Umbraco CMS 17 (LTS)
Umbraco CMS 17 (LTS)
Third-party support for the Umbraco CMS 17 (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Umbraco CMS 17 (LTS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- umbraco
- release
- 17
- product Label
- Umbraco CMS
- release Label
- 17 (LTS)
- codename
- lts
- true
- latest Version
- 17.6.2
- release Date
- 2025-11-27
- maintained
- true
- source Url
- https://endoflife.date/umbraco
Lifecycle Dates
- End of Service Life
- Nov 27, 2028
- Last OEM Support
- Nov 27, 2027
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Umbraco CMS 17 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Umbraco CMS 17 (LTS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Umbraco CMS 17 (LTS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Umbraco CMS 17 (LTS) Support: Frequently Asked Questions
Is the Umbraco CMS 17 (LTS) still supported?
Yes. The Umbraco CMS 17 (LTS) is currently supported by Umbraco CMS, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Umbraco CMS 17 (LTS) end of service life (EOSL) date?
Umbraco CMS lists the end of service life for the Umbraco CMS 17 (LTS) as Nov 27, 2028.
Can I keep using the Umbraco CMS 17 (LTS) after its EOSL date?
Yes. EOSL means Umbraco CMS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Umbraco CMS 17 (LTS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Umbraco CMS 17 (LTS)
5 published CVEs affect the Umbraco CMS 17 (LTS), including 1 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2026-31834 | HIGH | 7.2 | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authorization enforcement when modifying user group memberships. The affected functionality does not properly validate whether a user has sufficient privileges to assign highly privileged roles. This vulnerabi |
| CVE-2026-31833 | MEDIUM | 6.7 | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler attributes such as onclick and onload, when used within Umbraco web components (umb-*, uui-*, ufm-*) were not filtered. This vulnerability is fixed in 16.5.1 and 17.2.2. |
| CVE-2026-46616 | MEDIUM | 5.4 | Jun 10, 2026 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This issue has been patched in versions 13.14.0 and 17.4.0. |
| CVE-2026-31832 | MEDIUM | 5.4 | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endpoint that allows authenticated users to assign domain-related data to content nodes without proper authorization checks. The issue is caused by insufficient authorization enforcement on the affected API endpoint, whereby via an API call, domains can be set on content nodes that the editor does not have permission to access (either via user group pri |
| CVE-2026-46609 | MEDIUM | 4.6 | Jun 10, 2026 | Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0. |