Extended Support for Java 6 & Java 7

Security updates and 24/7 support through March 2028

Oracle stopped patching Java 6 in 2018 and Java 7 in 2022. We didn't stop. BellSoft sits on the OpenJDK Vulnerability Group, and 6 and 7 ship on the same quarterly cycle as our current releases.

Download Product Brief
Liberica JDK 6 and 7 builds are provided only with a commercial support subscription.
[object Object]

Control Your Timeline

Migrate when the business is ready, not when a CVE forces your hand. Budget it, test it, schedule it.
[object Object]

Runs Where You Run

32- and 64-bit builds for RHEL, Ubuntu, SLES, and Windows. Other platforms on request.

[object Object]

Operational Stability

Applications keep running exactly as they are. No downtime, no functionality loss, no retraining.

Don't Let Oracle's End-of-Life Put Your Business at Risk

Oracle ended support for Java 6 in 2018 and Java 7 in 2022. Every CVE published since then is still open in your runtime. What used to be a risk you could quietly carry is now an audit problem. Unsupported components fail evidence requirements in SOC 2, ISO 27001, and PCI-DSS, and EU regulation increasingly attaches obligations to component support and vulnerability handling.

critical

Your Java 6/7 applications are running unprotected

8
years

Without Java 6
security updates

4
years

Without Java 7
security updates

350
CVEs

With no security update
available

Compliance violations
accumulating
Insurance coverage
at risk

Java 6 and Java 7 End-of-Life Dates

Oracle's dates, and a fixed date you can plan a migration around

Release
Oracle JDK
GA
Oracle Public
Updates Ended
Oracle Java SE
EOL
Java 6 (1.6)
Dec 2006
Apr 2013
Dec 2018
Mar 2028
Java 7 (1.7)
Jul 2011
Apr 2015
Jul 2022
Mar 2028
See what extended support covers

Move to Liberica JDK 6&7 with expert support behind you

Oracle stopped patching these versions years ago. BellSoft keeps them secure, and when a
migration hits an edge case, you're working with the engineers who maintain the runtime itself.

  • You're in expert hands
    BellSoft sits on the OpenJDK Vulnerability Group and JCP committee, the engineers behind Java's security work. When something comes up, you're talking to them.
  • Most of the work is ours
    A same-version, TCK-verified switch, so the heavy lifting is on the JDK side. We're on call for the rest.
  • Even the hard cases have answers
    Applets, deprecated crypto, stale dependencies: the things that strand a legacy estate. Each has a route through. Applets, for one, move to OpenWebStart.

When one customer's move off Java 1.4 hit four months of edge cases, our engineers stayed in it until every CVE was closed.

Read the full story

What Extended Support Covers

Everything needed to keep a Java 6 or 7 runtime secure, compliant, and compatible with the
infrastructure around it. On a schedule you can plan maintenance windows around.

Quarterly Security Updates

Same cycle as every release.

CPU releases for 6 and 7 ship quarterly, simultaneously with every other Liberica JDK version. Predictable enough to plan maintenance windows around, months ahead.

media
CPU releases

Emergency Patches

Off-cycle zero-day fixes

Zero-day vulnerabilities are handled through emergency releases outside the quarterly cycle. You don't wait three months for a fix to something already being exploited.

zero-dayoff-cycle

Cryptography & TLS

TLS 1.2 and 1.3 via Bouncy Castle

Cryptography maintained per the OpenJDK roadmap. JDK 6 natively supports only TLS 1.0 and 1.1 — a Bouncy Castle implementation adds 1.2 and 1.3, so a 2006 runtime still reaches modern infrastructure.

TLS 1.2TLS 1.3Bounty Castle

Platform Coverage

Back to Server 2003 and XP

32- and 64-bit builds across Ubuntu, Debian, RHEL, CentOS, Oracle Linux, SLES, Amazon Linux, and Windows — including special builds for Windows Server 2003 and Windows XP SP3.

32-bit64-bitLinuxWindows

Deployment Formats

Fits your existing tooling

Shipped as MSI, ZIP, DEB, RPM, and TAR.GZ. Supported on Docker, KVM, Hyper-V, VirtualBox, and VMware vSphere.

MSIRPMDEBDocker

System Components

Time zones and root certificates

IANA time zone data and root certificates (cacerts) kept current. Prevents the silent breakage that stops scheduled jobs firing and outbound TLS connections resolving.

media
IANAtzdatacacertsTLS

What Does It Cost?

Per-server or per-core

Annual subscription sized to your deployment. Patches, emergency fixes, and 24/7 support all included — no separate charge for critical fixes.

CUSTOMER STORY

Four Months to Fix What
Quarterly Patching Prevents

Company A let the gap grow for nine years. Here's what closing it cost.
9
yearsunpatched
4
monthsto migrate
0
CVEsremaining
0
migrationremaining issues

UNPATCHED SINCE 2013

Company A's business-critical software still ran on Java 1.4, alongside an outdated Log4J. A security review found published CVEs in both.

NO REWRITE POSSIBLE

Remediation meant a supported runtime. JDK 6 was the nearest version still receiving vendor updates, and rewriting the application was off the table.

THE SWAP WAS THE EASY PART

Moving the runtime took days. Getting the application to work afterwards took months. Library differences between 1.4 and 6, dependencies that no longer resolved, failures that needed tracing one by one.

FOUR MONTHS OF JOINT DEBUGGING

BellSoft engineers worked directly with Company A's developers, analysing exception behaviour across both Java versions and updating libraries and configuration. Every identified CVE closed. Software stable on JDK 6.

Coverage and scope

01. What updates are included in extended support?

Quarterly CPU security updates, vulnerability fixes, cryptography maintenance per the OpenJDK roadmap, IANA time zone data, root certificate renewals, and functional regression fixes. Emergency releases for zero-day vulnerabilities are included at no extra cost.

02. Are there additional costs for security patches?

No. All security patches and quarterly updates are included in the subscription, including emergency releases for critical vulnerabilities.

03. How does BellSoft handle urgent vulnerabilities?

BellSoft is an active contributor to the OpenJDK Vulnerability Group, so our engineers work on CVEs alongside the people identifying them. Zero-days are handled through emergency releases outside the quarterly cycle, with 24/7 support response for incidents affecting your systems.

04. Which platforms are supported?

32- and 64-bit builds for Ubuntu (12.04–20.04), Debian (8–10), RHEL, CentOS and Oracle Linux (5.5+ through 8.x), SLES 11–15, Amazon Linux 1–2, and Windows Server 2008 R2 through 2019, plus Windows 7 SP1+ through 10. Special builds are available for Windows Server 2003 and Windows XP SP3. Certification on other operating systems is available on request.

05. What package formats and virtual environments do you support?

MSI, ZIP, DEB, RPM, and TAR.GZ packages. Supported virtual environments include Docker, KVM, Microsoft Hyper-V (gen 1 and 2), VirtualBox, and VMware vSphere.

06. How does BellSoft ensure compatibility and prevent regressions?

We test Liberica JDK 6 and 7 updates using the test suites available within the Java and OpenJDK ecosystem, and through source code compatibility. Liberica JDK is built from the OpenJDK source project.

Timeline and roadmap

01. What is extended support for Java 6 and 7?

Continued security maintenance after Oracle's end-of-life dates. Oracle ended commercial support for JDK 6 in 2018 and JDK 7 in July 2022. BellSoft provides security patches, functional fixes, and technical support for both through March 2028.

02. How long will BellSoft support Java 6 and Java 7?

Through March 2028 for both versions. JDK 6 and 7 are in maintenance mode — the JCP executive committee ratified the last maintenance update to both the specification and TCK in 2015.

Compliance and risk

01. What are the risks of running Java 6 or 7 without extended support?

Every CVE published since 2018 (JDK 6) or 2022 (JDK 7) remains unpatched in your runtime, and the weaknesses in these versions are well known and easily exploited. Unsupported components also fail evidence requirements in SOC 2, ISO 27001, and PCI-DSS audits, and cyber insurance policies increasingly exclude claims traced to knowingly unsupported software.

02. Does this help with EU CRA, NIS2, or DORA compliance?

Extended support gives you a component with an accountable vendor, a published support roadmap, and documented vulnerability handling — what each of these regimes requires of software in scope. The CRA requires manufacturers to define support periods and distribute security updates, with reporting obligations from September 2026 and full application from December 2027. NIS2 brings unsupported components into supply-chain risk management. DORA requires EU financial entities to manage legacy and end-of-life ICT assets explicitly. We provide the security advisories and patch documentation your compliance team needs as evidence. This isn't a substitute for legal advice on scope and applicability.

03. Can I run JDK 6 safely with modern TLS requirements?

JDK 6 natively supports only TLS 1.0 and 1.1, both now disabled by default in most modern software. A Bouncy Castle implementation adds TLS 1.2 and 1.3 support. Where that isn't practical, we recommend operating JDK 6 in a sandboxed environment where use of TLS 1.0 and 1.1 can be justified. We advise on the right approach for your setup as part of support.

Getting started

01. Can I download Liberica JDK 6 or 7 for free?

No. Liberica JDK 6 and 7 builds are provided only with a commercial support subscription. Liberica JDK 8 and later are free to download from our download centre, if you need a free, current Java runtime, start there.

02. How do I switch from Oracle JDK 6 or 7?

Liberica JDK is TCK verified, which means applications that work with Oracle JDK will run on Liberica JDK. It's a same-version switch, not a version upgrade. We provide migration guidance and compatibility support, and can help with more complex environments.

03. What licence does Liberica JDK use?

GPLv2 with Classpath Exception, which permits running both commercial and open source applications with no field-of-use restrictions or time limitations.

Get a Quote for Your Environment

Tell us what you're running and we'll come back with scope and pricing.