EOL by the Numbers
1. How fast software actually dies
We measured the full support lifespan of 7,144 software versions across 463 products in the endoflife.ai dataset — operating systems, runtimes, databases, frameworks, and tools. The median supported lifespan of a version is 18 months. Half of all software versions get less than a year and a half of patches from release to end of life.
2. The H2 2026 deadline pileup
Seven widely deployed products lose security support between September and December 2026 — one of the densest end-of-life windows on record:
| Date | Product | What ends |
|---|---|---|
| Sep 7, 2026 | OpenSSL 3.0 | Security fixes for the 3.0 LTS series end |
| Sep 30, 2026 | Oracle JDK 17 | Oracle support window closes |
| Oct 13, 2026 | Windows Server 2012 / 2012 R2 | Final Extended Security Update year ends — no patches at any price |
| Oct 31, 2026 | Python 3.10 | Security-only support ends |
| Nov 10, 2026 | .NET 8 and .NET 9 | LTS and STS support end on the same day |
| Nov 12, 2026 | PostgreSQL 14 | Five-year support window closes |
| Dec 31, 2026 | PHP 8.2 | Security support ends |
3. Actively exploited — and past end of life
Cross-referencing CISA's Known Exploited Vulnerabilities catalog (catalog version 2026.07.16, 1,647 entries) against the endoflife.ai lifecycle database: 24 technologies that appear by name in the KEV catalog also have versions past end of life — meaning attackers demonstrably exploit them in the wild, and for the EOL versions, no vendor patch will ever come. The list includes Windows and Windows Server, PHP, Node.js, Java, VMware products, Exchange, SharePoint, WordPress, Drupal, GitLab, Jenkins, Apache Tomcat, and the Spring Framework.
4. The 2026 CVE surge (context from FIRST)
Per FIRST's mid-year vulnerability forecast: the first half of 2026 produced 35,364 CVEs — more in six months than any full year before 2024 — with June 2026 the peak month at 7,454. FIRST projects roughly 66,000 CVEs for the full year, 46% above its own February estimate, attributing the surge to AI-assisted discovery. FIRST also notes exploitable risk has remained roughly flat: discovery is accelerating, not exploitation.
5. Even the dates themselves drift
In July 2026 we cross-checked the published end-of-life dates of 54 flagship products directly against vendor lifecycle documentation. Result: 11 vendor-published corrections — dates that had been revised by the vendor, slipped in practice, or were published as firm when the vendor had committed to nothing. We applied the corrections to our own data, documented each with its source, and filed the upstream fixes with the community database endoflife.date (6 pull requests, 1 issue).
6. The regulatory clock
Lifecycle awareness is becoming a legal obligation, not a hygiene practice. The EU Cyber Resilience Act's vulnerability-reporting obligations begin September 11, 2026 — during Black Hat/DEF CON week's aftermath and the same month three major EOL deadlines land. NIS2 and DORA already put unsupported components inside formal risk-management duties for covered entities.
Any statistic above may be reproduced with attribution. Suggested format:
Source: endoflife.ai, "EOL by the Numbers" (August 2026) — https://endoflife.ai/eol-by-the-numbersAll lifecycle dates behind these figures are tracked for 485 products and 8,000+ versions, cross-checked against vendor sources where verified (methodology), and available free via JSON API and MCP server. Press inquiries: [email protected].