On September 24, 2026, the PHP team published PHP 8.6.0 RC2, the first release candidate of the next PHP version, with general availability targeted for November 19, 2026. At the same time, PHP 8.2 is in its final months: php.net lists its security support as ending on December 31, 2026. If your business runs a PHP or Laravel application, the urgent item is not adopting 8.6 but getting off 8.2 before the end of the year.
What was announced
The PHP team's announcement of September 24, 2026 made PHP 8.6.0 RC2 available for testing. According to that announcement, RC1 was skipped because of a mistake made while packaging it, so the release candidate series starts at RC2. The same announcement says the next build, RC3, is planned for October 8, 2026, and asks people not to run this version in production.
The PHP 8.6 release timetable on the PHP wiki lists further release candidates on October 22 and November 5, 2026, and general availability on November 19, 2026. The wiki notes that individual releases may be added or removed as development progresses, so treat November 19 as a target, not a guarantee.
On the same day, php.net published security releases for every supported branch: PHP 8.5.11, 8.4.26, 8.3.35 and 8.2.34, each described in the php.net 2026 news archive as a security release that users of that branch are encouraged to install.
Key details
Status of each item as of October 4, 2026:
- Released and available now: PHP 8.5, 8.4, 8.3 and 8.2 with their September 24, 2026 security updates; Laravel 13 and Laravel 12.
- Preview, not for production: PHP 8.6.0 RC2.
- Announced with a future date: PHP 8.6 general availability (target November 19, 2026); end of PHP 8.2 security support (December 31, 2026).
The PHP project's supported versions page explains the policy: each branch gets two years of active support, then two more years of fixes for critical security issues only. The dates below come from that page.
| PHP branch | Active support until | Security support until | Position on October 4, 2026 |
|---|---|---|---|
| 8.2 | December 31, 2024 | December 31, 2026 | Security fixes only, under three months left |
| 8.3 | December 31, 2025 | December 31, 2027 | Security fixes only |
| 8.4 | December 31, 2026 | December 31, 2028 | Active support, moving to security only at year end |
| 8.5 | December 31, 2027 | December 31, 2029 | Active support |
| 8.6 | Not yet released | Not yet released | Release candidate, testing only |
For Laravel applications, the framework version matters as much as the PHP version. The Laravel 13 release notes give this support policy:
| Laravel version | PHP versions supported | Bug fixes until | Security fixes until |
|---|---|---|---|
| 11 | 8.2 to 8.4 | September 3, 2025 | March 12, 2026 (ended) |
| 12 | 8.2 to 8.5 | August 13, 2026 (ended) | February 24, 2027 |
| 13 | 8.3 to 8.5 | Q3 2027 | March 17, 2028 |
Two points stand out in that table. Laravel 12 stopped receiving bug fixes on August 13, 2026 and is now in its security-only period. And as of October 4, 2026, the table does not list PHP 8.6 for any Laravel version, which is expected while 8.6 is still a release candidate.
What this means for your business
This section is our practical interpretation of the dates above.
PHP 8.2 is the deadline that matters
After December 31, 2026, a vulnerability discovered in PHP 8.2 will not be patched by the PHP project. The php.net page on unsupported branches strongly urges users of end-of-life versions to upgrade because older versions may leave them exposed to security vulnerabilities and bugs fixed in newer releases. Beyond the direct risk, running unsupported software can raise questions in security questionnaires, penetration tests and compliance reviews in both the US and the UK. What your specific obligations are depends on your contracts and sector, so check with your own advisers.
Laravel 11 and 12 owners have a second clock running
A Laravel 11 application has been without framework security fixes since March 12, 2026. A Laravel 12 application has them until February 24, 2027. An application on Laravel 11 and PHP 8.2 therefore needs both a framework and a language upgrade, and it makes sense to plan them together. Laravel states in its release notes that it tries to keep major upgrades to a day or less of work, but the real effort depends on your third-party packages, how much custom code touches framework internals, and how good your automated test coverage is.
PHP 8.6 is something to test, not deploy
The UPGRADING notes shipped with RC2 list backward incompatible changes alongside new features. One example worth knowing about: the notes describe stricter default values for several session cookie settings. A release candidate can still change before the final release, so these notes are a preview, not a final list. For most businesses the sensible position is to let your developers run the test suite against 8.6 in a non-production environment and wait for your framework, packages and hosting provider to confirm support before scheduling a move.
Which version should you target?
| Your current setup | Reasonable target before December 31, 2026 |
|---|---|
| PHP 8.2 with Laravel 11 | Laravel 12 or 13 on PHP 8.4 or 8.5 |
| PHP 8.2 with Laravel 12 | PHP 8.4 or 8.5 now; plan Laravel 13 before February 24, 2027 |
| PHP 8.3 with Laravel 12 or 13 | No year-end deadline; apply the September 24 security release and plan a move to 8.4 or 8.5 during 2027 |
| PHP 8.1 or older | Already unsupported; treat as a priority project |
| Plain PHP or another framework on 8.2 | PHP 8.4 or 8.5, after checking each dependency's supported versions |
What to do now
- Ask your developer or hosting provider which PHP version and which Laravel version your production application runs. Get the exact numbers in writing.
- Confirm the September 24, 2026 security release for your branch (8.2.34, 8.3.35, 8.4.26 or 8.5.11) has been installed.
- If you are on PHP 8.2, schedule the upgrade so it is tested and live before December 31, 2026. Allow for the holiday code freeze many companies apply in December.
- Check that every third-party package and any payment, shipping or CRM integration supports the target PHP version.
- Run the upgrade in a staging environment with your automated tests first, and have a rollback plan.
- Add PHP and Laravel end-of-support dates to your maintenance calendar so the next deadline is not a surprise.
For technical readers
The RC2 UPGRADING file is the place to start an 8.6 compatibility check. Run your CI pipeline against the release candidate with deprecations reported, and file anything that looks like a regression on the php-src issue tracker, as the announcement requests. Keep 8.6 out of your production Composer platform requirements until your dependencies declare support.
Frequently asked questions
Will my application stop working on January 1, 2027 if it runs PHP 8.2?
No. End of security support means the PHP project stops issuing fixes for that branch, not that the software switches off. The application keeps running, but newly discovered vulnerabilities in PHP 8.2 will remain unpatched by the PHP project. Some hosting providers also retire old versions on their own schedules, so ask yours.
Should we skip straight to PHP 8.6?
Not for a year-end deadline. PHP 8.6 is a release candidate that the PHP team says should not be used in production, its final release is targeted for November 19, 2026, and Laravel's support table does not yet list it. PHP 8.4 or 8.5 gives you security support until the end of 2028 or 2029 respectively.
Do we have to upgrade Laravel at the same time as PHP?
It depends on the version. Laravel 12 supports PHP 8.2 to 8.5, so a Laravel 12 application can move to a newer PHP version without a framework upgrade. Laravel 11 supports up to PHP 8.4 but no longer receives security fixes, so a framework upgrade is advisable anyway. Laravel 13 requires PHP 8.3 or later.
Conclusion
PHP 8.6 entering its release candidate phase on September 24, 2026 is a useful signal that the yearly PHP cycle is turning over, and with it PHP 8.2 leaves security support on December 31, 2026. Find out what your application runs, apply the latest security release, and get an 8.2 upgrade tested before year end. If your application was built by a team that is no longer available, our guide to outsourcing software development from the US and UK covers how to evaluate a new partner, and if you would like a second opinion on an upgrade plan, Entrant Technologies offers Laravel development services and you can contact us to talk it through.