Palo Alto End of Life Has Two Clocks: Every PAN-OS Software Date, the Hardware Dates People Actually Search For, and Why 11.0 Died Before 10.2
"Palo Alto end of life" is really two different questions, and people ask both. One is about software: when does a PAN-OS release stop getting fixes? The other is about hardware: when does a firewall appliance — a PA-5250, say — stop being supported at all? Palo Alto Networks publishes the answers on two different pages, on two different clocks, and the clocks interlock in a way that decides real budgets: a PA-5200 Series box bought in 2022 is supported as hardware until August 31, 2028, but the newest operating system it will ever run leaves standard support on May 2, 2027.
This article keeps the two clocks separate and then shows where they connect. Along the way it covers the thing PAN-OS version numbers refuse to tell you — six times in this product's history, a newer release has died before an older one, including PAN-OS 11.0's death nine months ahead of 10.2, and the coming twin cliff where 11.2 expires one day before the older 11.1. And because this is a perimeter security appliance with one of the most serious exploitation records in CISA's Known Exploited Vulnerabilities catalog — twelve PAN-OS entries, six tied to known ransomware campaigns — the stakes of getting a date wrong are documented, not hypothetical.
Clock one, software: every PAN-OS release gets its own individually assigned death date
PAN-OS — the operating system on Palo Alto's firewalls — follows no fixed formula from release to end of life. Palo Alto Networks announces each release's end-of-life date individually, and the windows in the published record range from two years (11.0, 10.0) to more than four (9.1 got four and a half). The dates live on Palo Alto's software end-of-life summary, and we mirror them, re-verified nightly, in our tracked PAN-OS lifecycle data.
Two consequences follow from per-release dating. First, version order does not predict death order. Sort the catalog by end-of-life date and the version numbers shuffle: 3.0 died before the older 2.1, 6.0 before 5.1, 7.0 before 6.1, 10.0 a full two years before the older 9.1, 11.0 nine months before 10.2 — and in May 2027, 11.2 will die one day before the older 11.1. Six inversions. If your lifecycle intuition was trained on products where a higher number means a later date, PAN-OS breaks it routinely.
Second, the end-of-life date is not always the end of builds. Palo Alto's summary lists an Extended Support+ window for some trains after the standard date — 10.2's runs to March 31, 2027, and our tracked data shows the 10.2 train still receiving hotfix builds (10.2.18-h9 shipped July 21, 2026, eleven months after 10.2's end-of-life date). That tail is real, but it is an extension with its own wall, not a supported state — and as the KEV section below shows, what matters is which trains a fix actually ships for when an actively exploited vulnerability lands.
Clock two, hardware: end of sale, hardware end of life, and the last supported OS
The search data behind this article says plenty of people are asking about hardware end of life — "palo alto hardware end of life," "PA-5250 end of life" — and the software summary will not answer them. Hardware dates live on Palo Alto's separate hardware end-of-life summary, and each appliance row carries three things: an end-of-sale date (you can no longer buy it), a hardware end-of-life date roughly five years later (support ends entirely), and — the part that connects the two clocks — a last supported OS: the newest PAN-OS train that platform will ever be able to run.
Key platforms per Palo Alto's hardware end-of-life summary, fetched August 12, 2026 (this table is vendor-owned data reproduced for reference — confirm your exact model on the vendor page before committing budget):
| Hardware platform | End of sale | Hardware end of life | Last supported OS | Recommended replacement |
|---|---|---|---|---|
| PA-5200 Series (PA-5220, PA-5250, PA-5260, PA-5280) | Aug 31, 2023 | Aug 31, 2028 | PAN-OS 11.2 | PA-5400 / PA-5500 Series |
| PA-3200 Series (PA-3220, PA-3250, PA-3260) | Aug 31, 2023 | Aug 31, 2028 | PAN-OS 11.1 | PA-3400 Series |
| PA-800 Series (PA-820, PA-850) | Aug 31, 2024 | Aug 31, 2029 | PAN-OS 11.1 | PA-1400 Series |
| PA-220 | Jan 31, 2023 | Jan 31, 2028 | PAN-OS 10.2 | PA-400 / PA-500 Series |
| PA-7000 Series | Dec 31, 2025 | Dec 31, 2030 | PAN-OS 11.2 | PA-7500, PA-5450 |
The PA-5250 answer, in full: as part of the PA-5200 Series, it reached end of sale August 31, 2023, and its hardware end of life is August 31, 2028. Its last supported OS is PAN-OS 11.2 — it will never run PAN-OS 12. And that is where the clocks interlock: PAN-OS 11.2's own standard support ends May 2, 2027, roughly sixteen months before the hardware date. Palo Alto's pages handle the gap with a last-supported-OS rule — a release that is the final OS for a hardware platform remains supported for that hardware through the platform's end-of-life date (the software summary's own footnote to the Extended Support+ column says as much). So a PA-5250 is not orphaned in May 2027 — but from that point its operating system is a train the rest of the world has moved off, kept alive for legacy hardware. Every month past May 2027, a PA-5200 or PA-3200 estate is one step further from mainline fixes — on a device class attackers demonstrably hunt. For most fleets the honest reading of "hardware EOL August 31, 2028" is: the refresh budget belongs in 2027, and the May 2027 software cliff, not the 2028 hardware date, is the real deadline.
The 11.0 lesson: release-train math, not version numbers
If the two-clock confusion is the first way Palo Alto lifecycle planning goes wrong, version intuition is the second. Here is the cleanest example in the catalog. PAN-OS 11.0 was released November 17, 2022 — nine months after 10.2 (February 27, 2022). But 11.0 was assigned a two-year window and 10.2 a three-and-a-half-year one, so 11.0 died on November 17, 2024 — nine months before the older 10.2's August 27, 2025 date. Anyone who upgraded from 10.2 to 11.0 in 2023 "to stay current" moved onto the train that expired first.
What happened around 11.0's death date deserves the timeline treatment, because every fact in it is independently documented. Per our tracked data, the final 11.0 build ever — 11.0.6-h1 — shipped on November 17, 2024, 11.0's end-of-life date itself. Per Palo Alto's advisory for CVE-2024-0012, that build carried the fix for a CVSS 9.3 authentication bypass in the PAN-OS management web interface. The next day, November 18, 2024, CISA added CVE-2024-0012 to its Known Exploited Vulnerabilities catalog — together with CVE-2024-9474, an OS command injection that attackers were chaining with it to go from unauthenticated network access to root. Both KEV entries carry the known ransomware campaign use flag. So 11.0's very last day of life produced the patch for an actively exploited, ransomware-associated, chained attack — and every 11.0 device not updated to that final build by the time the train died is carrying the pair permanently.
The May 2027 twin cliff: 11.1 and 11.2, twenty-four hours apart, in reverse order
The next major deadline is really two: PAN-OS 11.2 dies May 2, 2027, and PAN-OS 11.1 dies May 3, 2027 — the sixth version-order inversion in the catalog, with the newer train expiring first, and both inside one 24-hour window just under nine months from this article's publication. Palo Alto's software summary lists both trains with an Extended Support+ window to August 31, 2027 — the same terminal date for both — so even the vendor tail ends in a single synchronized wall.
The twin cliff concentrates risk in a way single dates do not. 11.1 and 11.2 are the current mainstream trains for a large share of deployed hardware — including every PA-5200, PA-3200, PA-800 and PA-7000 Series device, for which one of them is the last supported OS. When both trains cross together, there is no "fall back to the adjacent release" move: the only supported directions are PAN-OS 12.1 (end of life August 28, 2028) or 12.2 (July 30, 2029) — and the EOL-hardware fleets listed above cannot take either. One date, two trains, and for a meaningful slice of the installed base the upgrade path is a forklift.
The KEV record: what end-of-fixes means on this specific product
The reason PAN-OS dates deserve this level of attention is not abstract. We pulled the live CISA Known Exploited Vulnerabilities catalog on August 12, 2026 (version 2026.08.10, 1,662 entries): it contains twelve PAN-OS entries — six flagged for known ransomware campaign use. (Three further Palo Alto entries cover Expedition, the migration tool, bringing the vendor total to fifteen.) Every row below is from the live catalog, not from memory:
| CVE | What it is | Added to KEV | Known ransomware use |
|---|---|---|---|
| CVE-2026-0257 | Authentication bypass allowing unauthorized VPN connections | May 29, 2026 | Yes |
| CVE-2026-0300 | Out-of-bounds write in the User-ID Authentication Portal (Captive Portal) — unauthenticated root code execution on PA-Series and VM-Series | May 6, 2026 | Unknown |
| CVE-2025-0111 | Authenticated file read via the management web interface | Feb 20, 2025 | Unknown |
| CVE-2025-0108 | Management web interface authentication bypass | Feb 18, 2025 | Unknown |
| CVE-2024-3393 | Malicious DNS packet — unauthenticated remote firewall reboot, repeated hits force maintenance mode | Dec 30, 2024 | Unknown |
| CVE-2024-9474 | Management interface OS command injection (privilege escalation; chained with CVE-2024-0012) | Nov 18, 2024 | Yes |
| CVE-2024-0012 | Management interface authentication bypass (chained with CVE-2024-9474) | Nov 18, 2024 | Yes |
| CVE-2024-3400 | GlobalProtect command injection — unauthenticated root command execution, CVSS 10.0 | Apr 12, 2024 | Yes |
| CVE-2022-0028 | URL filtering misconfiguration enabling reflected, amplified denial of service | Aug 22, 2022 | Unknown |
| CVE-2017-15944 | Chained remote code execution | Aug 18, 2022 | Unknown |
| CVE-2020-2021 | SAML authentication bypass | Mar 25, 2022 | Yes |
| CVE-2019-1579 | GlobalProtect portal/gateway remote code execution | Jan 10, 2022 | Yes |
Three patterns in that table matter for lifecycle planning. First, the VPN surface recurs: GlobalProtect remote code execution appears in 2019 (CVE-2019-1579) and again in 2024 — CVE-2024-3400, a CVSS 10.0 unauthenticated command injection affecting PAN-OS 10.2, 11.0 and 11.1 firewalls with a GlobalProtect gateway or portal configured, which Palo Alto acknowledged was under increasing attack — and again in 2026 as a VPN authentication bypass (CVE-2026-0257). The exact feature that makes a firewall internet-facing by design is the one attackers keep coming back to. Second, old trains stay hunted: a 2017 CVE entered the catalog in 2022, five years after disclosure. CISA adds entries on evidence of current exploitation — attackers demonstrably work the back catalog, which is exactly where EOL devices live. Third, the tempo is accelerating: two PAN-OS entries were added in May 2026 alone, with three-day federal remediation deadlines under CISA's BOD 26-04 regime — deadlines that assume a patch exists to apply. On a train past its end of fixes, that assumption fails permanently: this is the same product class and the same failure mode as FortiOS 7.2's September 30 cliff, where FortiOS 7.0 became permanently unpatchable against a KEV-listed CVE ten months after its end of support. Our Exploited & Unpatchable feed tracks that intersection — KEV-listed vulnerabilities that end-of-life versions will never receive fixes for — across the whole perimeter-appliance category.
Every PAN-OS version's dates
All lifecycle dates from our tracked PAN-OS lifecycle data, current as of the verification pass on August 12, 2026; Extended Support+ dates from Palo Alto's software end-of-life summary, same date. Each version links to its lifecycle page with live status and risk score.
| Version | Status | Released | End of Life (standard support ends) | Vendor Extended Support+ |
|---|---|---|---|---|
| PAN-OS 12.2 | Supported | Jul 30, 2026 | Jul 30, 2029 | to Jul 30, 2030 |
| PAN-OS 12.1 | Supported | Aug 28, 2025 | Aug 28, 2028 | to Aug 28, 2029 |
| PAN-OS 11.2 | Supported | May 2, 2024 | May 2, 2027 | to Aug 31, 2027 |
| PAN-OS 11.1 | Supported | Nov 3, 2023 | May 3, 2027 | to Aug 31, 2027 |
| PAN-OS 11.0 | EOL | Nov 17, 2022 | Nov 17, 2024 | — |
| PAN-OS 10.2 | EOL | Feb 27, 2022 | Aug 27, 2025 | to Mar 31, 2027 |
| PAN-OS 10.1 | EOL | May 31, 2021 | Dec 1, 2024 | ended Mar 31, 2026 |
| PAN-OS 10.0 | EOL | Jul 16, 2020 | Jul 16, 2022 | — |
| PAN-OS 9.1 | EOL | Dec 13, 2019 | Jun 30, 2024 | — |
| PAN-OS 9.0-XFR (VM-Series only) | EOL | Sep 19, 2019 | Sep 19, 2020 | — |
| PAN-OS 9.0 | EOL | Feb 6, 2019 | Mar 1, 2022 | — |
| PAN-OS 8.1 | EOL | Mar 1, 2018 | Mar 1, 2022 | — |
| PAN-OS 8.0 | EOL | Jan 29, 2017 | Oct 31, 2019 | — |
| PAN-OS 7.1 | EOL | Mar 29, 2016 | Jun 30, 2020 | — |
| PAN-OS 7.0 | EOL | Jun 4, 2015 | Dec 4, 2017 | — |
| PAN-OS 6.1 | EOL | Oct 25, 2014 | Oct 25, 2018 | — |
| PAN-OS 6.0 | EOL | Jan 19, 2014 | Mar 19, 2017 | — |
| PAN-OS 5.1 | EOL | May 9, 2013 | May 9, 2017 | — |
| PAN-OS 5.0 | EOL | Nov 13, 2012 | Nov 13, 2016 | — |
| PAN-OS 4.1 | EOL | Oct 31, 2011 | Apr 30, 2015 | — |
| PAN-OS 4.0 | EOL | Feb 22, 2011 | Dec 31, 2014 | — |
| PAN-OS 3.1 | EOL | Mar 15, 2010 | Jun 30, 2013 | — |
| PAN-OS 3.0 | EOL | Jun 17, 2009 | Dec 17, 2010 | — |
| PAN-OS 2.1 | EOL | Jan 5, 2009 | Jan 5, 2012 | — |
| PAN-OS 2.0 | EOL | May 20, 2008 | May 20, 2009 | — |
| PAN-OS 1.3 | EOL | Nov 15, 2007 | Nov 20, 2008 | — |
"End of Life" is the date on Palo Alto Networks' software end-of-life summary at which standard support ends. The Extended Support+ column reproduces the vendor's published extension windows where one is listed; a release that is the last supported OS for a hardware platform additionally remains supported for that hardware through the platform's own end-of-life date, per the vendor's footnotes. Our mirrored dates are re-verified nightly against the upstream endoflife.date dataset, whose cited source is Palo Alto's summary page.
The decision fork: 12.1, 12.2 — or new hardware
For estates on 11.1 or 11.2, the May 2027 twin cliff leaves two supported software landings, gated by one hardware question.
PAN-OS 12.1 — the established current train. Released August 28, 2025, with a year of field history behind it; end of life August 28, 2028, with a vendor Extended Support+ window to August 28, 2029. The conservative pick, at the cost of the nearer next upgrade.
PAN-OS 12.2 — the longest runway. Released July 30, 2026, only weeks old at this article's publication; end of life July 30, 2029, Extended Support+ to July 30, 2030. It resets the clock furthest at the cost of field maturity — a reasonable target for estates that upgrade rarely, once early-release hotfix cadence settles.
The hardware gate comes first. No PA-5200, PA-3200, PA-800 or PA-220 device can land on either 12.x train — their last supported OS is 11.2 or older, per the hardware table above. For those fleets, the software decision is the hardware decision: the May 2027 cliff is a refresh project with lead times measured in quarters, not a version bump. Check your exact models against Palo Alto's hardware end-of-life summary before writing the 2027 plan — an upgrade plan that ignores the hardware gate gets discovered by its exceptions.
One scope note, because the product names invite confusion: PAN-OS is the firewall operating system. Cortex XDR, Palo Alto's endpoint product, runs its own agent lifecycle on its own dates — we track it separately on the Cortex XDR lifecycle page.
We track PAN-OS and 480+ other products against vendor-verified dates — every PAN-OS version with live status, check any version in seconds, or see what else hits end of life this quarter.
PAN-OS currently carries an EOL Risk Score™ of 40/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the PAN-OS lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.
Frequently Asked Questions
When does PAN-OS 11.1 and 11.2 support end?
Within twenty-four hours of each other, in May 2027 — and in reverse version order. PAN-OS 11.2 reaches end of life May 2, 2027; the older PAN-OS 11.1 follows on May 3, 2027. Palo Alto Networks sets each release its own end-of-life date at announcement, so the dates do not sort by version number. Both trains are also listed with a vendor Extended Support+ window to August 31, 2027 on Palo Alto's end-of-life summary — a tail measured in months, not a second life. The supported landings are PAN-OS 12.1 (end of life August 28, 2028) and 12.2 (July 30, 2029).
What is the difference between Palo Alto software end of life and hardware end of life?
They are two separate clocks, published on two separate Palo Alto Networks pages. Software end of life is per PAN-OS release — PAN-OS 10.2 ended standard support August 27, 2025; 11.1 and 11.2 end in May 2027 — and lives on the software end-of-life summary. Hardware end of life is per appliance model: each platform gets an end-of-sale date, a hardware end-of-life date roughly five years later, and a last supported OS — the newest PAN-OS train that hardware will ever run. The clocks interlock: the PA-5200 Series reaches hardware end of life August 31, 2028, and its last supported OS is PAN-OS 11.2, whose own standard support ends May 2, 2027 — the box outlives its final operating system's standard support by roughly sixteen months.
When is the PA-5250 end of life?
The PA-5250 belongs to the PA-5200 Series (PA-5220, PA-5250, PA-5260, PA-5280), which Palo Alto Networks lists with an end-of-sale date of August 31, 2023 and a hardware end-of-life date of August 31, 2028, per its hardware end-of-life summary as of August 2026. Its last supported OS is PAN-OS 11.2 — the series will never run PAN-OS 12 — and the recommended replacements are the PA-5400 and PA-5500 Series. Note the software clock inside that window: PAN-OS 11.2's standard support ends May 2, 2027, over a year before the hardware date.
Is PAN-OS 10.2 still supported?
Standard support for PAN-OS 10.2 ended August 27, 2025 — its end-of-life date has passed. It is not yet fully abandoned: Palo Alto's end-of-life summary lists an Extended Support+ window for 10.2 to March 31, 2027, and the train is still receiving builds (10.2.18-h9 shipped July 21, 2026, per our tracked data). But that is a closing vendor extension, not a supported state. When the window shuts, 10.2 joins 11.0 and every older train in the state the KEV record makes concrete: any vulnerability found after the end of fixes stays exploitable on that train forever. Plan the exit to 12.1 or 12.2 now rather than at the wall.
Related
- All PAN-OS versions with live status · PAN-OS 11.1 — dates and risk score · PAN-OS 11.2 — dates and risk score · Cortex XDR lifecycle
- FortiOS 7.2 End of Support Is September 30, 2026 — the same perimeter-appliance story one vendor over: what happened when FortiOS 7.0 crossed its line
- Exploited & Unpatchable — the verified feed of KEV-listed vulnerabilities that end-of-life versions will never get fixes for
- CISA's 2026 Directives, Plainly — BOD 26-02's order to get end-of-support devices off the network edge
- The 2026 EOL Calendar — everything else with a date this year