CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Lifecycle

Product lifecycle

End of Support (EOS) and End of Life (EOL) dates for operating systems, databases, runtimes, web servers, virtualization platforms, network devices, and applications, from endoflife.date. End of Support means active support ends, though security patches usually continue; End of Life means security patches stop, and it is the date that matters most. The two are different, and this page keeps them apart. A status is shown at the product-and-release-cycle level only; this page never claims a specific version you run is end of life. Most products here carry an identity verified against the product's own identifier in the source, and only those may ever be linked to vulnerability records; a display-only tier (Windows Server, several other operating systems, and a number of infrastructure appliances whose identity the source does not assert) is shown for planning, and is never linked to any vulnerability record. Anything else shows no lifecycle status rather than a guessed one.

38 products tracked800 release cycles across those productsunder 1% vendor coverage of the vulnerability corpusSource: endoflife.date

The crosswalk's product vendors cover 17 of the 3,634 distinct vendors in this tracker's vulnerability corpus (under 1 percent). That is a vendor-level signal over the Common Vulnerabilities and Exposures (CVE) corpus, not a claim of full product coverage.

End of Life dates that need action

Imminent deadlines and release cycles already past End of Life come first. Supported latest-cycle cards follow this planning view.

Upcoming End of Life (next 24 months)

Every mapped product and release cycle reaching End of Life within 730 days, soonest first. The nearest of these also appear on the compliance Calendar.

  • OpenJDK (Oracle builds) 26
  • Fortinet FortiOS 7.2
  • FreeBSD 15.0
  • Windows 10-1607-e-lts
  • Windows 11-24h2-w
  • OpenSSL 3.4
  • Kubernetes 1.34
  • Citrix Virtual Apps and Desktops 2503
  • Python 3.10
  • Alpine Linux 3.21
  • OpenSSL 3.6
  • .NET 8
  • .NET 9
  • Windows 11-23h2-e
  • PostgreSQL 14
  • Fedora 43
  • FreeBSD 14.4
  • Microsoft .NET Framework 4.6.2
  • Windows 10-21h2-e-lts
  • Windows Server 2016

Showing the 20 soonest of 55. The full set is in the table below.

Already past End of Life

Most recently passed dates first.

  • OpenSSL 3.0
  • Debian 11
  • F5 BIG-IP 21.0
  • Cisco IOS XE 17.9
  • Microsoft SharePoint 2016
  • Microsoft SharePoint 2019
  • Microsoft SQL Server 13.0-sp3
  • Microsoft SQL Server 13.0-sp3-acp
  • Ubuntu 25.10
  • Amazon Linux 2
  • FreeBSD 14.3
  • Kubernetes 1.33
  • Citrix Virtual Apps and Desktops 2411
  • Node.js 25
  • Fedora 42
  • nginx 1.29
  • Windows Server 23h2-ac
  • FreeBSD 13
  • FreeBSD 13.5
  • MySQL 8.0

Showing the 20 most recently passed of 652. The full set is in the table below.

Lifecycle timeline (major operating systems)

Release to End of SupportEnd of Support to End of LifeExtended supportToday

All mapped products

FreeBSD1.0operating systemNot reportedEnd of Life
FreeBSD1.1operating systemNot reportedEnd of Life
FreeBSD2.0operating systemNot reportedEnd of Life
Debian1.1operating systemEnd of Life
FreeBSD2.1operating systemNot reportedEnd of Life
Debian1.2operating systemEnd of Life
FreeBSD2.2operating systemNot reportedEnd of Life
Debian1.3operating systemEnd of Life
Debian2.0operating systemEnd of Life
Microsoft SQL Server6.0-sp3databaseEnd of Life
FreeBSD3.0operating systemNot reportedEnd of Life
FreeBSD3.1operating systemNot reportedEnd of Life
FreeBSD3.2operating systemNot reportedEnd of Life
FreeBSD3.3operating systemNot reportedEnd of Life
FreeBSD3.4operating systemNot reportedEnd of Life
Debian2.1operating systemEnd of Life
FreeBSD4.0operating systemNot reportedEnd of Life
FreeBSD4.1operating systemNot reportedEnd of Life
macOS10.0operating systemNot reportedEnd of Life
FreeBSD3.5operating systemNot reportedEnd of Life
FreeBSD4.2operating systemNot reportedEnd of Life
FreeBSD4.3operating systemNot reportedEnd of Life
Microsoft SQL Server6.50-sp5adatabaseEnd of Life
FreeBSD4.4operating systemNot reportedEnd of Life
macOS10.1operating systemNot reportedEnd of Life
FreeBSD4.5operating systemNot reportedEnd of Life
FreeBSD4.6operating systemNot reportedEnd of Life
PostgreSQL6.3databaseNot reportedEnd of Life
Debian2.2operating systemEnd of Life
FreeBSD4.7operating systemNot reportedEnd of Life
FreeBSD5.0operating systemNot reportedEnd of Life
macOS10.2operating systemNot reportedEnd of Life
PostgreSQL6.4databaseNot reportedEnd of Life
FreeBSD4.8operating systemNot reportedEnd of Life
FreeBSD5.1operating systemNot reportedEnd of Life
PostgreSQL6.5databaseNot reportedEnd of Life
FreeBSD4.9operating systemNot reportedEnd of Life
Fedora1operating systemNot reportedEnd of Life
FreeBSD5.2operating systemNot reportedEnd of Life
Fedora2operating systemNot reportedEnd of Life
macOS10.3operating systemNot reportedEnd of Life
PostgreSQL7.0databaseNot reportedEnd of Life
Fedora3operating systemNot reportedEnd of Life
PostgreSQL7.1databaseNot reportedEnd of Life
Ubuntu4.10operating systemEnd of Life
Debian3.0operating systemEnd of Life
Fedora4operating systemNot reportedEnd of Life
FreeBSD5.3operating systemNot reportedEnd of Life
FreeBSD5.4operating systemNot reportedEnd of Life
Ubuntu5.04operating systemEnd of Life
About this data and its limits

Lifecycle dates come fromendoflife.date, a community-maintained, best-effort catalog. Products appear here in two tiers. Most are mapped to a canonical vendor and product verified against the product's own identifier in the source, and only those may ever be linked to a Common Vulnerabilities and Exposures (CVE) record. A display-only tier (Windows Server, several other operating systems, and a number of infrastructure appliances whose identity the source does not assert or asserts ambiguously) is shown because its dates matter to planning even though no single verified identifier exists for it; a display-only product's dates appear here, but it is never linked to any CVE record, the vulnerability scorer ignores it entirely, and the CSV download leaves its identity columns blank. A product that fits neither tier shows no lifecycle status here rather than a guessed one. The status of each release cycle is derived from its dates: Supported, End of Support, Extended support, End of Life, or Not announced when the source has not set a date. A status is shown at the product-and-release-cycle level only. This page never claims that a specific version you run is end of life, since that conclusion needs version-level data this page does not carry.

endoflife.date is a community-maintained, best-effort catalog licensed MIT. Its operating system and runtime coverage is dense, but its network-edge and appliance coverage is thinner: several appliances carry no Common Platform Enumeration (CPE) identity, and Ivanti and Citrix NetScaler are not tracked at all. Most products here are mapped to a canonical vendor and product verified against the product's own identifier in the source, and only those may ever be linked to vulnerability records. A display-only tier (Windows Server, several other operating systems, and a number of infrastructure appliances whose identity the source does not assert or asserts ambiguously) is shown because its dates matter to planning even though no single verified identifier exists for it; a display-only product is never linked to any vulnerability record. A product that fits neither tier shows no lifecycle status here rather than a guessed one.

Lifecycle data is fromendoflife.date, licensedMIT, maintained by endoflife.date contributors.

Glossary