Ubuntu 16.04 LTS, known as Xenial Xerus, reached a decisive support milestone on April 30, 2026. Canonical states that the ten-year Expanded Security Maintenance (ESM) period delivered through Ubuntu Pro has ended. The operating system does not stop booting on that date, and existing public-cloud images can still be launched. The important operational change is that those images are now deprecated and no longer receive the normal stream of security patches, bug fixes, or maintenance updates.

Why the April 30 deadline matters
Ubuntu 16.04 originally received five years of standard security coverage. Ubuntu Pro extended that through ESM to a total of ten years. After April 30, 2026, a newly disclosed vulnerability in an old package, library, or operating-system component may have no patch path under the completed ESM coverage. A server can look stable in monitoring while its exposure grows quietly. This is particularly relevant for internet-facing services, systems with privileged access, workloads holding personal or business-critical data, and estates subject to security or compliance reviews.
Canonical distinguishes running from being maintained. A Xenial instance may continue to serve traffic, but continued execution is not equivalent to an approved security posture. Administrators should treat any remaining 16.04 host as a tracked exception with an owner, a documented risk decision, and a dated remediation plan rather than as ordinary supported infrastructure.

Path one: migrate to a supported LTS
Canonical’s preferred route is moving workloads to a newer supported Ubuntu LTS release. The announcement names Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS as target releases. A fresh installation means building a new instance, deploying the application and configuration, validating it, then moving traffic. For many teams this is the cleaner option because it also refreshes image hardening, package repositories, service accounts, observability agents, backup settings, and infrastructure definitions.
An in-place migration is the alternative when redeploying immediately is impractical. It can preserve an existing machine layout, but it should never begin with production as the test environment. Review Canonical’s Ubuntu LTS Upgrade Guide first. Validate application runtimes, package repositories, kernel or driver dependencies, authentication integrations, storage capacity, maintenance windows, and rollback behavior. A successful upgrade command is not enough; the application, scheduled jobs, monitoring, backups, and recovery process must work on the target release.

Path two: Ubuntu Pro Legacy add-on
Canonical also recognises that legacy architecture, application compatibility, or regulatory dependencies can prevent an immediate move. For an active Ubuntu Pro subscription, the Ubuntu Pro Legacy add-on provides five additional years of security maintenance and support. Canonical says this extends the total Ubuntu 16.04 lifecycle to 15 years and keeps critical security patches available until 2031. It is intended to create time for a controlled migration, not to remove the need for one.
The add-on is not described as an automatic entitlement. Organisations that need to retain Ubuntu 16.04 securely should contact Canonical through its Support Form. Procurement, platform owners, and security teams should confirm coverage, applicable systems, costs, and the migration deadline together. Record why the extension is needed and review that rationale regularly.
Practical administrator checklist
- Inventory every Ubuntu 16.04 VM, bare-metal host, cloud image, template, snapshot, build runner, appliance, and disaster-recovery asset.
- Check Ubuntu Pro and ESM status, then mark April 30, 2026 as the end of the original ten-year coverage.
- Prioritise externally reachable services, privileged hosts, and systems processing sensitive data.
- Select a target: fresh deployment or in-place migration to Ubuntu 22.04, 24.04, or 26.04 LTS.
- Test dependencies, backups, restore procedures, monitoring, smoke tests, rollback, and downtime assumptions before production changes.
- Where migration cannot happen in time, engage Canonical about the Ubuntu Pro Legacy add-on through 2031.
- For every exception, document an accountable owner, risk acceptance, target completion date, and periodic review.
Conclusion
Ubuntu 16.04 LTS did not suddenly become unusable on April 30, 2026, but its ten-year Ubuntu Pro ESM window ended. The durable response is migration to a supported LTS. The Legacy add-on offers a limited security bridge for constrained environments until 2031. Accurate inventory and tested execution now are safer than discovering an unsupported Xenial dependency during the next urgent vulnerability response.
Source: Canonical Ubuntu Blog — Beyond the 10-year mark: Extending Ubuntu Pro 16.04 LTS security coverage.
