Statamic 5 security countdown: fixes stop in December 2026
Just a heads up Statamic's support policy lists December 2026 as the last month of security fixes for Statamic 5. After December, the only way to keep getting updates is to move to Statamic 6.
After December 2026, any new vulnerability found in Statamic 5 stays unfixed.
Where Statamic 5 sites stand today
If your site is on Statamic 5 and running anything below 5.74.3, it has at least two known vulnerabilities: the two that 5.74.3 fixed, both rated moderate.
moderateFront-end forms ignored the file types allowed on their upload fields. A visitor could upload types you'd meant to block, though Statamic still blocked dangerous ones such as .php. (CVE-2026-71434)moderateThe default form notification email printed what people typed as raw HTML, the code web pages are made of. Anyone submitting a form could add their own HTML to the email your team receives. (CVE-2026-71435)
Sites further behind have more, and some are more serious. One rated high let an attacker sign in as an existing user, even a super admin, without their password. It only affected sites that let people sign in with an outside account (OAuth) from a provider that doesn't verify email addresses. Statamic 5 fixed it in 5.74.1. (CVE-2026-64665)
The latest release, 5.74.4, came out on 12 August. It has no known security issues.
What changes after December
Your site won't stop working when the fixes end. What changes is that a new vulnerability in Statamic 5 won't be fixed.
Attackers don't wait long, either. The security firm Mandiant found that the average time from a fix coming out to a flaw being exploited fell from 63 days in 2018 and 2019 to five days in 2023.
Statamic 3 and 4 are already past this point. Their security fixes stopped in 2024. Many advisories published since then list every earlier version as affected, and there's no fixed release of 3 or 4 to update to. This isn't unique to Statamic, all Content Management Systems have a cut of date for supporting older versions.
If you're website is on an unsupported version of Statamic, upgrading to the latest version should be considered a priority.
How many sites are still on Statamic 5?
In the last full week of Packagist data, 21 to 27 September, Statamic 5 made up 19% of all Statamic installs. Of those, 59% were on a release below 5.74.3.
Packagist is the public registry Statamic is installed from. It counts installs and deploys, not websites, so read those figures as a rough guide. I checked the advisories against the Open Source Vulnerabilities database (OSV) on 2 October 2026.
How to check your Statamic version
There are two ways to find it.
In the Control Panel (CP), open Tools > Updates. Statamic's entry there shows the release you're running as its Current Version.
On the server, run
php please --versionin the site's folder. It prints a line such asStatamic 5.74.4.
What to do before December 2026
Update to 5.74.4 now. It stays within Statamic 5, so it's a smaller job than an upgrade, and it closes every known issue.
Plan the move to Statamic 6. A Statamic upgrade takes your site from Statamic 5 to the current release. Doing it before December means there's no gap in security fixes.
Keep it updated afterwards. Statamic 6 has a new release most weeks, and being on version 6 isn't enough on its own.
If you're not sure where your site stands, install Sentinel. It's a free Statamic addon that checks Statamic and the hundreds of packages it relies on against public advisories, flags versions that are out of date, and emails you a status report.
Once you're on Statamic 6, my website maintenance plan keeps it updated every month, with a report after each update showing what changed.
You might also like...
- Darkroom: a Statamic AI image generator for Nano Banana
- Tracer 2.0: my Statamic UTM builder gets site-wide settings
- Statamic 6 security: being on version 6 isn't enough
- Sentinel 2.3.0: faster scans for my Statamic security addon
- Warming Statamic static cache behind basic auth
- Over 250 installs on: Sentinel and CMS security for Statamic
- Statamic background recache smooths out bulk cache invalidations
- What a software supply chain attack means for your Statamic website
- A 7-day cooldown against npm supply-chain attacks
- Browser console errors: when the noise hides the signal