The ASA 5500-X Is Over: Cisco's 5506-X, 5508-X and 5516-X Passed Their Last Date of Support on August 31, 2026
The small-office Cisco firewall that sits in more branch closets than any other went out of support on Monday. Per Cisco bulletins EOL13763 and EOL13762, the ASA 5506-X, 5508-X and 5516-X reached their Last Date of Support on August 31, 2026. Orders closed on August 2, 2021; the last day to renew a service contract was October 28, 2025. Cisco's definition of the milestone is the strictest in the industry: after it, “all support services for the product are unavailable, and the product becomes obsolete.”
That closes the book on the ASA 5500-X generation. The mid-range 5525-X, 5545-X and 5555-X reached the same milestone on September 30, 2025; the data-centre 5585-X on May 31, 2023; the 5512-X, 5515-X and the older 5505 on August 31, 2022. There is no 5500-X model left with vendor support, and the platform carries the longest exploited-vulnerability record of any firewall in CISA's catalog.
The verified dates
Every milestone below is from the Cisco End-of-Sale and End-of-Life bulletin for that model, read on cisco.com. Cisco blocks automated fetches of its bulletins, so our ASA 5500-X page records the bulletin numbers and re-reads them by hand; the cells below are bound to that data.
| Model | Bulletin | End of sale | Last contract renewal | Last Date of Support | Cisco's stated migration |
|---|---|---|---|---|---|
| ASA 5506-X (incl. 5506W-X, 5506H-X) | EOL13763 | August 2, 2021 | October 28, 2025 | August 31, 2026 | Firepower 1000 Series |
| ASA 5508-X | EOL13762 | August 2, 2021 | October 28, 2025 | August 31, 2026 | Firepower 1000 Series |
| ASA 5516-X | EOL13762 | August 2, 2021 | October 28, 2025 | August 31, 2026 | Firepower 1000 Series |
| ASA 5525-X, 5545-X, 5555-X | EOL13130 | September 4, 2020 | November 30, 2024 | September 30, 2025 | Firepower 2100 Series |
| ASA 5585-X | c51-740021 | June 1, 2018 | August 27, 2022 | May 31, 2023 | Firepower 4100 Series |
| ASA 5512-X, 5515-X | EOL11414 | August 25, 2017 | November 20, 2021 | August 31, 2022 | See bulletin |
| ASA 5505 | c51-738642 | August 25, 2017 | November 20, 2021 | August 31, 2022 | ASA 5506-X (now itself past support) |
Why this platform's deadline matters more than most
Cisco ASA is the most-listed firewall in CISA's Known Exploited Vulnerabilities catalog: eleven entries, spanning a 2014 flaw added a decade late, the 2016 Shadow Brokers pair, the 2024 ArcaneDoor campaign, and an entry added on August 11, 2026 with a three-day federal due date. From CVE-2020-3259 onward, CISA's required action reads “apply mitigations per vendor instructions or discontinue use of the product” — the same doctrine that orders end-of-life routers unplugged, applied to the most common enterprise firewall.
| CVE | Added to KEV | What it was |
|---|---|---|
| CVE-2026-20349 | Aug 11, 2026 | ASA and Firewall Threat Defense vulnerability added with a due date of August 14, 2026 — three days, the shortest CISA assigns |
| CVE-2014-2120 | Nov 12, 2024 | Cross-site scripting in the WebVPN login page, a 2014 bug confirmed exploited ten years on |
| CVE-2024-20481 | Oct 24, 2024 | Remote-access VPN denial of service, exploited in credential brute-force campaigns |
| CVE-2024-20353 | Apr 24, 2024 | Denial of service — one half of the ArcaneDoor espionage campaign |
| CVE-2024-20359 | Apr 24, 2024 | Persistent local code execution — the other half of ArcaneDoor |
| CVE-2020-3259 | Feb 15, 2024 | Memory disclosure from the WebVPN service; known ransomware use |
| CVE-2016-6366 | May 24, 2022 | SNMP buffer overflow — the Shadow Brokers' EXTRABACON |
| CVE-2016-6367 | May 24, 2022 | CLI remote code execution from the same leak |
| CVE-2020-3452 | Nov 3, 2021 | Read-only path traversal in the web services interface |
| CVE-2020-3580 | Nov 3, 2021 | Cross-site scripting in the web services interface; known ransomware use |
| CVE-2018-0296 | Nov 3, 2021 | Denial of service via the web interface, with directory traversal |
The pattern that matters for September: every one of these was fixed by a software release for hardware Cisco still supported. An ASA 5506-X, 5508-X or 5516-X is now on hardware Cisco has declared obsolete, and the next entry in that table will have no fix for it. CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them; as of September 1, 2026 every ASA 5500-X is on that list.
What to do with the ones still running
The destination, in Cisco's own words from the bulletins: the Firepower 1000 Series for the 5506-X, 5508-X and 5516-X; the Firepower 2100 Series for the 5525-X, 5545-X and 5555-X; the Firepower 4100 Series for the 5585-X. Cisco's Technology Migration Program offers trade-in credit against the replacement, and Cisco Certified Refurbished units were offered only until the Last Date of Support, so that route is closed for the 5506-X, 5508-X and 5516-X as of this week.
The trap: keeping the old box on a “still works” basis with the ASA image it has. Cisco publishes no fixes for obsolete hardware, and the KEV record above shows how often ASA needs them. Third-party support contracts can replace a failed power supply; they cannot produce a patch.
The order of operations: (1) inventory every 5500-X by serial, including the 5506-X units at branches and the 5505s that were never decommissioned; (2) for the 5506-X, 5508-X and 5516-X, treat replacement as overdue rather than planned; (3) land on a current release on the replacement platform and confirm the 9.x line it runs is inside the software dates above; (4) retire the old appliances rather than repurposing them, because an ASA that still answers on the internet with a WebVPN login page is the KEV pattern above waiting to repeat.
Frequently Asked Questions
When did the Cisco ASA 5506-X, 5508-X and 5516-X reach end of support?
August 31, 2026, the Last Date of Support in Cisco bulletins EOL13763 and EOL13762. The three models left sale on August 2, 2021 and their service contracts could last be renewed on October 28, 2025. After the Last Date of Support, in Cisco's words, all support services for the product are unavailable and the product becomes obsolete.
What about the ASA 5525-X, 5545-X and 5555-X?
They reached their Last Date of Support a year earlier, on September 30, 2025, under bulletin EOL13130: end of sale September 4, 2020, end of service contract renewal November 30, 2024. Cisco names the Firepower 2100 Series as the migration.
Is any ASA 5500-X model still supported?
No. The 5585-X reached its Last Date of Support on May 31, 2023, and the 5512-X, 5515-X and the older 5505 on August 31, 2022. With the August 31, 2026 milestone the entire 5500-X generation is past vendor support.
What does Cisco recommend as the replacement?
Per the bulletins: the Firepower 1000 Series for the 5506-X, 5508-X and 5516-X; the Firepower 2100 Series for the 5525-X, 5545-X and 5555-X; the Firepower 4100 Series for the 5585-X. Cisco's Technology Migration Program offers trade-in credit toward the new equipment.
Why does this matter for security?
Cisco ASA has eleven entries in CISA's Known Exploited Vulnerabilities catalog, the most recent added on August 11, 2026 with a three-day federal due date. From CVE-2020-3259 onward, CISA's required action includes discontinuing use of the product if mitigations cannot be applied. An appliance past its Last Date of Support receives no software maintenance and no security fixes from Cisco.
How does this relate to CISA's edge-device directive?
CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them. Every ASA 5500-X model is an end-of-support device as of September 1, 2026.
Related
- Cisco ASA 5500-X Series (hardware) — every model with live status · Cisco ASA software · Secure Firewall Threat Defense
- SonicWall's Gen 6 cliff: October 1, 2026 — the other firewall generation going out this quarter
- The EOS Edge Device List — 25 platforms, vendor-verified, machine-readable
- End of support & the BOD 26-02 clock · Exploited & Unpatchable