Azure DevOps Server TFS 2018 End of Life Date
Azure DevOps Server TFS 2018 end-of-life date, support status, and CVE risk. Data from endoflife.date and official vendor documentation.
Azure DevOps Server 2018 was released on November 15, 2017 and support is scheduled to end on January 11, 2028 — a planned supported lifespan of 10 years and 2 months, in line with the 10 years and 1 month median for Azure DevOps Server releases. Its most recent patch is 2018.3.2patch20, published April 8, 2025.
| Version | Latest | EOL Date | Status |
|---|---|---|---|
| TFS 2005 | 2005.SP2 | Jul 12, 2016 | EOL |
| TFS 2010 | 2010.SP1 | Jul 14, 2020 | EOL |
| TFS 2012 | 2012.4 | Jan 10, 2023 | EOL |
| TFS 2013 | 2013.5 | Apr 9, 2024 | EOL |
| TFS 2015 | 2015.4.2patch8 | Oct 14, 2025 | EOL |
| TFS 2017 | 2017.3.1patch15 | Jan 11, 2027 | Warning |
| → TFS 2018 | 2018.3.2patch20 | Jan 11, 2028 | Active |
| 2019 | 2019.0.1patch16 | Apr 10, 2029 | Active |
What does Azure DevOps Server TFS 2018 end of life mean?
When Azure DevOps Server TFS 2018 reaches end of life, the maintainers stop issuing security patches for this version. CVEs discovered after the EOL date are publicly disclosed on the National Vulnerability Database with no patch available. Exploit code frequently appears on GitHub within days of disclosure.
The CVE blind spot: Most vulnerability scanners check for known CVEs but do not flag the ongoing accumulation of unpatched vulnerabilities in EOL software versions. Running Azure DevOps Server TFS 2018 past its EOL date creates a permanently growing attack surface that standard security tooling will not surface.
Migrate to Azure DevOps Server Azure DevOps Server or implement compensating controls — network segmentation, enhanced monitoring, restricted access — while migration is underway.