June 2025: Codegarden filled the roadmap and Umbraco 10 ran out of free patches

· JD + AI · Umbraco

June 2025: Codegarden filled the roadmap and Umbraco 10 ran out of free patches

If you still run Umbraco 10, the advisory of 24 June is the one to read twice. Umbraco shipped 10.8.11 because the vulnerability was reported while 10 was still inside its support window, and the post is explicit that any further security patch for that major will be released only under XLTS. The end of the free ride arrived as a paragraph in a patch note rather than as an announcement.

The rest of June was Codegarden. Umbraco used Odense to show Compose, an MCP server and a rebuilt search layer, then published a quarterly update that places most of it after the long-term-support version everyone is actually about to upgrade to.

One disclosure before the items: six of the twelve sources below are Umbraco's own blog, half of what we cite this month. On a Codegarden month that is unavoidable, and it means most of the roadmap in this post is the vendor describing itself.

Two advisories, and the last public patch for Umbraco 10

Security Advisory, June 3, 2025Andy Butland, Umbraco Moderate severity, affecting 15.0.0 to 15.4.1: a manipulated API request lets an authenticated backoffice user upload files with extensions the configuration forbids. Fixed in 15.4.2, and Cloud projects on the latest minor were patched the same day. Umbraco states there were "no indications that the vulnerabilities were discovered or exploited prior to the report", and credits the reporter by name.

Security Advisory, June 24, 2025Andy Butland, Umbraco Affects 13.0.0 to 13.9.1 and 10.0.0 to 10.8.10. An anonymous endpoint exposes the configured password requirements for backoffice users. No passwords, only the complexity rules, which is reconnaissance for a brute-force attempt rather than a breach on its own. Patched in 13.9.2 and 10.8.11.

Neither is dramatic. Both are the kind of authenticated-or-informational finding that a team defers for a sprint and then forgets. What makes the second one worth a calendar entry is the XLTS sentence attached to it: if your Umbraco 10 estate survived this long on the argument that patches keep arriving, that argument expired in June 2025.

Codegarden pointed past the LTS everyone is about to upgrade to

Product Update - Q2 2025Filip Bech-Larsen, Umbraco The single most useful document of the month, because it dates things. Umbraco 16 shipped in mid-June as a deliberately light release, with Tiptap replacing TinyMCE as the default rich-text editor, and the reason given for its thinness is the next LTS: v17 lands in November 2025 and Umbraco is limiting new features so the LTS-to-LTS upgrade stays manageable. The new search abstraction ships first as a separate package and is expected in core somewhere in the 18 to 21 cycle. Compose reaches a commercial offering in late 2025 or early 2026. Docker is now officially documented and supported. Cloud picked up Flexible Environments, CI/CD v2, hostname monitoring and a Canadian region.

Read that as a sequence and the conclusion is uncomfortable. The three things that would change how you build on Umbraco — Compose, provider-agnostic search, MCP — all land beside or after v17. The version most teams will spend Q4 2025 upgrading to is the stable one, not the interesting one. That is the correct call for anyone maintaining a fleet of v13 sites, and it also means "wait for the LTS and then reassess" buys you less than it sounds like.

Unveiling Umbraco MCP ServerFilip Bech-Larsen, Umbraco An MCP wrapper over the Management API: more than 315 endpoints, scoped through the API users introduced in v15 and the permission model you already configured. Bech-Larsen frames it as "making Umbraco accessible to AI" rather than adding AI to Umbraco, which is the more honest description of what a protocol adapter does. At the time of writing it ran locally against a community repository, with an official release expected in Q3 2025. Worth prototyping against a non-production project; not worth a client commitment yet.

uSync moved to v16 the same week, and said what that costs

uSync v15.1.9Kevin Jump Released 6 June with domain and publish-state fixes, and a warning in the body: "This might be the last support v15 release of uSync for Umbraco v15." From 12 June, development moved to v16 and v15 receives security fixes only.

uSync v16.0.0Kevin Jump Targets Umbraco v16, and the release notes say the focus is "purely on stability, and performance as we work towards the next Long term support version v17". Sync-scope adjustments, dashboard tweaks, a sort-order fix for uSync.Complete pushes. No new features by design.

Two independent release trains, both deciding that mid-2025 is for consolidation before v17. If you are still on 15, your deployment and serialisation tooling is now on a security-only branch, which folds the package upgrade into the same piece of work as the CMS upgrade rather than leaving it as a follow-up.

What the practitioners published

My Codegarden 2025 highlightsJeroen Breuer, jeroenbreuer.nl The best account of what was demonstrated live versus what was still a slide, which is the distinction the vendor's own write-up smooths over. Breuer separates block-level variation and Tiptap, running in front of an audience, from real-time collaboration, reusable blocks, Docker images and the search abstraction, which were roadmap. He also reports that the Compose session showed external systems surfacing inside the backoffice through a dedicated property editor. Two notes: our harvest recorded no author for this page, though the site names Breuer throughout and we credit him on that basis; and he attended as an MVP, so read the enthusiasm as a participant's, not an outsider's.

How to setup your own locally-hosted, private and completely free Chat GPT using Foundry Local and Open-WebUI and How to setup AI Toolkit with Foundry Local in Visual Studio CodeDennis Adolfi Two short, tested walkthroughs for running a model on your own machine and wiring it into VS Code. Adolfi notes that Microsoft's documentation claims AI Toolkit compatibility without explaining the setup, and fills the gap. The pairing with the MCP announcement is the useful part: the protocol question is what an assistant is allowed to do in your CMS, and this is the other half, where the model actually runs and whose network the content crosses.

ND & Me: Running in EmulationMatt Brailsford A late diagnosis of autism, ADHD and dyslexia, and what three days of Codegarden costs afterwards. Brailsford is proposing a virtual peer support group for the Umbraco community off the back of his conference session. Not a technical item, and the most-read thing on this list in most teams.

Umbraco Awards Winners 2025Pernille Stausbøll, Umbraco Useful for one number: the Cloud winner runs seventy sites on a single Umbraco Cloud instance. The package award went to SeoToolkit by Patrick de Mooij, with BlockPreview, Clean, Content Lock, CSP Manager and Slimsy as runners-up, which doubles as a shortlist for anyone auditing an Umbraco install.

Why Open Source is the Smart Choice for EnterprisesEmma Potter, Umbraco Positioning material from the vendor, arguing that the value is "transparency, flexibility, and long-term value" rather than price. Fine as a link to forward to a procurement team, and not evidence of anything.

What we would do with June

Patch, then treat the v13 to v17 move as the only Umbraco decision that matters between now and November. The Codegarden announcements are real and they are also mostly post-LTS, so building a 2025 plan around Compose or the search abstraction means building it on dates the vendor has already told you are provisional.

A word on this month's coverage, since it was reconstructed from feed archives rather than collected live. Eighteen Umbraco items cleared scope and twelve are cited below. Two of the URLs the harvest returned from jeroenbreuer.nl are not articles at all, its sitemap and its feed page, captured as though they were posts, and both were fetched in 2026, so they list 2026 writing inside a June 2025 window. They are not in the source list because there is nothing there to cite. The lesson for anyone building the same kind of pipeline is that backfilling through a live site gives you the site as it is today, not as it was in the month you asked for.

Sources

umbraco · umbraco-cms · umbraco-backoffice · umbraco-cloud · product · community · release · sitecore-search

2026 © Umbracolombia - All rights reserved.