EOL by the Numbers

Verified end-of-life software statistics · August 2026 edition · Last updated July 20, 2026 · Every number below links to its source. Journalists, researchers, and analysts: cite freely with attribution.

18 mo
Median supported lifespan of a software version — measured, not estimated
7
Major products reaching end of life between September and December 2026
24
Technologies named in CISA's exploited-vulnerabilities catalog with versions past EOL
~66,000
CVE disclosures projected for 2026 (FIRST mid-year forecast)

1. How fast software actually dies

We measured the full support lifespan of 7,144 software versions across 463 products in the endoflife.ai dataset — operating systems, runtimes, databases, frameworks, and tools. The median supported lifespan of a version is 18 months. Half of all software versions get less than a year and a half of patches from release to end of life.

"Across 7,144 measured software versions, the median supported lifespan is just 18 months (endoflife.ai Software Lifespan Study, 2026)." Source: The Software Lifespan Study — full methodology, per-category breakdowns, and the extremes.

2. The H2 2026 deadline pileup

Seven widely deployed products lose security support between September and December 2026 — one of the densest end-of-life windows on record:

DateProductWhat ends
Sep 7, 2026OpenSSL 3.0Security fixes for the 3.0 LTS series end
Sep 30, 2026Oracle JDK 17Oracle support window closes
Oct 13, 2026Windows Server 2012 / 2012 R2Final Extended Security Update year ends — no patches at any price
Oct 31, 2026Python 3.10Security-only support ends
Nov 10, 2026.NET 8 and .NET 9LTS and STS support end on the same day
Nov 12, 2026PostgreSQL 14Five-year support window closes
Dec 31, 2026PHP 8.2Security support ends
"Between September and December 2026, OpenSSL 3.0, Oracle JDK 17, Windows Server 2012's final ESU year, Python 3.10, .NET 8 and 9, PostgreSQL 14, and PHP 8.2 all reach end of life (endoflife.ai)." Source: The H2 2026 EOL Pileup — what stops on each date and the survival plan. Live countdowns: EOL Watch.

3. Actively exploited — and past end of life

Cross-referencing CISA's Known Exploited Vulnerabilities catalog (catalog version 2026.07.16, 1,647 entries) against the endoflife.ai lifecycle database: 24 technologies that appear by name in the KEV catalog also have versions past end of life — meaning attackers demonstrably exploit them in the wild, and for the EOL versions, no vendor patch will ever come. The list includes Windows and Windows Server, PHP, Node.js, Java, VMware products, Exchange, SharePoint, WordPress, Drupal, GitLab, Jenkins, Apache Tomcat, and the Spring Framework.

"24 technologies named in CISA's Known Exploited Vulnerabilities catalog also have versions past end of life — actively attacked, never to be patched (endoflife.ai analysis of KEV catalog v2026.07.16)." Method: name-match of KEV vendor/product fields against the endoflife.ai database; ecosystem-level exposure (e.g., a distro shipping a KEV-listed kernel) deliberately excluded from this count. Details: Risk Score methodology.

4. The 2026 CVE surge (context from FIRST)

Per FIRST's mid-year vulnerability forecast: the first half of 2026 produced 35,364 CVEs — more in six months than any full year before 2024 — with June 2026 the peak month at 7,454. FIRST projects roughly 66,000 CVEs for the full year, 46% above its own February estimate, attributing the surge to AI-assisted discovery. FIRST also notes exploitable risk has remained roughly flat: discovery is accelerating, not exploitation.

"For supported software, more CVE discovery means more patches. For end-of-life software, it only means a faster-growing pile of permanent, publicly documented vulnerabilities." Context and analysis: Gold Eagle Can't Patch What Nobody Maintains. Primary source for figures: FIRST, June 15, 2026.

5. Even the dates themselves drift

In July 2026 we cross-checked the published end-of-life dates of 54 flagship products directly against vendor lifecycle documentation. Result: 11 vendor-published corrections — dates that had been revised by the vendor, slipped in practice, or were published as firm when the vendor had committed to nothing. We applied the corrections to our own data, documented each with its source, and filed the upstream fixes with the community database endoflife.date (6 pull requests, 1 issue).

"Of 54 flagship products cross-checked against vendor lifecycle documentation, 11 required corrections — published EOL dates drift, and most consumers never notice (endoflife.ai verification program, July 2026)." Full corrections table, per-product sources, and methodology: endoflife.ai/accuracy. Machine-readable: verification.json.

6. The regulatory clock

Lifecycle awareness is becoming a legal obligation, not a hygiene practice. The EU Cyber Resilience Act's vulnerability-reporting obligations begin September 11, 2026 — during Black Hat/DEF CON week's aftermath and the same month three major EOL deadlines land. NIS2 and DORA already put unsupported components inside formal risk-management duties for covered entities.

"The CRA's reporting obligations start September 11, 2026 — the same month OpenSSL 3.0 and Oracle JDK 17 reach end of life." Analysis: the CRA's EOL problem · EU compliance hub.
How to cite this page
Any statistic above may be reproduced with attribution. Suggested format:
Source: endoflife.ai, "EOL by the Numbers" (August 2026) — https://endoflife.ai/eol-by-the-numbers

All lifecycle dates behind these figures are tracked for 485 products and 8,000+ versions, cross-checked against vendor sources where verified (methodology), and available free via JSON API and MCP server. Press inquiries: [email protected].