Skip to content
PHP 8.6 Reaches Release Candidate as PHP 8.2 Nears End of Security Support
  Posted on 03 Oct, 2026
  Tech News

On September 24, 2026, the PHP team published PHP 8.6.0 RC2, the first release candidate of the next PHP version, with general availability targeted for November 19, 2026. At the same time, PHP 8.2 is in its final months: php.net lists its security support as ending on December 31, 2026. If your business runs a PHP or Laravel application, the urgent item is not adopting 8.6 but getting off 8.2 before the end of the year.

What was announced

The PHP team's announcement of September 24, 2026 made PHP 8.6.0 RC2 available for testing. According to that announcement, RC1 was skipped because of a mistake made while packaging it, so the release candidate series starts at RC2. The same announcement says the next build, RC3, is planned for October 8, 2026, and asks people not to run this version in production.

The PHP 8.6 release timetable on the PHP wiki lists further release candidates on October 22 and November 5, 2026, and general availability on November 19, 2026. The wiki notes that individual releases may be added or removed as development progresses, so treat November 19 as a target, not a guarantee.

On the same day, php.net published security releases for every supported branch: PHP 8.5.11, 8.4.26, 8.3.35 and 8.2.34, each described in the php.net 2026 news archive as a security release that users of that branch are encouraged to install.

Key details

Status of each item as of October 4, 2026:

  • Released and available now: PHP 8.5, 8.4, 8.3 and 8.2 with their September 24, 2026 security updates; Laravel 13 and Laravel 12.
  • Preview, not for production: PHP 8.6.0 RC2.
  • Announced with a future date: PHP 8.6 general availability (target November 19, 2026); end of PHP 8.2 security support (December 31, 2026).

The PHP project's supported versions page explains the policy: each branch gets two years of active support, then two more years of fixes for critical security issues only. The dates below come from that page.

PHP branchActive support untilSecurity support untilPosition on October 4, 2026
8.2December 31, 2024December 31, 2026Security fixes only, under three months left
8.3December 31, 2025December 31, 2027Security fixes only
8.4December 31, 2026December 31, 2028Active support, moving to security only at year end
8.5December 31, 2027December 31, 2029Active support
8.6Not yet releasedNot yet releasedRelease candidate, testing only

For Laravel applications, the framework version matters as much as the PHP version. The Laravel 13 release notes give this support policy:

Laravel versionPHP versions supportedBug fixes untilSecurity fixes until
118.2 to 8.4September 3, 2025March 12, 2026 (ended)
128.2 to 8.5August 13, 2026 (ended)February 24, 2027
138.3 to 8.5Q3 2027March 17, 2028

Two points stand out in that table. Laravel 12 stopped receiving bug fixes on August 13, 2026 and is now in its security-only period. And as of October 4, 2026, the table does not list PHP 8.6 for any Laravel version, which is expected while 8.6 is still a release candidate.

What this means for your business

This section is our practical interpretation of the dates above.

PHP 8.2 is the deadline that matters

After December 31, 2026, a vulnerability discovered in PHP 8.2 will not be patched by the PHP project. The php.net page on unsupported branches strongly urges users of end-of-life versions to upgrade because older versions may leave them exposed to security vulnerabilities and bugs fixed in newer releases. Beyond the direct risk, running unsupported software can raise questions in security questionnaires, penetration tests and compliance reviews in both the US and the UK. What your specific obligations are depends on your contracts and sector, so check with your own advisers.

Laravel 11 and 12 owners have a second clock running

A Laravel 11 application has been without framework security fixes since March 12, 2026. A Laravel 12 application has them until February 24, 2027. An application on Laravel 11 and PHP 8.2 therefore needs both a framework and a language upgrade, and it makes sense to plan them together. Laravel states in its release notes that it tries to keep major upgrades to a day or less of work, but the real effort depends on your third-party packages, how much custom code touches framework internals, and how good your automated test coverage is.

PHP 8.6 is something to test, not deploy

The UPGRADING notes shipped with RC2 list backward incompatible changes alongside new features. One example worth knowing about: the notes describe stricter default values for several session cookie settings. A release candidate can still change before the final release, so these notes are a preview, not a final list. For most businesses the sensible position is to let your developers run the test suite against 8.6 in a non-production environment and wait for your framework, packages and hosting provider to confirm support before scheduling a move.

Which version should you target?

Your current setupReasonable target before December 31, 2026
PHP 8.2 with Laravel 11Laravel 12 or 13 on PHP 8.4 or 8.5
PHP 8.2 with Laravel 12PHP 8.4 or 8.5 now; plan Laravel 13 before February 24, 2027
PHP 8.3 with Laravel 12 or 13No year-end deadline; apply the September 24 security release and plan a move to 8.4 or 8.5 during 2027
PHP 8.1 or olderAlready unsupported; treat as a priority project
Plain PHP or another framework on 8.2PHP 8.4 or 8.5, after checking each dependency's supported versions

What to do now

  • Ask your developer or hosting provider which PHP version and which Laravel version your production application runs. Get the exact numbers in writing.
  • Confirm the September 24, 2026 security release for your branch (8.2.34, 8.3.35, 8.4.26 or 8.5.11) has been installed.
  • If you are on PHP 8.2, schedule the upgrade so it is tested and live before December 31, 2026. Allow for the holiday code freeze many companies apply in December.
  • Check that every third-party package and any payment, shipping or CRM integration supports the target PHP version.
  • Run the upgrade in a staging environment with your automated tests first, and have a rollback plan.
  • Add PHP and Laravel end-of-support dates to your maintenance calendar so the next deadline is not a surprise.

For technical readers

The RC2 UPGRADING file is the place to start an 8.6 compatibility check. Run your CI pipeline against the release candidate with deprecations reported, and file anything that looks like a regression on the php-src issue tracker, as the announcement requests. Keep 8.6 out of your production Composer platform requirements until your dependencies declare support.

Frequently asked questions

Will my application stop working on January 1, 2027 if it runs PHP 8.2?

No. End of security support means the PHP project stops issuing fixes for that branch, not that the software switches off. The application keeps running, but newly discovered vulnerabilities in PHP 8.2 will remain unpatched by the PHP project. Some hosting providers also retire old versions on their own schedules, so ask yours.

Should we skip straight to PHP 8.6?

Not for a year-end deadline. PHP 8.6 is a release candidate that the PHP team says should not be used in production, its final release is targeted for November 19, 2026, and Laravel's support table does not yet list it. PHP 8.4 or 8.5 gives you security support until the end of 2028 or 2029 respectively.

Do we have to upgrade Laravel at the same time as PHP?

It depends on the version. Laravel 12 supports PHP 8.2 to 8.5, so a Laravel 12 application can move to a newer PHP version without a framework upgrade. Laravel 11 supports up to PHP 8.4 but no longer receives security fixes, so a framework upgrade is advisable anyway. Laravel 13 requires PHP 8.3 or later.

Conclusion

PHP 8.6 entering its release candidate phase on September 24, 2026 is a useful signal that the yearly PHP cycle is turning over, and with it PHP 8.2 leaves security support on December 31, 2026. Find out what your application runs, apply the latest security release, and get an 8.2 upgrade tested before year end. If your application was built by a team that is no longer available, our guide to outsourcing software development from the US and UK covers how to evaluate a new partner, and if you would like a second opinion on an upgrade plan, Entrant Technologies offers Laravel development services and you can contact us to talk it through.

Post Written by
"Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations."
Latest Blogs
 
If you ask three vendors what it costs to build an AI agent, you will probably get three figures that are far apart, and none of them will be wrong. They are pricing different things: a different scop ...
on 03 Oct, 2026 Read More
 
Most people have been stuck with a bad support bot: it misreads the question, repeats the same help article, and hides the route to a person. The bots people dislike usually fail for design reasons, n ...
on 03 Oct, 2026 Read More
 
Most software projects now include an API, whether or not anyone asked for one by name. Your mobile app needs it to talk to your servers. Your accounting system needs it to receive orders. A partner w ...
on 03 Oct, 2026 Read More