endoflife.ai
End of Support EOS Edge Device List EOL Checker EOL Watch

Ivanti's Hardware Cliff: ISA6000 and ISA8000 Reach End of Life January 31, 2027 — and Take Connect Secure 22.x With Them

By Scott Bissett  ·  Published: September 2, 2026  ·  EOL Watch — news analysis  ·  Every date verified against Ivanti's End of Sale & End of Life notice for ISA6000 and ISA8000 (read September 2, 2026) and Ivanti's software support matrix

The boxes under the most-exploited VPN in CISA's catalog have an expiry date, and it is closer than most inventories show. Per Ivanti's End of Sale & End of Life notice, the ISA6000 and ISA8000 hardware appliances — the physical platform for Ivanti Connect Secure and Policy Secure since 2022 — reach end of support and end of life on the same day, January 31, 2027. Orders closed on January 31, 2026. Support and RMAs continue until the date, and then Ivanti's words are that service delivery “cannot be guaranteed.”

Two things make this more than a hardware refresh. First, the software goes with the hardware: Ivanti states that after January 31, 2027 no 22.x Connect Secure release is supported on any platform, and that the 22.7, 22.8, 25.1.0.x and 25.1.1.x lines entered End of Engineering retroactively on January 31, 2026. Second, the virtual appliances are caught in it too: the ISA4000-V, ISA6000-V and ISA8000-V track their terminal software releases and carry the same January 31, 2027 end of life. A fleet that thinks of this as “the old physical boxes” is under-counting.

The verified dates

Hardware milestones from Ivanti's notice (customer-portal knowledge base, created August 6, 2025, last modified August 31, 2026); software dates from Ivanti's release support matrix. Both are the sources our Ivanti Secure Appliance and Connect Secure pages re-verify; every cell below is bound to that data.

PlatformLast day to orderEnd of support = end of lifeReplacement
ISA8000 (c/f)January 31, 2026January 31, 2027ISA8500 (DDR5), shipping since March 2026
ISA6000January 31, 2026January 31, 2027ISA6500 (DDR5), shipping since March 2026
ISA8000-VJanuary 31, 2027ISA8500-V, no additional charge
ISA6000-VJanuary 31, 2027ISA6500-V, no additional charge
ISA4000-VJanuary 31, 2027ISA4500-V, no additional charge
Connect Secure lineGAEnd of EngineeringEnd of SupportRuns on the old hardware?
22.7May 21, 2024January 31, 2026 (retroactive)January 31, 2027Yes — dies with it
22.8July 24, 2025January 31, 2026 (retroactive)January 31, 2027Yes — dies with it
25.1.0September 24, 2025January 31, 2026 (retroactive)January 31, 2027Yes
25.1.1March 16, 2026January 31, 2026 (retroactive)January 31, 2027Yes — the last release that does
25.1.2May 1, 2026January 31, 2027No — ISA6500/8500 and the new virtuals
25.1.3July 31, 2026April 30, 2027No
The reason, in Ivanti's words: the five major memory manufacturers have announced the end of life of DDR4 RAM; every ISA6000 and ISA8000 carries a DDR4 component, and there is no path to upgrade memory inside the existing appliance. DDR5 requires new hardware. Ivanti says it secured enough supply to support the platform until January 2027 and no further — which is why an appliance line that started shipping in April and June 2022 is retiring after less than five years, and why Ivanti gave roughly eighteen months' notice rather than its usual runway.

Why this platform's deadline matters more than most

Ivanti Connect Secure — and Pulse Connect Secure before it — is the VPN product with the most consequential exploitation record of the decade. CISA's Known Exploited Vulnerabilities catalog lists fourteen entries for the product line: eight Pulse-era flaws added together on November 3, 2021, and the modern run below, which began with the January 2024 emergency directive and has continued through 2025. From CVE-2023-46805 onward, CISA's required action reads “apply mitigations per vendor instructions or discontinue use of the product” — the same doctrine that orders end-of-life routers unplugged, applied to an enterprise VPN.

CVEAdded to KEVWhat it was
CVE-2023-46805Jan 10, 2024Authentication bypass — paired with CVE-2024-21887 in the January 2024 emergency directive
CVE-2024-21887Jan 10, 2024Command injection; chained with CVE-2023-46805 for unauthenticated remote code execution
CVE-2024-21893Jan 31, 2024Server-side request forgery in the SAML component, exploited while the January patches were still rolling out
CVE-2025-0282Jan 8, 2025Stack-based buffer overflow, exploited as a zero-day before the fix shipped
CVE-2025-22457Apr 4, 2025Stack-based buffer overflow, exploited against appliances still on 22.7R2.5 and earlier

The pattern that matters for January 2027: every one of these was fixed by a software release on supported hardware. After the cliff, an ISA6000 or ISA8000 is on software that receives no new fixes on hardware that receives no support — the exact combination that put the Pulse-era appliances on the exploited-and-unpatchable list. CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them; this is the milestone it was written for.

Working back from January 31

The destination: ISA6500 or ISA8500 hardware, or the ISA4500-V/6500-V/8500-V virtual appliances, running Connect Secure 25.1.2.0 or later. Ivanti supports the 25.x line on a quarterly N-2 model — the current release plus two previous, roughly nine months each — so the target is “current 25.x,” not a fixed version. Ivanti offers a trade-in allowance against the new hardware, existing licences transfer without repurchase, and the virtual upgrades are free.

The trap: 25.1.1.0 runs on the old boxes and is tempting as a “get current” step. It is the last release that does, and Ivanti says it will answer questions on it after the hardware EOL but will not address hardware-related issues. Landing on 25.1.1.0 in 2026 is a bridge to the same cliff, not a way past it. Note too that 25.1.2.0 changed the licence-server model: it serves only the new platforms and subscription licences, so a mixed fleet needs separate licence-server instances during the migration.

The order of operations: (1) inventory every ISA6000, ISA8000 and ISA-V, physical and virtual, including the ones in secondary sites; (2) order replacement hardware now — the new models ship, but a January 2027 deadline with a hardware lead time is a Q4 2026 project, not a January one; (3) stage 25.1.2.0 or later on the new platform, test the licence-server split, then cut over; (4) decommission the old appliances rather than leaving them reachable, because a retired Connect Secure that still answers on the internet is the KEV pattern above waiting to repeat.

Facing an end-of-life deadline?
Tell us which product and we’ll reply with vetted extended-support options and pricing guidance — free, no obligation. Vendors don’t pay for placement.

Free · No obligation · Independent · dates verified against vendor sources · Not urgent? Follow the EOL radar or see the 2026 EOL calendar →

Frequently Asked Questions

When do the Ivanti ISA6000 and ISA8000 reach end of life?

January 31, 2027, per Ivanti's End of Sale and End of Life notice for the two models. End of support and end of life fall on the same day; support and RMAs continue until then. The last day to order either model was January 31, 2026.

Why is Ivanti retiring the ISA6000 and ISA8000 early?

The appliances use DDR4 RAM, which the major memory manufacturers have discontinued, and DDR5 is not backward compatible - there is no path to re-memory the existing units. Ivanti's replacements, the DDR5-based ISA6500 and ISA8500, have shipped since March 2026.

Does the ISA end of life affect Ivanti Connect Secure software?

Yes. Ivanti states that after January 31, 2027 no 22.x Connect Secure release is supported on any hardware, and that 22.7, 22.8, 25.1.0.x and 25.1.1.x entered End of Engineering retroactively on January 31, 2026. 25.1.1.0 is the last release supported on ISA6000 and ISA8000; 25.1.2.0 and later target the ISA6500 and ISA8500.

Are the virtual appliances affected too?

Yes. Ivanti's notice fixes the ISA4000-V, ISA6000-V and ISA8000-V virtual appliances at the same January 31, 2027 end of life, because they track their terminal software releases. Their successors are the ISA4500-V, ISA6500-V and ISA8500-V, which Ivanti offers as equivalent upgrades at no additional charge.

What should an ISA6000 or ISA8000 fleet do before January 31, 2027?

Move to ISA6500 or ISA8500 hardware, or to the new virtual appliances, and land on Connect Secure 25.1.2.0 or later, which Ivanti supports on a quarterly N-2 model of roughly nine months per release. Ivanti offers a trade-in allowance, and existing licences transfer without repurchase. Anything still on 22.x on January 31, 2027 is unsupported on every platform.

How does this relate to CISA's edge-device directive?

CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them. Ivanti Connect Secure has fourteen entries in CISA's Known Exploited Vulnerabilities catalog going back to the Pulse Secure era, five of them from 2024 and 2025 with a required action that includes discontinuing use of the product if mitigations cannot be applied. The ISA end of life is exactly the kind of milestone the directive is written around.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)