VMware Cloud Foundation End of Life: the 4.x Line Is Dead, 5.x Ends in 2027 — and VCF 9.0 Expires Before 5.2
VMware Cloud Foundation is the product Broadcom bet the VMware acquisition on — the full-stack bundle of ESXi, vCenter, vSAN, NSX and SDDC Manager that the entire portfolio has been consolidated into. Which makes its lifecycle table the most consequential set of dates in the post-Broadcom VMware estate, and that table currently says three things at once: every VCF 4.x release is already end of life (4.5, the last of the line, died May 31, 2025), VCF 5.0 and 5.1 both die June 1, 2027 — under ten months from today — and VCF 5.2 follows on October 11, 2027. The only release line with a future is VCF 9.x, sold under the subscription-only licensing model Broadcom moved VMware to after December 2023.
The table also contains a trap for anyone navigating by version number: VCF 9.0 reaches end of support on September 17, 2027 — 24 days before VCF 5.2 does. The newest-but-one platform release dies before the release four major versions behind it. If your upgrade plan says "get to 9.0 during 2027," it is a plan to shorten your support runway. More on that below.
And because VCF 9 is also where Broadcom folded what remains of Tanzu, this article answers the question a lot of people arrive here asking and find no clean answer to anywhere: what actually happened to VMware Tanzu?
The forced march: one line dead, one line closing, one exit
A VCF date is a bundle date. VMware Cloud Foundation ships ESXi, vCenter Server, vSAN, NSX and SDDC Manager as one validated bill of materials — VCF 4.x is built on the vSphere 7 generation (the 4.5 BOM lists ESXi 7.0 Update 3), VCF 5.x on vSphere 8, and VCF 9.0's bill of materials lists ESXi 9.0 and the 9.x component set. When a VCF release leaves support, the platform's supported combination leaves with it — which is why the VCF table deserves reading separately from the ESXi/vSphere dates we cover elsewhere.
The state of the three lines, plainly. The 4.x line is fully dead: eleven releases across 2.x/3.x/4.x are past end of support, several of the early 4.x releases had support windows measured in months (4.2 shipped February 2021 and ended that May; 4.0 lasted sixteen months), and the last survivor, 4.5, ended May 31, 2025. The 5.x line is closing on a compressed schedule: 5.0 (June 2023) and 5.1 (November 2023) share a single terminal date, June 1, 2027 — Broadcom did not give 5.1's five extra months of release lag any extra runway — while 5.2 (July 2024) runs to October 11, 2027. The 9.x line is the exit, and the only one: VCF 9.0 shipped June 17, 2025, 9.1 followed May 12, 2026, and Broadcom's forward roadmap for the flagship platform runs exclusively through it.
The licensing context matters as much as the dates. Since December 2023, Broadcom no longer sells VMware perpetual licenses or Support and Subscription renewals — the portfolio is subscription-only, a change widely documented in Broadcom's customer communications and covered in our ESXi/vSphere article. VCF 9 is the consolidation vehicle for that model: the SKUs Broadcom sells are subscriptions to the platform, not licenses to a version. We won't speculate on pricing here — quotes vary too much by estate to be honestly generalized — but the structural point is fixed: there is no path forward inside the Broadcom catalog that does not end in a VCF 9.x subscription.
One honesty note on sources: Broadcom's authoritative Product Lifecycle portal is a login-gated application we could not fetch directly for this article. The dates below are from our tracked lifecycle data — sourced from endoflife.date, which cites Broadcom's own release notes per cycle — and the Tanzu record is built from Broadcom's public knowledge-base notices, linked inline. Where the record is behind the login wall, we say so.
Every VMware Cloud Foundation version's dates
All 16 tracked VCF releases, newest first. Each version links to its lifecycle page with live status and risk score; this table is refreshed from the data layer at every site build, so the dates and badges below self-heal if Broadcom moves anything.
| Version | Released | End of support (EOL) | Status |
|---|---|---|---|
| VCF 9.1 | May 12, 2026 | Aug 12, 2028 | Supported |
| VCF 9.0 | Jun 17, 2025 | Sep 17, 2027 | Supported |
| VCF 5.2 | Jul 23, 2024 | Oct 11, 2027 | Supported |
| VCF 5.1 | Nov 7, 2023 | Jun 1, 2027 | Supported |
| VCF 5.0 | Jun 1, 2023 | Jun 1, 2027 | Supported |
| VCF 4.5 | Oct 11, 2022 | May 31, 2025 | EOL |
| VCF 4.4 | Feb 10, 2022 | Sep 30, 2024 | EOL |
| VCF 4.3 | Aug 24, 2021 | Oct 31, 2023 | EOL |
| VCF 4.2 | Feb 4, 2021 | May 25, 2021 | EOL |
| VCF 4.1 | Oct 6, 2020 | Feb 10, 2022 | EOL |
| VCF 4.0 | Apr 14, 2020 | Aug 24, 2021 | EOL |
| VCF 3.11 | Feb 14, 2022 | Apr 30, 2023 | EOL |
| VCF 3.10 | May 26, 2020 | Sep 1, 2022 | EOL |
| VCF 3.9 | Oct 24, 2019 | Oct 24, 2020 | EOL |
| VCF 3.8 | Jul 18, 2019 | Jul 18, 2020 | EOL |
| VCF 2.3 | Aug 15, 2018 | Nov 15, 2020 | EOL |
Dates from our tracked dataset (verification pass 2026-08-12), which sources Broadcom's per-release notes via endoflife.date. Broadcom's own lifecycle portal sits behind a login and can list additional milestones (such as end of technical guidance) beyond the end-of-support dates shown here — confirm there before signing anything. Live per-version status: the VCF lifecycle page.
The oddity: VCF 9.0 dies before VCF 5.2
Look at the top three rows of that table again. VCF 9.0 — released June 2025, the first release of the new platform generation — ends support September 17, 2027. VCF 5.2 — released July 2024, four major version numbers behind — ends October 11, 2027. The newer platform expires first, by 24 days.
There is no scandal in the mechanics: each release runs a fixed clock from its own dates, 9.0 got a roughly 27-month window, and 5.2's window happens to reach further into 2027. But the consequence is real and worth stating precisely, because it breaks the intuition nearly every upgrade plan is built on: "upgrade to the newer major version" and "extend your support runway" are not the same action. An estate that moves from 5.2 to 9.0 in mid-2027 lands on a release with less support remaining than the one it left. The correct landing for a 2027 upgrade is VCF 9.1 (supported to August 12, 2028) or whatever 9.x release is newest when you move.
This is the same lesson our data keeps teaching across vendors — version numbers order features, not lifecycles. Dates are the only thing to navigate by, and they need checking per release, not per line.
What happened to VMware Tanzu?
People search "VMware Tanzu EOL" and get a fog of SKU names, because what Broadcom did to Tanzu was not a single end-of-life event — it was a staged retirement of a portfolio, documented across knowledge-base notices rather than one announcement. Here is the record, limited to what Broadcom's public notices actually say.
The SKU record. Under VMware, "Tanzu" was an umbrella over many products — Tanzu Kubernetes Grid (TKG), Tanzu Kubernetes Grid Integrated (TKGi), Tanzu Application Platform, Tanzu Application Service, Tanzu Build Service and more. Broadcom's End of Availability notification states that "all legacy Tanzu SKUs have been retired as of May 6th, 2024," directing customers to the new Tanzu portfolio offerings and their account teams for the mapping. A second wave followed effective May 4, 2025: the first-generation Tanzu Platform SKUs (TNZ-PLAT, TNZ-PLAT-SM, TNZ-SPRING) and Tanzu Data SKUs (TNZ-DATA-SUITE, TNZ-TDSV) reached End of Availability, replaced by V2 successors — and Tanzu Platform SaaS reached End of Availability May 1, 2025. The surviving application-platform portfolio has been repositioned around Spring, private PaaS and AI workloads, per Broadcom's own announcements.
The Kubernetes runtime moved into VCF. The capability most searchers mean by "Tanzu" — running Kubernetes on vSphere — was not killed; it was renamed and absorbed. What was sold as the Tanzu Kubernetes Grid Service now ships as vSphere Kubernetes Service (VKS), a Supervisor Service inside VCF 9 — Broadcom's VKS release notes live under the VCF 9 documentation tree, at a URL that still carries the old tanzu-kubernetes-grid-service name. The standalone TKG product's documentation tops out at version 2.5, and its published support policy is N-2 with a minimum of 12 months per minor release — with the actual end dates listed only in Broadcom's login-gated Product Lifecycle portal, which we could not fetch and will not guess at.
The security floor: what the KEV catalog already says
End-of-life risk for a platform like VCF is not hypothetical, because the components it bundles have a documented exploitation record. We checked the live CISA Known Exploited Vulnerabilities catalog on August 11, 2026: it holds 32 VMware entries, and one of them — CVE-2021-21973, a vCenter Server SSRF — lists "vCenter Server and Cloud Foundation" as the affected products by name.
The entry that matters most for old VCF estates is CVE-2024-37085, the ESXi Active Directory authentication bypass, KEV-listed July 30, 2024 with known ransomware campaign use (Akira and Black Basta, per the reporting behind our feed entry). The chain is short and documented: VCF 4.x's bill of materials bundles ESXi 7.0 Update 3; Broadcom's advisory VMSA-2024-0013 lists ESXi 7.0 as affected with "No Patch Planned," shipping the fix only in ESXi 8.0 U3; and ESXi 7.0 reached end of general support October 2, 2025, so that patch is never coming. A VCF 4.x environment still running today therefore contains a hypervisor with a CISA-KEV-listed, ransomware-exploited, permanently unpatched vulnerability — which is why this CVE sits in our Exploited & Unpatchable feed. The mitigation is an Active Directory reconfiguration workaround, not a patch.
The honest limits of that claim: KEV listing means confirmed exploitation somewhere, not imminent compromise of your estate, and a segmented, workaround-applied 4.x environment is a different risk than an exposed one. But the direction is one-way — every future ESXi or vCenter CVE lands on the dead lines unfixed. The 5.x line stays patched until its 2027 dates; the 4.x line's exposure only grows.
The decision fork: the escalator or the exits
Path 1 — ride the Broadcom escalator. Upgrade to VCF 9.x — targeting 9.1 or newer, per the oddity above — and accept the subscription model. This keeps the VMware operational stack, skills and integrations intact, and for estates deeply built on vSAN/NSX/SDDC Manager automation it is often the lowest-execution-risk move. Its cost is a commercial commitment on Broadcom's terms; get a real quote before comparing anything against it.
Path 2 — hold on 5.x while you decide, with a hard boundary. VCF 5.2 is patched until October 11, 2027, and holding a supported release while evaluating is legitimate — but 5.0/5.1 estates have only until June 1, 2027, and a bundle upgrade of this size consumes quarters, not weeks. The date to plan backward from is your line's, not the line above it.
Path 3 — evaluate the exits. The post-Broadcom migration wave is real enough that we cover its two most common landing zones as first-class products: Proxmox VE — whose own 8-to-9 deadline is August 31, 2026 — and Nutanix AOS, whose lifecycle runs a much faster clock than vSphere's. Microsoft Hyper-V is the third common evaluation. None is a drop-in replacement for a full VCF stack — vSAN and NSX equivalence is exactly where these projects grow — and we advocate none of them; the sibling articles exist so the alternative lifecycles can be compared honestly rather than assumed. One fact worth weighing on every path: no third-party extended-support vendor ships security patches for out-of-support VCF releases. Past the dates, there is no rented bridge — only the escalator or an exit.
We track VMware Cloud Foundation and 480+ other products against vendor-verified dates — every VCF release, ESXi, Horizon, check any version in seconds, or see what else hits end of life this quarter.
VMware Cloud Foundation currently carries an EOL Risk Score™ of 45/100 — Grade C, elevated risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the VMware Cloud Foundation lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, a supported 5.x release buys the decision time — but for VCF no extended-support bridge exists past the dates. One to three years, commit now: 9.x subscription or a migration, scoped against a real Broadcom quote. Indefinitely, pick the platform whose licensing model you can live with long-term — and plan the next upgrade before it surprises you.
Frequently Asked Questions
When does VMware Cloud Foundation 5.2 reach end of life?
VMware Cloud Foundation 5.2 reaches end of support on October 11, 2027, per our tracked lifecycle data. It is the last 5.x release to expire: VCF 5.0 and 5.1 both end earlier, on June 1, 2027 — the same day, despite shipping five months apart. Every 4.x release is already end of life; 4.5, the last of that line, ended May 31, 2025. After the 5.x line closes, the only release line Broadcom supports is VCF 9.x.
Is VMware Tanzu end of life?
There is no single Tanzu end-of-life date, and that is the honest answer. Broadcom retired Tanzu as a standalone portfolio in stages: its notice states all legacy Tanzu SKUs were retired as of May 6, 2024; select Tanzu Platform and Tanzu Data SKUs reached End of Availability effective May 4, 2025; and Tanzu Platform SaaS reached End of Availability May 1, 2025. The Kubernetes runtime itself was not killed — it moved: the capability formerly sold as Tanzu Kubernetes Grid continues as vSphere Kubernetes Service (VKS) inside VMware Cloud Foundation 9. Per-SKU support end dates sit in Broadcom's login-walled Product Lifecycle portal, so anyone holding a Tanzu contract must map their specific SKU with their account team.
Does VCF 9.0 really go end of life before VCF 5.2?
Yes. VCF 9.0 reaches end of support September 17, 2027 — 24 days before VCF 5.2 does on October 11, 2027 — even though 9.0 is the newer platform by four major version numbers. Each release runs its own clock from its own release date, and 5.2 carries a longer window than 9.0 was given. The practical consequence: an estate that upgrades from 5.2 to 9.0 in 2027 shortens its support runway rather than extending it. The release with the longest published runway is VCF 9.1, supported to August 12, 2028.
What are the alternatives to upgrading to VCF 9?
Within the Broadcom catalog, none — the 4.x line is dead, the 5.x line ends between June and October 2027, and VCF 9.x is the only continuing release line, sold under the subscription-only licensing model Broadcom moved VMware to after December 2023. Outside the catalog, the commonly evaluated exits are Proxmox VE, Nutanix AOS with AHV, and Microsoft Hyper-V — each a real migration project with different tradeoffs, not a drop-in swap. No third-party extended-support vendor ships security patches for out-of-support VCF releases, so running past the dates means running unpatched.
Related
- All VMware Cloud Foundation versions with live status · VCF 5.2 — dates and risk score
- VMware ESXi & vSphere End of Life in the Broadcom Era — the hypervisor layer's dates and the perpetual-license story
- VMware / Omnissa Horizon End of Life — the VDI product Broadcom divested instead
- Proxmox VE 8 End of Life: August 31, 2026 — the most common open-source exit lane's own deadline
- Nutanix AOS 6.10 End of Life: October 31, 2026 — the HCI alternative's faster clock
- Exploited & Unpatchable — the KEV-listed CVEs that will never be fixed on EOL versions, ESXi 7.0 included
- The 2026 EOL Calendar — everything else with a date this year