EOL Products With Actively Exploited Vulnerabilities

This page tracks the one intersection that matters most for security prioritization: software that has reached end-of-life and has at least one vulnerability CISA has confirmed is being actively exploited. Neither endoflife.date nor the NVD alone tells you this — it takes cross-referencing both, daily.

For each entry below, the only real remediation is migrating to a newer major version — no supported release exists on the same major as the affected one. That's a stronger claim than "end-of-life" alone: some projects (the Linux kernel, WordPress) keep backporting security patches to old branches long after their listed EOL date, and some EOL minor releases still have a supported release in the same major — a routine update, not a migration. We exclude both cases rather than risk overstating the urgency. Only products with a verified no-fixes-after-EOL policy, and only entries that genuinely require a major version jump, make it onto this page — deliberately a short, conservative list.

Updated daily · last data refresh: October 7, 2026 · reflects CISA's KEV catalog as of the most recent daily sync, not a real-time feed.

CVESeverityAffected EOL products
CVE-2018-7602
Confirmed exploited — pre-KEV EPSS was 99.1%, superseded
9.8
Drupal 7.x — 1 EOL minor release, latest EOL January 5, 2025 · migrate to 10.6
CVE-2025-14847
Confirmed exploited — pre-KEV EPSS was 83.2%, superseded
7.5
MongoDB 3.x / 4.x / 5.x / 6.x — 6 EOL minor releases, latest EOL July 31, 2025 · migrate to 7.0
CVE-2026-9082
Confirmed exploited — pre-KEV EPSS was 15.7%, superseded
9.8
Drupal 8.x / 9.x — 7 EOL minor releases, latest EOL November 1, 2023 · migrate to 10.6

Frequently asked questions

What does 'end-of-life' (EOL) mean for a piece of software?

A release reaches end-of-life when its maintainer stops shipping security patches for it. The software keeps running exactly as before — nothing breaks on its own — but any vulnerability discovered afterward is never fixed by the vendor. From that point on, every new CVE against it is permanent.

Why is a CVE on an EOL product more dangerous than the same CVE on a supported one?

On a supported version, a critical CVE has a fix: update, and it's resolved. On an EOL version, there is no fix to apply — the only remediation is migrating to a version that still receives patches. The vulnerability itself isn't more severe, but the set of realistic responses shrinks to one, and that one takes longer than applying a patch.

What is CISA's KEV catalog, and why does it matter more than a CVSS score?

The Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency. A CVE is only added once there's evidence it's being exploited in the wild — not modeled, not theoretical. CVSS measures how bad a vulnerability could be; KEV confirms it already is being used by attackers. A KEV entry on software you can't patch is the highest-confidence signal you'll get that you're currently exposed.

What should I do if I can't migrate off an EOL product right away?

Migration is the only permanent fix, but if it can't happen immediately: restrict network exposure to only what's required, monitor the system more closely for compromise indicators, and treat the migration as a dated priority rather than an open-ended backlog item. This list exists to help you decide which EOL system to migrate first — the ones combining EOL status with confirmed active exploitation are the ones attackers are most likely probing for right now.

Get notified the moment this happens to your stack

Free — track up to 3 products in one project, daily checks, email alerts.

Create a free project