EOL Products With Actively Exploited Vulnerabilities

This page tracks the one intersection that matters most for security prioritization: software that has reached end-of-life and has at least one vulnerability CISA has confirmed is being actively exploited. Neither endoflife.date nor the NVD alone tells you this — it takes cross-referencing both, daily.

Every row below is unpatchable by definition: the vendor no longer ships fixes for that version, and the vulnerability isn't theoretical — it's in CISA's Known Exploited Vulnerabilities (KEV) catalog. If a product in your stack shows up here, migration isn't a nice-to-have. It's the only way to close the hole.

Updated daily · last data refresh: August 4, 2026 · reflects CISA's KEV catalog as of the most recent daily sync, not a real-time feed.

CVESeverityAffected EOL products
CVE-2026-63030
Confirmed exploited — pre-KEV EPSS was 98.4%, superseded
9.8
Wordpress 6.9 — EOL May 20, 2026 · migrate to 7.0
CVE-2026-31431
Confirmed exploited — pre-KEV EPSS was 94.5%, superseded
7.8
Linux 5.4 — EOL December 3, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.5 — EOL November 28, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.3 — EOL July 11, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.0 — EOL January 12, 2023 · migrate to 7.1, 6.18, 6.12
Linux 4.19 — EOL December 5, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.19 — EOL October 24, 2022 · migrate to 7.1, 6.18, 6.12
Linux 6.15 — EOL August 20, 2025 · migrate to 7.1, 6.18, 6.12
Linux 5.13 — EOL September 18, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.19 — EOL April 22, 2026 · migrate to 7.1, 6.18, 6.12
Linux 6.16 — EOL October 12, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.17 — EOL December 18, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.4 — EOL September 13, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.7 — EOL April 3, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.10 — EOL October 10, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.14 — EOL November 21, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.9 — EOL July 27, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.2 — EOL May 17, 2023 · migrate to 7.1, 6.18, 6.12
Linux 5.18 — EOL August 21, 2022 · migrate to 7.1, 6.18, 6.12
Linux 6.14 — EOL June 10, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.8 — EOL May 30, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.13 — EOL April 20, 2025 · migrate to 7.1, 6.18, 6.12
Linux 5.16 — EOL April 13, 2022 · migrate to 7.1, 6.18, 6.12
Linux 5.11 — EOL May 19, 2021 · migrate to 7.1, 6.18, 6.12
Linux 4.14 — EOL January 10, 2024 · migrate to 7.1, 6.18, 6.12
Linux 7.0 — EOL June 27, 2026 · migrate to 7.1, 6.18, 6.12
Linux 5.12 — EOL July 20, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.11 — EOL December 5, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.17 — EOL June 14, 2022 · migrate to 7.1, 6.18, 6.12
CVE-2026-9082
Confirmed exploited — pre-KEV EPSS was 88.3%, superseded
9.8
Drupal 8.9 — EOL November 2, 2021 · migrate to 11.4, 11.3, 10.6
Drupal 9.4 — EOL June 21, 2023 · migrate to 11.4, 11.3, 10.6
Drupal 9.0 — EOL June 16, 2021 · migrate to 11.4, 11.3, 10.6
Drupal 9.5 — EOL November 1, 2023 · migrate to 11.4, 11.3, 10.6
Drupal 9.3 — EOL December 14, 2022 · migrate to 11.4, 11.3, 10.6
Drupal 10.5 — EOL June 17, 2026 · migrate to 11.4, 11.3, 10.6
Drupal 9.1 — EOL December 8, 2021 · migrate to 11.4, 11.3, 10.6
Drupal 10.0 — EOL December 15, 2023 · migrate to 11.4, 11.3, 10.6
Drupal 10.1 — EOL June 20, 2024 · migrate to 11.4, 11.3, 10.6
Drupal 10.4 — EOL December 10, 2025 · migrate to 11.4, 11.3, 10.6
Drupal 10.3 — EOL June 16, 2025 · migrate to 11.4, 11.3, 10.6
Drupal 9.2 — EOL June 15, 2022 · migrate to 11.4, 11.3, 10.6
Drupal 11.1 — EOL December 10, 2025 · migrate to 11.4, 11.3, 10.6
Drupal 11.0 — EOL June 16, 2025 · migrate to 11.4, 11.3, 10.6
Drupal 10.2 — EOL December 17, 2024 · migrate to 11.4, 11.3, 10.6
Drupal 11.2 — EOL June 17, 2026 · migrate to 11.4, 11.3, 10.6
CVE-2025-14847
Confirmed exploited — pre-KEV EPSS was 83.0%, superseded
7.5
MongoDB 4.0 — EOL April 30, 2022 · migrate to 8.3, 8.0, 7.0
MongoDB 5.0 — EOL October 31, 2024 · migrate to 8.3, 8.0, 7.0
MongoDB 4.2 — EOL April 30, 2023 · migrate to 8.3, 8.0, 7.0
MongoDB 3.6 — EOL April 30, 2021 · migrate to 8.3, 8.0, 7.0
MongoDB 4.4 — EOL February 29, 2024 · migrate to 8.3, 8.0, 7.0
MongoDB 8.2 — EOL July 31, 2026 · migrate to 8.3, 8.0, 7.0
MongoDB 6.0 — EOL July 31, 2025 · migrate to 8.3, 8.0, 7.0
CVE-2026-60137
Confirmed exploited — pre-KEV EPSS was 79.0%, superseded
5.9
Wordpress 6.8 — EOL December 2, 2025 · migrate to 7.0
Wordpress 6.9 — EOL May 20, 2026 · migrate to 7.0
CVE-2022-0492
Confirmed exploited — pre-KEV EPSS was 5.5%, superseded
7.8
Linux 5.4 — EOL December 3, 2025 · migrate to 7.1, 6.18, 6.12
Linux 4.9 — EOL January 7, 2023 · migrate to 7.1, 6.18, 6.12
Linux 4.19 — EOL December 5, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.13 — EOL September 18, 2021 · migrate to 7.1, 6.18, 6.12
Linux 5.14 — EOL November 21, 2021 · migrate to 7.1, 6.18, 6.12
Linux 5.16 — EOL April 13, 2022 · migrate to 7.1, 6.18, 6.12
Linux 5.11 — EOL May 19, 2021 · migrate to 7.1, 6.18, 6.12
Linux 4.14 — EOL January 10, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.12 — EOL July 20, 2021 · migrate to 7.1, 6.18, 6.12
Linux 5.17 — EOL June 14, 2022 · migrate to 7.1, 6.18, 6.12
CVE-2025-38352
Confirmed exploited — pre-KEV EPSS was 1.2%, superseded
7.8
Linux 5.4 — EOL December 3, 2025 · migrate to 7.1, 6.18, 6.12
Linux 4.9 — EOL January 7, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.5 — EOL November 28, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.3 — EOL July 11, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.0 — EOL January 12, 2023 · migrate to 7.1, 6.18, 6.12
Linux 4.19 — EOL December 5, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.19 — EOL October 24, 2022 · migrate to 7.1, 6.18, 6.12
Linux 6.15 — EOL August 20, 2025 · migrate to 7.1, 6.18, 6.12
Linux 5.13 — EOL September 18, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.16 — EOL October 12, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.4 — EOL September 13, 2023 · migrate to 7.1, 6.18, 6.12
Linux 6.7 — EOL April 3, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.10 — EOL October 10, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.14 — EOL November 21, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.9 — EOL July 27, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.2 — EOL May 17, 2023 · migrate to 7.1, 6.18, 6.12
Linux 5.18 — EOL August 21, 2022 · migrate to 7.1, 6.18, 6.12
Linux 6.14 — EOL June 10, 2025 · migrate to 7.1, 6.18, 6.12
Linux 6.8 — EOL May 30, 2024 · migrate to 7.1, 6.18, 6.12
Linux 6.13 — EOL April 20, 2025 · migrate to 7.1, 6.18, 6.12
Linux 5.16 — EOL April 13, 2022 · migrate to 7.1, 6.18, 6.12
Linux 5.11 — EOL May 19, 2021 · migrate to 7.1, 6.18, 6.12
Linux 4.14 — EOL January 10, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.12 — EOL July 20, 2021 · migrate to 7.1, 6.18, 6.12
Linux 6.11 — EOL December 5, 2024 · migrate to 7.1, 6.18, 6.12
Linux 5.17 — EOL June 14, 2022 · migrate to 7.1, 6.18, 6.12

Frequently asked questions

What does 'end-of-life' (EOL) mean for a piece of software?

A release reaches end-of-life when its maintainer stops shipping security patches for it. The software keeps running exactly as before — nothing breaks on its own — but any vulnerability discovered afterward is never fixed by the vendor. From that point on, every new CVE against it is permanent.

Why is a CVE on an EOL product more dangerous than the same CVE on a supported one?

On a supported version, a critical CVE has a fix: update, and it's resolved. On an EOL version, there is no fix to apply — the only remediation is migrating to a version that still receives patches. The vulnerability itself isn't more severe, but the set of realistic responses shrinks to one, and that one takes longer than applying a patch.

What is CISA's KEV catalog, and why does it matter more than a CVSS score?

The Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency. A CVE is only added once there's evidence it's being exploited in the wild — not modeled, not theoretical. CVSS measures how bad a vulnerability could be; KEV confirms it already is being used by attackers. A KEV entry on software you can't patch is the highest-confidence signal you'll get that you're currently exposed.

What should I do if I can't migrate off an EOL product right away?

Migration is the only permanent fix, but if it can't happen immediately: restrict network exposure to only what's required, monitor the system more closely for compromise indicators, and treat the migration as a dated priority rather than an open-ended backlog item. This list exists to help you decide which EOL system to migrate first — the ones combining EOL status with confirmed active exploitation are the ones attackers are most likely probing for right now.

Get notified the moment this happens to your stack

Free — track up to 3 products in one project, daily checks, email alerts.

Create a free project