EOL Products With Actively Exploited Vulnerabilities
This page tracks the one intersection that matters most for security prioritization: software that has reached end-of-life and has at least one vulnerability CISA has confirmed is being actively exploited. Neither endoflife.date nor the NVD alone tells you this — it takes cross-referencing both, daily.
Every row below is unpatchable by definition: the vendor no longer ships fixes for that version, and the vulnerability isn't theoretical — it's in CISA's Known Exploited Vulnerabilities (KEV) catalog. If a product in your stack shows up here, migration isn't a nice-to-have. It's the only way to close the hole.
Updated daily · last data refresh: August 4, 2026 · reflects CISA's KEV catalog as of the most recent daily sync, not a real-time feed.
| CVE | Severity | Affected EOL products |
|---|---|---|
| CVE-2026-63030 Confirmed exploited — pre-KEV EPSS was 98.4%, superseded | 9.8 | |
| CVE-2026-31431 Confirmed exploited — pre-KEV EPSS was 94.5%, superseded | 7.8 | |
| CVE-2026-9082 Confirmed exploited — pre-KEV EPSS was 88.3%, superseded | 9.8 | |
| CVE-2025-14847 Confirmed exploited — pre-KEV EPSS was 83.0%, superseded | 7.5 | |
| CVE-2026-60137 Confirmed exploited — pre-KEV EPSS was 79.0%, superseded | 5.9 | |
| CVE-2022-0492 Confirmed exploited — pre-KEV EPSS was 5.5%, superseded | 7.8 | |
| CVE-2025-38352 Confirmed exploited — pre-KEV EPSS was 1.2%, superseded | 7.8 |
Frequently asked questions
What does 'end-of-life' (EOL) mean for a piece of software?
A release reaches end-of-life when its maintainer stops shipping security patches for it. The software keeps running exactly as before — nothing breaks on its own — but any vulnerability discovered afterward is never fixed by the vendor. From that point on, every new CVE against it is permanent.
Why is a CVE on an EOL product more dangerous than the same CVE on a supported one?
On a supported version, a critical CVE has a fix: update, and it's resolved. On an EOL version, there is no fix to apply — the only remediation is migrating to a version that still receives patches. The vulnerability itself isn't more severe, but the set of realistic responses shrinks to one, and that one takes longer than applying a patch.
What is CISA's KEV catalog, and why does it matter more than a CVSS score?
The Known Exploited Vulnerabilities (KEV) catalog is maintained by the U.S. Cybersecurity and Infrastructure Security Agency. A CVE is only added once there's evidence it's being exploited in the wild — not modeled, not theoretical. CVSS measures how bad a vulnerability could be; KEV confirms it already is being used by attackers. A KEV entry on software you can't patch is the highest-confidence signal you'll get that you're currently exposed.
What should I do if I can't migrate off an EOL product right away?
Migration is the only permanent fix, but if it can't happen immediately: restrict network exposure to only what's required, monitor the system more closely for compromise indicators, and treat the migration as a dated priority rather than an open-ended backlog item. This list exists to help you decide which EOL system to migrate first — the ones combining EOL status with confirmed active exploitation are the ones attackers are most likely probing for right now.
Get notified the moment this happens to your stack
Free — track up to 3 products in one project, daily checks, email alerts.
Create a free project