Security Intelligence · Updated 2026-08-08
Exploited & Unpatchable
Some vulnerabilities are being exploited right now — on software the vendor will never fix. This list is the intersection of two public facts that normally live apart: CISA's Known Exploited Vulnerabilities catalog (what attackers are actually using) and verified end-of-life data (which versions have run out of patches). When a version appears in both, the fix ships only to supported releases and never reaches the dead one. Every entry below is verified by hand against the vendor's own advisory.
12Verified entries
9Products
100%Primary-source verified
DailyRadar review
What qualifies
A CVE on CISA's Known Exploited Vulnerabilities catalog that affects one or more product versions past their vendor end-of-life date, where the vendor's fix ships only in supported versions and no update is expected for the end-of-life line. If a vendor later backports a fix to an end-of-life version, that entry is removed. Conservative by design — an entry is listed only when the vendor's affected-versions and fixed-versions lists both confirm the gap.
Unauthenticated remote code execution via the agent polling protocol (Deserialization of untrusted data)
End-of-life versions affected — no fix will come
2025.07 2025.03 2024.12 2024.07 2024.03 2023.11 2023.05 2022.10 2022.04
Fixed only in
2025.11.7, 2026.1.3
Why it stays unpatched
JetBrains provides security fixes only for the current and immediately previous release lines. The fix exists solely in 2025.11.7 and 2026.1.3; every earlier line is past end of support and receives no update for this actively exploited flaw.
Symlink-based persistence that survives patching — a post-exploitation weakness abused after a threat actor has already exploited a separate filesystem-level vulnerability. KEV-listed by CISA. (Improper link resolution / persistence)
End-of-life versions affected — no fix will come
7.0 6.4
Fixed only in
7.6.2, 7.4.7
Why it stays unpatched
Fortinet's advisory FG-IR-25-934 lists 'FortiOS 7.0 all versions' and '6.4 all versions' as affected, and gives their only remediation as 'Migrate to a fixed release' — no fixed build is or will be published for either branch. FortiOS 7.0 reached end of support 2025-09-30 and 6.4 on 2024-09-30. (The current 7.2 branch is also given no build but is excluded here because it remains supported until 2026-09-30.)
Remote code execution via the Jolokia JMX-HTTP bridge — effectively unauthenticated on the 6.0 and 6.1 lines (the console's Jolokia endpoint sits outside the security constraints per CVE-2024-32114), and authenticated on the 5.x lines (Exposure of a management interface (JMX via Jolokia))
End-of-life versions affected — no fix will come
6.1 6.0 5.18 5.17 5.16
Fixed only in
5.19.4, 6.2.3
Why it stays unpatched
The fix ships only in the 5.19.x line (5.19.4) and in 6.2.3. Every ActiveMQ line below that — 6.0, 6.1, and 5.16 through 5.18 — is past end of life and receives no backport; all fall within the vendor's affected range with no available patch. The 6.0/6.1 lines are the most exposed, being effectively unauthenticated.
Authenticated remote code execution via PHP object deserialization in the file-upload handler (the _from request parameter). The vulnerable code path had been present in the codebase for roughly a decade. (Deserialization of untrusted data (RCE))
End-of-life versions affected — no fix will come
1.4 1.3 1.2
Fixed only in
1.5.10, 1.6.11
Why it stays unpatched
The fix shipped only in 1.5.10 and 1.6.11. NVD's authoritative affected range (versionStartIncluding 0, versionEndExcluding 1.5.10) places the 1.4, 1.3 and 1.2 lines within scope, and no fixed point release was issued for any of them — all three are past end of life. Basis is stated explicitly (NVD range plus the documented decade-long presence of the deserialization path); the entry is removed if a backport later appears.
Active Directory integration authentication bypass — a member of a domain group named 'ESX Admins' gains full host administrative access. Exploited in the wild by ransomware operators (Akira, Black Basta). (Authentication bypass)
End-of-life versions affected — no fix will come
7.0
Fixed only in
ESXi 8.0 U3 (ESXi80U3-24022510)
Why it stays unpatched
Broadcom's own advisory matrix (VMSA-2024-0013) lists ESXi 7.0 as affected with fixed version 'No Patch Planned' — the fix ships only in 8.0 U3, and Broadcom stated in writing that 7.0 will receive no patched build. Only a manual Active Directory reconfiguration workaround exists. ESXi 7.0 reached end of general support on 2025-10-02, so no update will come.
Improper authorization allowing an unauthenticated attacker to reset Confluence and create an administrator account, leading to full compromise. Mass-exploited (including ransomware) since November 2023. (Improper authorization)
End-of-life versions affected — no fix will come
7.0–7.18 (non-LTS) 6.x 5.x
Fixed only in
7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1
Why it stays unpatched
The only 7.x fix shipped on the 7.19 LTS line (7.19.16); every earlier non-LTS 7.x branch and all of 6.x and 5.x fall under the advisory's 'all versions prior to the listed fix versions' and received no fixed release for this actively exploited authorization bypass. All are past end of life (Confluence Server as a whole reached end of life 2024-02-15). This is a distinct CVE from the other Confluence entries; the 8.0–8.2 branches are deliberately excluded as a normal non-LTS lifecycle case rather than an abandoned-branch one.
Unauthenticated OGNL injection allowing remote code execution. Mass-exploited in the wild since June 2022. (OGNL expression injection (RCE))
End-of-life versions affected — no fix will come
6.x
Fixed only in
7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1
Why it stays unpatched
Atlassian's advisory names every release after 1.3.0 as affected but shipped fixes only on the 7.4 and 7.13–7.18 branches. Confluence 6.x was already past end of life at the June 2022 disclosure and received no fixed build for this actively exploited RCE. (Confluence Server as a whole reached end of life 2024-02-15.) Branches that did receive a per-branch backport are deliberately excluded.
Improper validation of the recipient address in deliver_message() allowing remote command execution as root ('Return of the WIZard'). Mass-exploited in the wild. (Improper input validation (RCE))
End-of-life versions affected — no fix will come
4.91
Fixed only in
4.92
Why it stays unpatched
The Exim advisory names 4.87 through 4.91 as affected and delivers the fix only as the forward 4.92 release — no patched build was issued for the 4.91 line, which reached end of life 2019-02-10. Under Exim's model the only remediation is to upgrade off the dead branch.
Remote code execution via the DataImportHandler dataConfig request parameter, which accepts a full DIH configuration including a script transformer. (Unsafe configuration accepted at request time (RCE))
End-of-life versions affected — no fix will come
7 6 5
Fixed only in
8.2.0
Why it stays unpatched
The mitigation exists only from Solr 8.2.0 onward; no fixed release was issued for the 7.x, 6.x or 5.x lines, all past end of life. The DataImportHandler that carries the flaw shipped in every one of these versions, and none received a backport.
Unauthenticated OGNL injection allowing remote code execution. Widely exploited since 2021 and on CISA's KEV catalog. (OGNL expression injection (RCE))
End-of-life versions affected — no fix will come
6.0–6.12
Fixed only in
6.13.23, 7.4.11, 7.11.6, 7.12.5, 7.13.0
Why it stays unpatched
Atlassian's advisory lists the 4.x, 5.x and 6.0–6.12 lines among affected versions but issued fixed builds only on 6.13, 7.4, 7.11, 7.12 and 7.13. The 6.0–6.12 lines were past end of life at disclosure and received no fixed build for this actively exploited RCE. The 6.13 branch, which did receive a backport, is excluded.
Forced OGNL double-evaluation of attacker-supplied input allowing remote code execution (S2-061). (OGNL expression injection (RCE))
End-of-life versions affected — no fix will come
2.3
Fixed only in
2.5.26
Why it stays unpatched
S2-061 lists the affected range as Struts 2.0.0 through 2.5.25 and ships the fix only in 2.5.26. The Struts 2.3 line ended at 2.3.37 and reached end of life on 2019-05-14 — eighteen months before this advisory — so no 2.3.x fix was ever released. A 2.3.x install cannot patch in place. (The 2.5 line is excluded: 2.5.26 is a same-line fix and 2.5 was supported until 2024-04-30.)
Remote code execution via the VelocityResponseWriter when params.resource.loader.enabled is set, allowing a Velocity template to be supplied and executed. (Server-side template injection (RCE))
End-of-life versions affected — no fix will come
7 6 5
Fixed only in
8.4
Why it stays unpatched
The vulnerable parameters-based resource loader was removed only in Solr 8.4; no fixed release was issued for the 7.x, 6.x or 5.x lines (the 7.x line ended at 7.7.2), all past end of life. Every one of these versions is inside the vendor's 5.0.0–8.3.1 affected range with no available patch.
Methodology
This feed exists because two datasets that answer half the question each normally live in separate worlds. CISA's Known Exploited Vulnerabilities catalog tells you a vulnerability is being exploited in the wild. Lifecycle data tells you whether a given version still receives fixes. The dangerous case — exploited and unpatchable — is where they overlap, and until you join them by hand, no single source shows it.
How each entry is verified
For every entry we confirm, from primary sources: (1) the CVE is on CISA's KEV catalog; (2) the vendor's security advisory lists the specific version as affected; (3) that version is past its end-of-life date in our verified lifecycle data; and (4) the vendor's fix ships only in supported versions, leaving the end-of-life line without an update. Every entry links its KEV record, the vendor advisory, the NVD detail, and our lifecycle page so you can check our work. Each carries the date it was last reviewed.
What this is not
We do not detect exploitation ourselves — that signal comes from CISA. We do not publish exploit code, proof-of-concept detail, or anything that is not already public in the sources we link. This is an aggregation of public facts, arranged so defenders can answer one specific question — "is anything in my stack both actively exploited and past the point of a fix?" — in one place instead of five.
When an entry disappears
Vendors occasionally ship an out-of-band fix for an end-of-life version. When that happens, the entry no longer qualifies and is removed — because the claim on this page must stay true. A shrinking list is a feature: it means a fix arrived where none was expected.
Using the data
The full feed is available as JSON at /exploited-and-unpatchable.json, free, with attribution to endoflife.ai. Version-level risk scoring for any product is in the API (/v1/score/{product}/{version} returns the EOL date, days past EOL, CISA KEV exposure, and the EOL Risk Score in one call). Building lifecycle-aware security tooling and want a richer feed? [email protected].