endoflife.ai
Progress WS_FTP Server Progress MOVEit Transfer EOS Edge Device List Exploited & Unpatchable EOL Watch

Progress WS_FTP Server 9.0 Leaves Active Support on October 23, 2026

By Scott Bissett  ·  Published: October 10, 2026  ·  EOL Watch — deadline analysis  ·  Read at Progress's WS_FTP Product Support Lifecycle page and the WS_FTP Server release notes; lifecycle dates from that page as we serve them.

Progress gives its two current WS_FTP Server releases two years of Active support each, and for the 2024 release, version 9.0, those two years run out this month. The company's own WS_FTP Product Support Lifecycle page carries the line as "WS_FTP Server 2024 (9.0)" with three dates under three headings: ACTIVE October 23, 2024, SUNSET October 23, 2026, RETIRED April 23, 2027. The note beneath the table says the Active phase "starts during the month listed", so each column is the date a phase begins. From the Sunset date 9.0 stops getting service packs and hot fixes; six months later it is Retired.

What Sunset means, in Progress's own terms. The lifecycle page defines the phase: "No service packs or hot fixes are provided for versions of the product in the sunset phase. If a product defect is found and verified, Progress will make best effort to provide a work around but will not update the sunset phase version." Technical support itself continues ("Progress provides technical support to customers under warranty or covered by a current service agreement for their product"), and "Sunset phase begins the day after Active phase ends." So a 9.0 server in Sunset can still open a case. What the policy says it does not get is a fix: Progress "will advise migration to a newer version or related active product if that resolves the reported issue."
Quick answer: WS_FTP Server 9.0 enters Progress's Sunset phase on October 23, 2026 and is Retired on April 23, 2027. In Sunset, Progress's policy provides technical support but no service packs or hot fixes. The current release is WS_FTP Server 2025 (10.0), Active until its Sunset date of December 10, 2027. Every WS_FTP Server version's dates are on the Progress WS_FTP Server lifecycle page.

Every WS_FTP Server version Progress lists

Progress ships a WS_FTP Server major release roughly every year or two and names each by year, with the engineering version in brackets. Its lifecycle page lists three: 2025 (10.0), 2024 (9.0) and 2022 (8.8). Here they are with the three dates from that page as we serve them on the Progress WS_FTP Server page, plus the date of each line's most recent release from the WS_FTP Server release notes:

VersionStatusActive fromSunsetRetiredMost recent releaseProgress phase on the date of this article
2025 (10.0)SupportedDecember 10, 2025December 10, 2027June 9, 2028October 1, 2026Active
2024 (9.0)ApproachingOctober 23, 2024October 23, 2026April 23, 2027October 1, 2026Active, Sunset this month
2022 (8.8)EOLDecember 6, 2022January 3, 2026July 4, 2026August 28, 2025Retired

Two notes on the table. First, the Status column is the site's generic badge (Supported, Approaching, EOL), computed from the Retired date at every build; the last column is Progress's own phase name on the day this was written. Second, the 8.8 "Active from" date comes from the release notes, not the lifecycle page. The lifecycle page prints a January 2023 Active date for 8.8, but it also says "The Active phase starts during the month listed. The actual day varies based on the release schedule", and the WS_FTP Server 2022 release notes give the actual day as December 6, 2022. The Sunset and Retired dates are as printed. For 9.0 and 10.0 the release notes and the lifecycle page agree on the day.

The two newer lines each get two years of Active; 8.8 got three. Every line gets about six months of Sunset before it is Retired. Both Active lines are still taking releases: 9.0's most recent is dated October 1, 2026 and 10.0's October 1, 2026, which is what the Active phase looks like from the outside: Progress says service packs "are targeted to be delivered on a bi-monthly release cadence". That cadence stops for 9.0 on its Sunset date. Anything older than 8.8 is not on the page at all, and the page covers that too: "Releases not listed in the table below are considered Retired."

Active, Sunset, Retired: the three phases as Progress defines them

Progress uses the same three-phase model across its product lines, and the WS_FTP lifecycle page spells each phase out. Quoting the page, read in the browser on 9 and 10 October 2026:

Active.

"Progress provides technical support and product updates to customers under warranty or covered by a current service agreement for their product." Release types in this phase: "Service packs include corrections for multiple security and/or product defects. Service packs are targeted to be delivered on a bi-monthly release cadence." "Hot fixes are targeted corrections for security or product defects. Hot fixes are delivered on an as needed basis. Deployment of a hot fix will require the most recent service pack for the targeted major version." And: "Active phase starts when a major version is first made available for download on the Progress Community."

Sunset.

"No service packs or hot fixes are provided for versions of the product in the sunset phase. If a product defect is found and verified, Progress will make best effort to provide a work around but will not update the sunset phase version. Progress does not develop additional features and/or functionalities for the product and will advise migration to a newer version or related active product if that resolves the reported issue." "Sunset phase begins the day after Active phase ends."

Retired.

"Technical support will offer 'best effort' support which may require the customer upgrade to the most current version of their product to resolve a known product issue that is resolved within a more current version." "No product updates are provided for this version of the product." "Retired begins the day after Sunset phase ends."

The practical difference between Sunset and Retired is small for a security team and large for a help desk. In both phases the policy provides no service packs and no hot fixes. In Sunset you can still log a case and get an answer; in Retired the answer is best effort and may be "upgrade". Across all three phases the page repeats the same line: Progress "strongly recommends that customers upgrade to the most current version of their product" and "reserves the right to require that a customer upgrade to the most current version of their product to resolve a product issue."

Running WS_FTP Server past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers WS_FTP Server is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Where a 9.0 server goes

To WS_FTP Server 2025 (10.0), the only line Progress lists that stays Active after this month. Its dates on the lifecycle page as we serve them:

VersionActive fromSunsetRetired
2025 (10.0)December 10, 2025December 10, 2027June 9, 2028

A server moved to 10.0 now is inside Active until December 10, 2027 and Retired on June 9, 2028. Two things on the lifecycle page bear on the move itself. "New major versions must be activated on-line before they can be used. Updated activations are only provided for licenses covered by a current service agreement." So the upgrade is also a licensing check: a lapsed service agreement means no activation for 10.0, and under the Sunset terms no fixes for 9.0 either. And Progress's recommendation is the same in every phase: upgrade to the most current version. On a release train with one line Active at a time after this month, that is not advice so much as a description of the only supported state.

The exploitation record

WS_FTP Server has 1 entry in CISA's Known Exploited Vulnerabilities catalog, and 1 KEV entry for the product carries CISA's known-ransomware-campaign-use flag. The entry is CVE-2023-40044, which CISA names "Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability" (CWE-502), added to the catalog on October 5, 2023 with a federal due date of October 26, 2023. CISA's description, verbatim: "Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system." Its required action: "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable." Its knownRansomwareCampaignUse field reads "Known". The entry's notes point to Progress's September 2023 advisory and to the NVD record.

That flaw predates both 9.0 and 10.0. It is here because it shows what a WS_FTP Server is to an attacker: a box that exists to accept files from outside the organisation, usually reachable from the internet, running under an account that can write to disk. That is the same profile as its stablemate MOVEit Transfer, and the reason both sit on our EOS Edge Device List. The next flaw of this kind gets a service pack or hot fix on the lines in Active. Under the terms quoted above, a 9.0 server after its Sunset date is told to migrate.

What to do

On 9.0: plan the move to 10.0 ahead of October 23, 2026, and check the service agreement first, because 10.0 needs an online activation that Progress only issues to covered licences. The 9.0 line's most recent release is dated October 1, 2026; be on it before the move, since Progress's own hot-fix rule requires "the most recent service pack for the targeted major version".

On 8.8 or older: you are Retired already; 8.8 since July 4, 2026, and anything older by Progress's "not listed" rule. The same move to 10.0, sooner, and treat the server as unpatched for anything disclosed since its last release on August 28, 2025.

On 10.0: Active until December 10, 2027. Take the bi-monthly service packs as they land; the hot-fix rule means you cannot skip them and still get an emergency fix.

Everyone: the Progress WS_FTP Server page carries every version with its Active, Sunset and Retired dates, verified against the lifecycle page and refreshed at every build, so a new release Progress lists shows up there before it shows up here. The MOVEit Transfer page does the same for the other Progress file transfer product, which uses the same three phases on its own lifecycle page.

Frequently Asked Questions

When does Progress WS_FTP Server 9.0 reach end of life?

Progress's WS_FTP Product Support Lifecycle page lists 9.0 as Active from October 23, 2024, Sunset from October 23, 2026 and Retired from April 23, 2027. In Progress's own words, no service packs or hot fixes are provided for versions of the product in the Sunset phase, and in the Retired phase no product updates are provided and technical support is best effort.

What is the difference between Active, Sunset and Retired for WS_FTP Server?

Progress defines three phases. Active: technical support and product updates (service packs on a targeted bi-monthly cadence, hot fixes as needed) for customers under warranty or a current service agreement. Sunset: technical support continues but no service packs or hot fixes are provided; if a defect is verified Progress will make best effort to provide a work around but will not update the Sunset version. Retired: best-effort technical support that may require upgrading, and no product updates at all. Sunset begins the day after Active ends and Retired begins the day after Sunset ends.

Is WS_FTP Server 8.8 still supported?

No. On Progress's lifecycle page WS_FTP Server 2022 (8.8) entered Sunset on January 3, 2026 and has been Retired since July 4, 2026. Progress also states that releases not listed in its lifecycle table are considered Retired, which covers every version older than 8.8.

Which WS_FTP Server version should a 9.0 server move to?

The newest release, WS_FTP Server 2025 (10.0), which has been Active since December 10, 2025, with Sunset on December 10, 2027 and Retired on June 9, 2028. Progress strongly recommends that customers upgrade to the most current version of their product, and new major versions must be activated online, with updated activations only provided for licenses covered by a current service agreement.

Related

© 2026 endoflife.ai · How we verify our dates · API · About