Ivanti Connect Secure Hits End of Support Days Before CISA's Edge-Device Deadline
Two clocks are converging on the same week of early 2027, and the organizations most exposed to both are US federal agencies. Per Ivanti's own EOL Timelines and Support Matrix, Ivanti Connect Secure 22.7, 22.8, and the 25.1.0 through 25.1.2 releases all reach End of Support on January 31, 2027. And CISA's Binding Operational Directive 26-02 — "Mitigating Risk From End-of-Support Edge Devices," issued February 5, 2026 — gives federal civilian agencies twelve months to decommission listed end-of-support edge devices. That deadline lands in early February 2027, days after the Ivanti date.
A federal ICS appliance running 22.7 or 22.8 today therefore has both clocks expiring the same week — and under the directive's other requirement, it has been reportable since day one: agencies must inventory every edge device that is EOS or will be within twelve months, a horizon these releases entered on January 31, 2026, when their End of Engineering arrived and Ivanti's fix commitment dropped to "a limited-effort basis, as determined by Ivanti."
The verified dates
| Release | Launched | End of Engineering | End of Support |
|---|---|---|---|
| ICS 22.7 | May 21, 2024 | Jan 31, 2026 — passed | Jan 31, 2027 |
| ICS 22.8 | Jul 24, 2025 | Jan 31, 2026 — passed | Jan 31, 2027 |
| ICS 25.1.0 | Sep 24, 2025 | Jan 31, 2026 — passed | Jan 31, 2027 |
| ICS 25.1.3 | Jul 31, 2026 | rolling (N-2 policy) | Apr 30, 2027 |
| PCS 9.1x | May 13, 2019 | Jun 30, 2024 — passed | Dec 31, 2024 — passed |
Full version detail, provenance, and live risk scores are on our Ivanti Connect Secure lifecycle page, published today as part of our EOS Edge Device List buildout.
The 9.x line already showed us the ending
This is not a hypothetical risk model — the previous generation ran the experiment. Pulse Connect Secure 9.1x reached End of Support on December 31, 2024. Barely three months later, Ivanti's April 2025 advisory for CVE-2025-22457 — a CVSS 9.0, unauthenticated remote-code-execution flaw that CISA added to the KEV catalog with a one-week federal deadline — confirmed that "End-of-Support Pulse Connect Secure 9.1x appliances… have been exploited at the time of disclosure." The advisory's remedy for the 9.x line was not a patch: "Customers' only option is to migrate." That case is now documented on our Exploited & Unpatchable feed — exploitation observed on the end-of-support line itself, with the vendor stating in writing that no code changes will come.
Working back from the deadline
The destination: 25.1.3 or later — noting its own End of Support already reads April 30, 2027, because Ivanti's N-2 policy keeps each minor in full support for roughly nine months. Staying supported on this platform is an operational treadmill, not a one-time upgrade. The hardware catch: per Ivanti's matrix, 25.1.2 and later run only on the newer ISA appliances (ISA 6500/8500 and their virtual equivalents) — so for fleets on older hardware, the January 31 software deadline is effectively a hardware refresh deadline. The federal calendar: BOD 26-02's twelve-month decommission deadline in early February 2027 is the outer bound; its continuous-discovery requirement (standing by early 2028) makes the 12-month EOS horizon a permanent watch item — which is exactly what deadline alerts and the EOS Edge Device List exist to feed.
Frequently Asked Questions
When does Ivanti Connect Secure 22.7 reach end of support?
January 31, 2027, per Ivanti's EOL Timelines and Support Matrix — and the same date applies to ICS 22.8 and the 25.1.0 through 25.1.2 releases. End of Engineering for 22.7 and 22.8 came a year earlier, on January 31, 2026, after which Ivanti says security updates and bug fixes continue only on a limited-effort basis. 25.1.3 carries a later End of Support date of April 30, 2027.
How does this interact with CISA BOD 26-02?
BOD 26-02, issued February 5, 2026, gives US federal civilian agencies twelve months to decommission listed end-of-support edge devices — a deadline landing in early February 2027, days after the January 31, 2027 End of Support for ICS 22.7/22.8/25.1.0–25.1.2. The directive also requires tracking any edge device reaching EOS within 12 months — a horizon these releases entered in January 2026. A federal ICS appliance on these releases has both clocks expiring the same week.
What happened when the 9.x line reached end of support?
Pulse Connect Secure 9.1x reached End of Support December 31, 2024. Three months later, Ivanti's advisory for CVE-2025-22457 (CVSS 9.0, KEV-listed) confirmed exploitation of end-of-support 9.1x appliances and stated the line "no longer receives any code changes… Customers' only option is to migrate." The full verified entry is on our Exploited & Unpatchable feed.
What should ICS fleets do before January 31, 2027?
Move to 25.1.3 or later, plan for the N-2 treadmill (each minor gets roughly nine months of full support), and check the hardware constraint — 25.1.2+ requires the newer ISA appliances, making this a hardware-refresh decision for older fleets. Federal agencies should work back from the BOD 26-02 February 2027 deadline.
Related
- Ivanti Connect Secure — every line with live status · The EOS Edge Device List
- End of support & the BOD 26-02 clock — all four directive deadlines
- Exploited & Unpatchable — including the CVE-2025-22457 × 9.1x entry
- BOD 26-04 & 26-02 explained — the deep dive on both directives