Umbraco CMS

Umbraco CMS 17 (LTS)

Umbraco CMS 17 (LTS)

Third-party support for the Umbraco CMS 17 (LTS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.

EOSL Date: Nov 27, 2028
Issue Management

24/7 engineers own your Umbraco CMS 17 (LTS) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
umbraco
release
17
product Label
Umbraco CMS
release Label
17 (LTS)
codename
lts
true
latest Version
17.6.2
release Date
2025-11-27
maintained
true
source Url
https://endoflife.date/umbraco

Lifecycle Dates

End of Service Life
Nov 27, 2028
Last OEM Support
Nov 27, 2027

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Umbraco CMS 17 (LTS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Umbraco CMS 17 (LTS)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Umbraco CMS 17 (LTS) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Umbraco CMS 17 (LTS) Support: Frequently Asked Questions

Is the Umbraco CMS 17 (LTS) still supported?

Yes. The Umbraco CMS 17 (LTS) is currently supported by Umbraco CMS, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.

When is the Umbraco CMS 17 (LTS) end of service life (EOSL) date?

Umbraco CMS lists the end of service life for the Umbraco CMS 17 (LTS) as Nov 27, 2028.

Can I keep using the Umbraco CMS 17 (LTS) after its EOSL date?

Yes. EOSL means Umbraco CMS stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Umbraco CMS 17 (LTS) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Umbraco CMS 17 (LTS)

5 published CVEs affect the Umbraco CMS 17 (LTS), including 1 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.

CVESeverityCVSSPublishedSummary
CVE-2026-31834HIGH7.2Mar 10, 2026Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authorization enforcement when modifying user group memberships. The affected functionality does not properly validate whether a user has sufficient privileges to assign highly privileged roles. This vulnerabi
CVE-2026-31833MEDIUM6.7Mar 10, 2026Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Settings can inject malicious HTML into property type descriptions. Due to an overly permissive attributeNameCheck configuration (/.+/) in the UFM DOMPurify instance, event handler attributes such as onclick and onload, when used within Umbraco web components (umb-*, uui-*, ufm-*) were not filtered. This vulnerability is fixed in 16.5.1 and 17.2.2.
CVE-2026-46616MEDIUM5.4Jun 10, 2026Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This issue has been patched in versions 13.14.0 and 17.4.0.
CVE-2026-31832MEDIUM5.4Mar 10, 2026Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability exists in a backoffice API endpoint that allows authenticated users to assign domain-related data to content nodes without proper authorization checks. The issue is caused by insufficient authorization enforcement on the affected API endpoint, whereby via an API call, domains can be set on content nodes that the editor does not have permission to access (either via user group pri
CVE-2026-46609MEDIUM4.6Jun 10, 2026Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
Get Third Party Support

Related Umbraco CMS Products

All Umbraco CMS products →
Umbraco CMS 17 (LTS)
Save 40-70% vs OEM
Get Third Party Support