Oracle stopped patching Java 6 in 2018 and Java 7 in 2022. We didn't stop. BellSoft sits on the OpenJDK Vulnerability Group, and 6 and 7 ship on the same quarterly cycle as our current releases.
32- and 64-bit builds for RHEL, Ubuntu, SLES, and Windows. Other platforms on request.
Applications keep running exactly as they are. No downtime, no functionality loss, no retraining.
Oracle ended support for Java 6 in 2018 and Java 7 in 2022. Every CVE published since then is still open in your runtime. What used to be a risk you could quietly carry is now an audit problem. Unsupported components fail evidence requirements in SOC 2, ISO 27001, and PCI-DSS, and EU regulation increasingly attaches obligations to component support and vulnerability handling.
Without Java 6
security updates
Without Java 7
security updates
With no security update
available
Oracle's dates, and a fixed date you can plan a migration around
See what extended support coversOracle stopped patching these versions years ago. BellSoft keeps them secure, and when a
migration hits an edge case, you're working with the engineers who maintain the runtime itself.
Everything needed to keep a Java 6 or 7 runtime secure, compliant, and compatible with the
infrastructure around it. On a schedule you can plan maintenance windows around.
Same cycle as every release.
CPU releases for 6 and 7 ship quarterly, simultaneously with every other Liberica JDK version. Predictable enough to plan maintenance windows around, months ahead.

Off-cycle zero-day fixes
Zero-day vulnerabilities are handled through emergency releases outside the quarterly cycle. You don't wait three months for a fix to something already being exploited.
TLS 1.2 and 1.3 via Bouncy Castle
Cryptography maintained per the OpenJDK roadmap. JDK 6 natively supports only TLS 1.0 and 1.1 — a Bouncy Castle implementation adds 1.2 and 1.3, so a 2006 runtime still reaches modern infrastructure.
Back to Server 2003 and XP
32- and 64-bit builds across Ubuntu, Debian, RHEL, CentOS, Oracle Linux, SLES, Amazon Linux, and Windows — including special builds for Windows Server 2003 and Windows XP SP3.
Fits your existing tooling
Shipped as MSI, ZIP, DEB, RPM, and TAR.GZ. Supported on Docker, KVM, Hyper-V, VirtualBox, and VMware vSphere.
Time zones and root certificates
IANA time zone data and root certificates (cacerts) kept current. Prevents the silent breakage that stops scheduled jobs firing and outbound TLS connections resolving.
Per-server or per-core
Annual subscription sized to your deployment. Patches, emergency fixes, and 24/7 support all included — no separate charge for critical fixes.
Company A's business-critical software still ran on Java 1.4, alongside an outdated Log4J. A security review found published CVEs in both.
Remediation meant a supported runtime. JDK 6 was the nearest version still receiving vendor updates, and rewriting the application was off the table.
Moving the runtime took days. Getting the application to work afterwards took months. Library differences between 1.4 and 6, dependencies that no longer resolved, failures that needed tracing one by one.
BellSoft engineers worked directly with Company A's developers, analysing exception behaviour across both Java versions and updating libraries and configuration. Every identified CVE closed. Software stable on JDK 6.
Quarterly CPU security updates, vulnerability fixes, cryptography maintenance per the OpenJDK roadmap, IANA time zone data, root certificate renewals, and functional regression fixes. Emergency releases for zero-day vulnerabilities are included at no extra cost.
No. All security patches and quarterly updates are included in the subscription, including emergency releases for critical vulnerabilities.
BellSoft is an active contributor to the OpenJDK Vulnerability Group, so our engineers work on CVEs alongside the people identifying them. Zero-days are handled through emergency releases outside the quarterly cycle, with 24/7 support response for incidents affecting your systems.
32- and 64-bit builds for Ubuntu (12.04–20.04), Debian (8–10), RHEL, CentOS and Oracle Linux (5.5+ through 8.x), SLES 11–15, Amazon Linux 1–2, and Windows Server 2008 R2 through 2019, plus Windows 7 SP1+ through 10. Special builds are available for Windows Server 2003 and Windows XP SP3. Certification on other operating systems is available on request.
MSI, ZIP, DEB, RPM, and TAR.GZ packages. Supported virtual environments include Docker, KVM, Microsoft Hyper-V (gen 1 and 2), VirtualBox, and VMware vSphere.
We test Liberica JDK 6 and 7 updates using the test suites available within the Java and OpenJDK ecosystem, and through source code compatibility. Liberica JDK is built from the OpenJDK source project.
Continued security maintenance after Oracle's end-of-life dates. Oracle ended commercial support for JDK 6 in 2018 and JDK 7 in July 2022. BellSoft provides security patches, functional fixes, and technical support for both through March 2028.
Through March 2028 for both versions. JDK 6 and 7 are in maintenance mode — the JCP executive committee ratified the last maintenance update to both the specification and TCK in 2015.
Every CVE published since 2018 (JDK 6) or 2022 (JDK 7) remains unpatched in your runtime, and the weaknesses in these versions are well known and easily exploited. Unsupported components also fail evidence requirements in SOC 2, ISO 27001, and PCI-DSS audits, and cyber insurance policies increasingly exclude claims traced to knowingly unsupported software.
Extended support gives you a component with an accountable vendor, a published support roadmap, and documented vulnerability handling — what each of these regimes requires of software in scope. The CRA requires manufacturers to define support periods and distribute security updates, with reporting obligations from September 2026 and full application from December 2027. NIS2 brings unsupported components into supply-chain risk management. DORA requires EU financial entities to manage legacy and end-of-life ICT assets explicitly. We provide the security advisories and patch documentation your compliance team needs as evidence. This isn't a substitute for legal advice on scope and applicability.
JDK 6 natively supports only TLS 1.0 and 1.1, both now disabled by default in most modern software. A Bouncy Castle implementation adds TLS 1.2 and 1.3 support. Where that isn't practical, we recommend operating JDK 6 in a sandboxed environment where use of TLS 1.0 and 1.1 can be justified. We advise on the right approach for your setup as part of support.
No. Liberica JDK 6 and 7 builds are provided only with a commercial support subscription. Liberica JDK 8 and later are free to download from our download centre, if you need a free, current Java runtime, start there.
Liberica JDK is TCK verified, which means applications that work with Oracle JDK will run on Liberica JDK. It's a same-version switch, not a version upgrade. We provide migration guidance and compatibility support, and can help with more complex environments.
GPLv2 with Classpath Exception, which permits running both commercial and open source applications with no field-of-use restrictions or time limitations.
Get a Quote for Your Environment