align both to patched floors even if the marketing site "rarely changes."




