Drupal 10, Umbraco 13 and Kentico Xperience 13 End of Life: What to Do Before December 2026

Three widely used content management system versions lose support within about three weeks of each other:
- Drupal 10: end of life on 9 December 2026.
- Umbraco 13: end of life on 14 December 2026.
- Kentico Xperience 13: all support, security fixes included, stops from 1 January 2027.
Nothing switches off on those dates. On 10 December a Drupal 10 site serves pages exactly as it did on 8 December, and editors still publish. What stops is the supply of security fixes. From then on, a vulnerability found in your version stays open unless someone closes it for you.
As this is written, on 3 October 2026, there are about ten weeks to the first two dates. That is enough for a well-kept Drupal or Umbraco site. It is not enough for a Kentico 13 rebuild.
Who This Is Really For
The work lands hardest on sites with custom code: custom Drupal modules and themes, custom Umbraco property editors and dashboards, Kentico widgets and integrations, and anything built by an agency that has since moved on.
If your Drupal site is close to a stock install with popular contributed modules, the upgrade is mostly mechanical, and your hosting partner may already have it scheduled. Ask them for the date.
If you run Umbraco 13 and buy extended support (below), December is not a cliff for you. It is a patch cutoff you have paid to postpone.
Drupal 10: Ends 9 December 2026
What ends
The project's own statement is short: "Drupal 10 will reach end of life on December 9, 2026." Drupal 10.6 is the last minor release, and the release schedule says no new releases of Drupal 10 will be made after that date.
In the week of 20 September 2026, drupal.org's usage statistics counted 221,417 sites on Drupal 10 branches against 210,728 on Drupal 11, out of 524,579 reporting. About four in ten reporting Drupal sites have ten weeks left on their current version. Of those, 21,148 are still on Drupal 10.0, 10.1 or 10.2, which means an extra step first.
What the upgrade involves
The official Drupal 10 to 11 upgrade guide breaks down into a handful of jobs:
- Hosting first. Drupal 11 needs PHP 8.3.0 or later. Drupal 10 ran happily on PHP 8.1 and 8.2. PHP 8.1 is already out of support, and security support for PHP 8.2 ends on 31 December 2026. If your server runs either, change PHP first, as its own tested piece of work.
- Get to Drupal 10.3.0 or later. Core updates from before 10.3.0 have been removed in Drupal 11, so a site on 10.2 cannot jump straight across.
- Deal with removed core modules. Actions UI, Activity Tracker, Book, Forum, Statistics and Tour are gone from core in Drupal 11. If you use one, stop using it or switch to its contributed version while still on Drupal 10.3 or later, before the code upgrade.
- Port custom code. The Upgrade Status module shows where your code and your contributed modules are not ready. Drupal Rector rewrites many deprecated API calls automatically; the rest is done by hand. On a site with years of custom modules, this is where the hours go.
- Check every contributed module. Each one needs a Drupal 11 compatible release. Where none exists, the guide points to patches in the module's issue queue or to the Lenient Composer endpoint. Every module carried that way is maintenance you now own.
- Tooling. You need command line access with Composer and Drush, and a record of any customised scaffold files so they survive the upgrade.
Should you wait for Drupal 12?
No. Drupal 12.0.0 is scheduled for the week of 7 December 2026, the same week Drupal 10 security support ends. A .0 release in the week your current version expires is not a plan. Drupal 11.4 keeps receiving security fixes after that week, and 11.5 is released alongside 12.0. Move to 11 now and look at 12 next year.
Umbraco 13: Ends 14 December 2026
What ends
Umbraco 13 is a long term support release. According to Umbraco's support lifecycle page, it has been in its security phase (security fixes only) since 14 December 2025, and it reaches end of life on 14 December 2026, after which Umbraco says it "is no longer recommended".
There is a second date underneath it. Umbraco 13 runs on .NET 8, and Microsoft ends support for .NET 8 on 10 November 2026. The runtime your site depends on loses support a month before the CMS does.
What the upgrade involves
Umbraco's rule is that you move to the nearest long term support version before the latest one. Umbraco 13 is itself an LTS release, so the target is Umbraco 17, the next LTS. It was released on 27 November 2025, enters its security phase on 27 November 2027 and reaches end of life on 27 November 2028. It runs on .NET 10.
The difficult step sits in the middle. Umbraco 14 replaced the editing interface entirely, and the version specific upgrade notes put it in one line: "AngularJS removed: A new backoffice built with Web Components, Lit, and fueled by the Umbraco UI Library."
In practice that means:
- Every backoffice customisation is rewritten. Custom property editors, dashboards, custom sections and the interface parts of packages were AngularJS in Umbraco 13. None of it carries over; it is rebuilt as web components.
- Property editors are split in two, a server part and a client part, which changes how custom ones are structured.
- Some editors are gone. Nested Content, the Grid layout and the legacy Media Picker have been removed. Umbraco recommends Block List or Block Grid in their place. This is a content job as well as a code job: pages built with those editors need their stored content converted.
- Macros are removed. Umbraco points to partial views or blocks in the rich text editor instead.
- XPath is removed, with Dynamic Roots among the replacements.
- Packages need an Umbraco 17 release. An abandoned package means a replacement or a rewrite.
Umbraco's guidance is to upgrade offline, test fully, then run the upgrade on each environment. Bring your editors into testing early: the backoffice they use every day will look and behave differently.
Public-facing templates usually change less than the backoffice, except where they render Nested Content, Grid or macros. Searching your views for those three is a quick first measure of the job.
Buying time: XLTS
Umbraco sells extended long term support (XLTS) for LTS versions from Umbraco 10 onward, 13 included. You choose 6, 12 or 24 months, and coverage starts the day after end of life. It covers security patches only, with a frozen feature set. You buy it from Umbraco (partners go through their partner manager), and the page publishes no price.
XLTS makes sense when the rewrite of custom editors cannot finish properly by 14 December. It makes less sense as a way of postponing the decision, because the rewrite costs the same next year. And it patches Umbraco, not the runtime: .NET 8 support ends either way.
Kentico Xperience 13: Ends 1 January 2027
What ends
Kentico 13 is already on reduced support. Through 2026, Kentico issues releases "only in the form of security hotfixes". Then, per Kentico's support lifecycle: "From January 1, 2027: We will cease all support, maintenance, updates, releases, hotfixes, patches, repairs (including security repairs), and any other services related to Kentico Xperience 13."
No extension is listed. The successor is Xperience by Kentico, which Kentico offers "based on mutually agreed terms". That is a new licence conversation, not a version bump.
What the move involves
Xperience by Kentico is a different product, and the Kentico Migration Tool is honest about its limits: "The tool migrates data models and content only. Code migration is not supported."
What it moves, according to its documentation:
- Page types become content types. Pages become website channel pages or reusable content items.
- Categories become taxonomies.
- Media libraries and their files, Page Builder content and custom page templates (from Kentico 13).
- Editor users and roles, contacts and activities, consents.
- Custom module classes with their data, and custom tables (as module classes or content items).
What it does not move:
- Code and customisations. Controllers, views, widget code, integrations, scheduled tasks. The code that retrieves pages has to be rewritten for content items.
- Form autoresponder and notification emails. These are copied across by hand.
- Marketing automation and static contact groups.
- Macros, which will not work after migration, and page permissions.
- Media held in Azure Blob Storage or Amazon S3. The tool reads media from the local file system only.
Two practical points. The source must be on Kentico 13 Refresh 5 (hotfix 13.0.64) or later, so check that first. And the migration can be run multiple times, with built-in and custom data transformations, so you can rehearse it and refine the mapping before the real cut-over.
Put plainly: the content survives, and the website around it is rebuilt. That is a project of months, and on 3 October there are thirteen weeks to 1 January. Most Kentico 13 sites will run unpatched for a while. Better to plan that period than discover it.
Because the code is rebuilt either way, it is fair to ask whether Xperience by Kentico or another platform fits better. Staying has one clear advantage: a migration tool built for your content model. Make it a decision, not a default.
What Running Unpatched Really Means
The site keeps working. The risk changes shape:
- The next vulnerability stays open. Fixes keep shipping for the supported versions, and their advisories are public. When a flaw fixed in a newer version also exists in yours, the advisory shows attackers where to look.
- The stack ages around the CMS. PHP 8.2 loses security support on 31 December 2026. .NET 8 loses support on 10 November 2026. Contributed modules and packages are likely to stop testing against versions nobody supports.
- The audit answer changes. If your security policy, a cyber insurance questionnaire or a public sector contract asks whether your software is supported, the honest answer becomes no.
If you must run unpatched for a while, reduce exposure: put the admin interface behind a VPN or an IP allowlist, remove unused modules, add a web application firewall, test your backups and read the vendor's advisories for the newer version. These measures shrink the risk. They do not replace patches.
How to Decide
- Drupal 10, mostly contributed modules: upgrade to Drupal 11. Ten weeks is enough if you start this month.
- Drupal 10 with heavy custom code or an old PHP host: fix hosting first, then port the code. If you will overrun, plan a short unpatched window with the hardening above.
- Umbraco 13 with few backoffice customisations: upgrade to Umbraco 17.
- Umbraco 13 with custom editors, Nested Content or Grid: buy XLTS for 6 or 12 months and do the rewrite properly.
- Kentico 13: start the migration project now, harden the current site for January, and decide the destination on its merits.
- A redesign was coming anyway: let end of life be the trigger, and do not port code you are about to throw away. If templates are being rebuilt, that is also the cheapest moment to fix accessibility; our European Accessibility Act guide covers what that means for a website.
A Timeline From Today
By mid October. Inventory each site: exact CMS version, PHP or .NET version, custom modules, editors and widgets, and the compatibility of every contributed module or package. On Drupal, run Upgrade Status. On Kentico, confirm hotfix 13.0.64 or later.
By the end of October. Decide per site: upgrade, buy time or rebuild. If you need XLTS, start the purchase, since cover begins the day after end of life.
November. Drupal: move hosting to PHP 8.3, upgrade on staging, test. Umbraco: move to .NET 10, upgrade a copy, rewrite the custom editors, convert Nested Content and Grid content. Kentico: apply the hardening measures and run a first migration rehearsal.
Late November to early December. Production upgrades, with a buffer before 9 and 14 December. If your organisation freezes changes before the holidays, plan around it.
January 2027. Kentico sites run hardened while the migration continues.
Where to Get Help
We do this kind of work: auditing what is custom on an inherited site, porting Drupal modules, rewriting Umbraco backoffice extensions as web components, and rebuilding the code a migration tool leaves behind. That work sits under our legacy system maintenance service; if a rebuild is on the table, our web accessibility remediation service covers that side.
If one of these dates is yours and you are not sure what is under the hood, write to office@c9group.dev.