NewsOpen SourceDatabasesSecurity

97% of Teams Run Databases Past End-of-Life: Percona’s 2026 Report

Almost every engineering team is running at least one database version past its end-of-life—and most know it. Percona’s 2026 State of Open Source Database Management report, released September 9, puts a number on that uncomfortable truth: 97% of organizations are running EOL database versions, with 44% saying they have many in that state. That’s not a technology problem. That’s an organizational habit with an accelerating price tag.

The EOL Clock Is Running Out

The timing makes this report land harder than usual. MySQL 8.0 hit end-of-life in April 2026—used by roughly half of all organizations. PostgreSQL 14 reaches EOL on November 12, 2026, with 44 CVEs already discovered this year alone, up from just 7 in all of 2025. When end-of-life hits, patches stop. CVEs don’t.

The risk isn’t theoretical. CVE-2026-6471 (PostGREShell)—a logical-decoding flaw present since PostgreSQL 9.4—lets any account with replication privileges escalate to superuser and install a persistent backdoor. Patches closed it for supported versions. If you’re on PostgreSQL 14 past November 12, you’re on your own.

Most vulnerability scanners don’t flag EOL status. That gap is the single most underestimated risk in enterprise security. For teams in healthcare, finance, or government, running unsupported database software is typically a direct compliance finding under HIPAA, FedRAMP, and SOC 2. It doesn’t matter how locked-down the rest of your stack is.

PostgreSQL Won the AI Infrastructure Vote

The report’s most striking finding isn’t the EOL number—it’s where the industry is placing its AI bets. 78% of respondents say PostgreSQL is important to their current or planned AI/ML initiatives, with 25% calling it outright “mission critical.” That’s not a future forecast. It’s a decision that’s already been made in engineering orgs across the country.

The reason isn’t idealism—it’s pgvector. PostgreSQL with pgvector absorbs most vector workloads under 50 million vectors and reduces total cost of ownership by 40–60% compared to a purpose-built vector database. It’s MIT-licensed, enabled with a single CREATE EXTENSION vector call, and supported out-of-the-box on AWS RDS, Aurora, Supabase, Neon, and Azure. Teams aren’t switching to PostgreSQL for AI. It was already there.

This puts an awkward spotlight on any team still running PostgreSQL 14 or older: the database the industry has designated as its AI backbone is, for nearly half of organizations, also sitting in legacy debt.

Vendor Lock-In Is Now a Compliance Argument

54% of respondents say vendor lock-in makes it harder to adapt to changing regulatory requirements. That framing matters. Lock-in has traditionally been positioned as a technical risk—“we might want to switch someday.” It’s now being lived as a legal problem: when a new compliance mandate lands, teams tied to a proprietary managed database can’t move fast enough.

The EU AI Act, evolving GDPR enforcement, and sector-specific data residency rules are arriving faster than managed cloud vendors can adapt their services. Orgs that built on open source retain the ability to respond. Those that optimized for managed convenience are finding the fine print.

The Cloud Cost Math Is Breaking

31% of respondents identify rising cloud spend as the biggest barrier to reducing database total cost of ownership. Another 23% point to rising licensing costs. AWS RDS production workloads routinely run $744/month or more once Multi-AZ, IOPS upgrades, and egress are accounted for. Self-hosted PostgreSQL on equivalent compute: $135–220/month. For non-customer-facing workloads—analytics, staging, internal tools—the managed database premium is increasingly hard to justify.

What to Do Before November 12

The report is a survey, not a prescription, but the actions follow directly from the findings:

  • Audit your database versions now. Run endoflife.date against your full stack. MySQL 8.0, PostgreSQL 14, Redis 6.x, and Elasticsearch 7.x are the most common landmines.
  • Prioritize the PostgreSQL 14 upgrade. November 12 is the hard deadline. With 44 CVEs already this year, there is no buffer in waiting.
  • Run the cloud cost math on non-production workloads. Managed databases make sense for customer-facing production systems with small ops teams. They are harder to justify for everything else.
  • Evaluate pgvector before adding a separate vector database. If your workload is under 50 million vectors, you probably do not need a dedicated vector DB—and the operational overhead saved is real.

Percona’s framing is direct: “The real value of open source in 2026 isn’t lower cost or visible code. It’s freedom and optionality—the ability to adapt as regulation, cloud economics, and AI requirements keep changing.” The 97% EOL statistic suggests most organizations are burning that optionality without realizing it.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News