PHP tags three release candidates at once, all active branches in a single day
The PHP Group just tagged PHP 8.6.0 RC3, 8.5.12 RC1, and 8.4.27 RC1 in one day across every active branch. Here's what each fix list means for you.
The PHP Group has now confirmed three release candidates for the same round of testing. On 6 October 2026, maintainers simultaneously tagged 8.6.0 RC3, 8.5.12 RC1, and 8.4.27 RC1, and each carries an official NEWS entry dated 8 October.
If you run anything PHP-based, this is the window you'd normally start a test cycle. Candidates aren't production material, but a bad interaction you catch now beats one you catch in the wild.
Tagging the current development line alongside both maintenance branches on the same date isn't a fluke. It lets distro maintainers, CI systems, and eager testers validate a single code snapshot against every branch that will ship over the coming weeks. Standard end-of-cycle chore.
PHP 8.6.0 RC3, the biggest of the three
PHP 8.6 is the current major release, so the feature freeze is well behind it. By RC3 the new stuff was locked in: partial function application, the clamp() helper, Time\Duration, readonly properties with default values, and a shared first-class callable cache. Now the changelog is entirely about hardening.
A mature major release candidate should look, more or less, exactly like this.
The candidate's own NEWS entry lists 21 areas needing fixes. Most of them are memory-safety and correctness issues buried across extensions you probably don't name at dinner parties. A few are worth flagging though.
There's a VM crash where the optimizer failed to unfold a constant-vs-constant comparison (GH-23644), plus Opcache/JIT problems including a parent's private property leaking into a child's shadowing public property (GH-23679). Sharp eyes will also spot a fix for Opcache folding $cond ? -0.0 : 0.0 into a bare -0.0 (GH-24063).
Keep in mind that 8.6 is still the in-development line, so you're most likely to hit something here. The project also deprecated using "let" and "is" as names for classes, functions, or constants, along with "_" as a constant alias. Build your code around either keyword? Now's the time to check.
The maintenance branches: 8.5.12 RC1 and 8.4.27 RC1
The other two are more conventional. Both 8.5.12 and 8.4.27 sit in their long bug-fix phase, so expect no new features, just a pile of corrections. Both kicked off their candidate cycle at RC1 this round, following 8.5.11 and 8.4.26 respectively.
8.5.12 touches 29 areas. 8.4.27 is the widest of the three at 30, which makes sense. It's older, and its backlog tends to be longer.
The shared fixes are the ones that actually matter, since they show up in all three branches. You'll find the same BCMath negative-sign truncation, the same BZ2 use-after-free in bzopen(), and the same built-in-server file-descriptor leak on HEAD requests (GH-23764). There's also the PCNTL signal-drop fix (GH-23986) and a spread of use-after-free corrections across DOM, FFI, and the PDO family.
One that tripped up Windows users specifically: the built-in server was leaking a descriptor on every static-file HEAD request. If you've ever watched a small PHP app slowly eat memory on a quiet box, that one stung.
Where things stand
These are bug-fix candidates, not security releases. Their NEWS entries cite no CVEs, but the pile of use-after-frees, buffer overflows, and out-of-bounds reads they sweep up is exactly the kind of thing the PHP Group and OSS-Fuzz treat as security-relevant anyway.
For context, the recent 8.5.x and 8.4.x cycles have already tackled flagged issues including mysqlnd wire-protocol overreads, GD vulnerabilities, a phar TAR injection, and OpenSSL TLS wildcard bugs. This round continues that trajectory without opening any new public disclosure.
Taggers on this batch came from the usual core team: Joe Ferguson, Daniel Scherzer, and Buckley's Calvin Buckley, working alongside Ilia Alshanetsky, Jakub Zelenka, and others. That's the stable handoff you want to see.
If no blocking bugs surface, the last RC in each line simply becomes the final version. Otherwise more candidates follow before GA ships.
Head here to download the PHP 8.6.0 RC3 source, here to download 8.5.12 RC 1, and here for 8.4.27 RC 1.
