PHP 8.6 RC3 Is Out, PHP 8.2 Ends Dec 31: Check Your Site

The PHP team released PHP 8.6.0 RC3 on October 8, 2026, with the final version planned for November 19. Six weeks after that, on December 31, PHP 8.2 stops receiving security fixes. Any site running WordPress, Drupal or other PHP software is affected, and checking your version takes a minute.

What we know

  • RC3: php.net announced PHP 8.6.0 RC3 on October 8, 2026. It is a test build: the announcement asks people not to run it in production.
  • What is left: RC4 is planned for October 22, according to that announcement. The PHP wiki timetable adds RC5 on November 5 and the general release on November 19, 2026. The announcement calls the schedule a rough outline, so dates can move.
  • RC1 never shipped: a packaging mistake meant RC2 went out in its place on September 24, according to that day's announcement.
  • PHP 8.2 is ending: php.net's supported-versions table puts the end of its security support on December 31, 2026. After that the branch is unsupported.
  • PHP 8.4 changes phase: its active support ends the same day. Until December 31, 2028 it gets critical security fixes only.
  • The other branches: PHP 8.3 has security fixes until December 31, 2027 and PHP 8.5 until December 31, 2029, per the same table. PHP 8.1 reached end of life on December 31, 2025.
  • What 8.6 changes for websites: the RC3 upgrade notes switch three session defaults to secure values: session.use_strict_mode and session.cookie_httponly become 1, and session.cookie_samesite becomes "Lax". They also deprecate several MySQLi functions and list backward-incompatible changes across 25 sections, the core plus 24 extensions, by this article's count.
  • How many sites are behind: WordPress.org's usage statistics, checked on October 10, 2026, show 24.60% of WordPress sites on PHP 8.2 and another 35.67% on PHP 8.1 or older, versions that are already unsupported. The second figure is this article's sum.

What changes and what doesn't

Nothing changes on your site today. RC3 is for testing, not for a production server.

The date that matters is the end of PHP 8.2. From January 1, 2027, a security flaw found in that branch will no longer get an official fix. The site keeps working, but its exposure grows every month. php.net tells users of unsupported releases to upgrade as soon as they can.

There is no need to jump to PHP 8.6 in November either. WordPress's compatibility table stops at PHP 8.5 and has no 8.6 column yet. Drupal's table marks no release as compatible with 8.6 and points to a tracking issue.

The cautious target today is PHP 8.3 or 8.4. WordPress recommends PHP 8.3 or greater. Drupal 11 supports 8.3 and 8.4 in all four releases in its table (11.1 to 11.4), and Drupal 10 (10.4 to 10.6) supports 8.1 through 8.4. PHP 8.4 leaves more room: it is patched until the end of 2028, a year longer than 8.3.

How to tell if it affects you

  1. Check which PHP version your site runs. In WordPress: Tools → Site Health → Info → Server. In Drupal: Reports → Status report. Many hosting panels show it in a PHP version selector.
  2. If you see 8.1 or lower, your site already runs without official PHP patches. Some hosts and Linux distributions backport fixes to older versions: ask yours.
  3. If you see 8.2, you have 82 days from today, October 10, until December 31. The count is this article's.
  4. Update everything else first. WordPress or Drupal core, then plugins or modules, then the theme. An abandoned plugin is usually the first thing to break on a newer PHP version.
  5. Test on a copy. If your host offers a staging environment, switch the version there and walk through the key pages: forms, checkout and login. If it does not, take a backup and switch during a quiet hour. In the following days, watch the crawl stats report in Search Console for server errors.
  6. On shared hosting, ask your provider: "Which PHP versions do you offer today, how long will you keep PHP 8.2, and when will PHP 8.6 be available?"
  7. If your site is custom-built, ask whoever maintains it to read the upgrade notes before moving to 8.6. Per those notes, an application that relies on the session cookie arriving with cross-site POST submissions will have to adjust session.cookie_samesite.

Dates for the calendar: October 22 (RC4), November 5 (RC5), November 19 (PHP 8.6, if the timetable holds) and December 31, 2026 (end of PHP 8.2 and of active support for PHP 8.4).

Related: Let's Encrypt Cuts Certificates to 64 Days: What to Check

Sources

Updates: this note will add the actual PHP 8.6 release date if the timetable changes, and whatever WordPress and Drupal publish about their compatibility with that version.