Skip to main content

Pantheon release notes

Your destination for staying informed about our latest innovations and product updates.
Subscribe to RSS feed

Action required
October 6, 2026

The latest security release for WordPress, 7.1.3, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.3 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has deployed a platform-wide mitigation (virtual patching via our routing network) against external abuse of the stored XSS on the Comments administration page, and is actively monitoring that rule. However, customers need to update their sites as soon as possible.

Highlights

This release resolves seven security vulnerabilities:

  • A stored XSS on the Comments administration page, exploitable via pending comments.
  • A DoS issue in the WP_Http::make_absolute_url() method.
  • A second-order SQL injection in WordPress WXR export.
  • A weakness allowing Author role users to sticky posts.
  • Unauthenticated disclosure of comments on private and unpublished posts.
  • Imgur embeds are vulnerable to XSS.
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision.

For full details, see the WordPress 7.1.3 release notes and WordPress documentation.

October 2, 2026

The 1.34.0 update is now available for the WordPress (composer managed) upstream. This update changes the default PHP version to 8.3, syncs the upstream with Roots Bedrock, and fixes a PHP warning. The Bedrock sync changes the Composer repository defaults, which can cause merge conflicts in your composer.json file.

Updates

  • Updates the default PHP version to 8.3 and changes the PHP requirement in composer.json to >=8.3. For more information about the PHP default change, see New default PHP version 8.3 for WordPress upstreams. (For more information see #204.)
  • Syncs the upstream with Bedrock. (For more information see #201.) This includes:
    • Changing the Composer repository from WPackagist (wpackagist.org) to WP Packages (repo.wp-packages.org). Package names for plugins and themes change from wpackagist-plugin/* and wpackagist-theme/* to wp-plugin/* and wp-theme/*.
    • Removing the roots/wp-password-bcrypt package from composer.json.
    • Setting WP_ENVIRONMENT_TYPE from WP_ENV when it is not already defined, and setting WP_DEVELOPMENT_MODE when it is configured.
    • Setting MYSQL_CLIENT_FLAGS to use SSL when DB_SSL is set.

Bug fixes

  • Resolves a rtrim() warning in PHP 8.1 and later environments. (For more information see #189. Props @mattmacneil.)

For more details, refer to the WordPress (Composer Managed) changelog.

Action required

To benefit from these updates and ensure your site is using the most current version, apply the update to your WordPress (composer managed) site or custom upstream.

If your composer.json file requires plugins or themes using wpackagist-plugin/* or wpackagist-theme/* package names, or has custom entries in repositories, applying this update can cause merge conflicts in that file. When you resolve the conflicts, keep your custom requirements and update the package names to the new wp-plugin/* and wp-theme/* names, or keep the WPackagist repository entry.

For assistance with managing merge conflicts, refer to our documentation on auto-resolving via the dashboard or manually resolving via the command line.

October 2, 2026

Pantheon has updated the default PHP version for the WordPress and WordPress (composer managed) upstreams to PHP 8.3, replacing the previous default of PHP 8.2.

New sites created from these upstreams use PHP 8.3. Existing sites that do not set php_version in their own pantheon.yml move to PHP 8.3 when they apply this upstream update.

Action required

Test the update before you deploy it to the Live environment. Apply it in Dev or a Multidev environment, confirm your plugins and theme work on PHP 8.3, then promote it.

If your site needs to stay on PHP 8.2, pin the version by setting php_version: 8.2 in your site's pantheon.yml before you apply the update. For steps, see Manage PHP Versions.

If you maintain a custom upstream, this change is not reflected in your pantheon.upstream.yml unless you update your fork from Pantheon's upstream.

September 30, 2026

PHP 8.1 has reached End of Sale on the Pantheon platform. Newly created sites after September 30 2026 will no longer be able set their PHP version to 8.1.

Sites already running PHP 8.1 continue to run. They keep receiving LTS security coverage through PHP Runtime Generation 2, with no action required. A removal date for PHP 8.1 has not been set, and Pantheon guarantees at least 90 days of advance notice before removing any PHP version from the platform.

Action required

If you maintain a custom upstream that sets php_version: 8.1 in pantheon.upstream.yml, update it to a supported version. New sites created from that upstream may otherwise behave unexpectedly on creation.

If your site runs PHP 8.1, plan an upgrade to a recommended PHP version. Pantheon recommends PHP 8.3 or 8.4 for all production sites. For steps, see Upgrade PHP Versions.

September 30, 2026

Pantheon is beginning the phased migration of Advanced Global CDN (AGCDN) to our next-generation edge platform. Starting September 30, 2026, AGCDN customers whose current configuration is fully supported in Phase 1 are eligible to migrate. Pantheon will contact eligible customers directly.

What's included

Once your migration is complete, you control your edge settings yourself in the Pantheon Dashboard. Changes no longer require a request to Pantheon. Phase 1 controls are configured at the workspace level, apply to every site and environment in the workspace, and are enforced at the edge before requests reach your site.

  • IP and CIDR blocking
  • Geo blocking
  • ASN blocking
  • Enterprise WAF
  • Image Optimization

How migration works

This migration is not self-serve. Pantheon's Professional Service will:

  1. Review your current Legacy AGCDN configuration and confirm feature support with current capabilities on NextGen.
  2. Migrate your supported rules and configuration.
  3. Make the migrated configuration available for you to review.
  4. Coordinate the DNS cutover with you during an agreed change window.
  5. Validate the configuration after cutover.

Action required

If you are eligible for Phase 1, you will receive an email. Respond to the ticket to confirm your technical contact so we can schedule your migration.

AGCDN customers who are not contacted for Phase 1 don't need to do anything at this time, and will be contacted at a later date.

Learn more about our switch to Next-generation GCDN with bot protection in this related blog post.

September 29, 2026

Pantheon is announcing that, as of December 31, 2026, PHP version 7.4 will enter End of Sale. As a result, no new sites can be created with this version after that date.

What happens to existing sites when a PHP version reaches End of Sale?

Existing sites running an end-of-sale PHP version will not be affected. Pantheon will continue to apply security patches for PHP 7.4 where available for the duration of End of Sale.

What to expect going forward

In the future, we expect to transition PHP 7.4 to End of Support status. When this happens, this version will no longer be supported by PHP maintainers, nor will Pantheon provide ongoing updates from our contracted vendors. Customers will assume additional security risk by staying on these versions. Pantheon commits to providing at least 90 days advance notice to customers before transitioning a version of PHP to End of Support.

Action required

If your site is running PHP 7.4, we encourage you to upgrade it to a current PHP version. We recommend PHP 8.3 or 8.4 for all production sites.

For guidance on upgrading, refer to Upgrade PHP Versions.

September 22, 2026

The latest security release for WordPress, 7.1.2, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.2 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of this vulnerability (CVE-2026-87902), and is actively monitoring those rules. However, customers need to update their sites as soon as possible.

Highlights

This release resolves one critical severity vulnerability (CVE-2026-87902) that does not require authentication to exploit. Under certain server and theme conditions, an unauthenticated attacker can cause page template resolution to include a chosen readable local PHP file outside the active theme directories, which could potentially lead to remote code execution.

For full details, see the WordPress 7.1.2 release notes and WordPress documentation.

September 18, 2026

The latest security release for WordPress, 7.1.1, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.1 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of some of these vulnerabilities, and are actively monitoring those rules. This includes an unauthenticated stored cross-site scripting vulnerability (CVE-2026-93485), reported through Patchstack's Vulnerability Disclosure Program, which was already covered by these mitigations ahead of the release. However, customers need to update their sites as soon as possible.

Highlights

This release resolves 11 security vulnerabilities, most requiring an authenticated role (Contributor or above) to exploit. WordPress has not assigned CVE identifiers to these issues.

For full details, see the WordPress 7.1.1 release notes and WordPress documentation.