End of life software is software whose maker has stopped supporting it: no more security fixes, bug fixes or help from the vendor. The program usually keeps running. What ends is the stream of updates that closes newly discovered holes, so the risk grows the longer it stays in use.

That gap between “still works” and “still safe” is the whole subject. Windows 10 is the clearest current example: it reached end of support on October 14, 2025, and the one-year consumer Extended Security Updates program runs until October 13, 2026.

End of life, end of support, end of sale

Vendors use several phrases, and they do not always mean the same thing.

Term What usually stops What usually continues
End of sale New licenses or devices Updates and support for existing users
End of mainstream support Feature changes and non-security fixes Security updates
End of support / end of life Security updates and vendor help The software itself, unpatched
Paid extended updates Nothing extra; you buy more time Security fixes for a fee, for a limited period

Microsoft’s Fixed Lifecycle Policy shows the pattern. Products get at least five years of Mainstream Support, with security and non-security updates. Some then get Extended Support, which keeps security updates but stops non-security fixes and design changes. Beyond end of support, security updates are available only through the paid Extended Security Update program. The policy also warns that “older products may not meet today’s more demanding security requirements.”

Microsoft’s Windows end-of-support page puts the user-level effect plainly: a Windows 10 PC “will continue to function,” but without security updates it is “more vulnerable and susceptible to viruses and malware.”

Open-source projects have end dates too

End of life is not only a commercial idea. Open-source projects publish schedules, and they are just as firm.

The Python core team’s version status page says each release moves from bugfix to security-only fixes and then, five years after release, to end of life, when “the release cycle is frozen; no further changes are allowed.” Python 3.10 reached end of life on October 1, 2026, so a server still on 3.10 gets no further security releases from the Python team.

Linux distributions add another layer. Canonical’s Ubuntu release cycle gives each LTS release five years of standard security maintenance; Ubuntu 22.04 LTS, for example, has standard maintenance until May 2027. Expanded Security Maintenance through an Ubuntu Pro subscription extends security coverage to 10 years, and a legacy add-on goes further. Interim releases get only nine months.

Why end of life software is a security risk

Vulnerabilities keep being found in old code after its vendor stops looking. Once support ends, a newly found flaw in that version may never be fixed, and a fix published for a newer version can show attackers where to look in the old one.

Other parts of a setup also move on. Browsers, drivers and libraries eventually stop supporting old operating systems and runtimes, so an end-of-life component can block updates elsewhere. Our explainer on software dependency risk covers how one stale package affects everything built on it.

The US Cybersecurity and Infrastructure Security Agency and the FBI treat the question from the vendor’s side. Their Product Security Bad Practices guidance lists failing to “clearly communicate the period of support” for on-premises products as a bad practice, and recommends that manufacturers state the support period at the time of sale and provide security updates through all of it. The guidance is voluntary. In the EU, the Cyber Resilience Act, Regulation (EU) 2024/2847, will require manufacturers of many products with digital elements to set a support period, normally at least five years, once its main obligations apply on December 11, 2027.

How to find end of life software you are running

A short inventory covers most households and small offices:

  1. Operating systems. Check the exact version and edition on each computer and phone. On Windows, run winver; on Ubuntu, lsb_release -a.
  2. Runtimes and databases. Note versions of Python, Node.js, PHP, Java, .NET, PostgreSQL or MySQL on any server or developer machine.
  3. Office suites and browsers. Extended-support browser channels have their own end dates.
  4. Devices. Phones, routers and NAS boxes stop getting firmware updates on the maker’s schedule.
  5. Compare with the vendor’s dates. Use the vendor’s lifecycle page, or our end-of-life dates catalog, which lists support end dates for Windows, Office, Ubuntu, Debian, Python, Node.js, PHP, Java, .NET, PostgreSQL, MySQL, Firefox ESR and Google Pixel phones, with a list of dates coming up.

Record the date you checked. Lifecycle pages change when vendors extend or shorten support.

What to do when support ends

There are four realistic options, roughly in order of preference:

  • Upgrade in place to a supported version, after a backup and a check that your applications support it.
  • Replace the software or device when the upgrade path needs hardware the old machine lacks; Windows 11’s TPM 2.0 requirement is an example, explained in our TPM guide.
  • Buy time through a paid extension such as Windows ESU or Ubuntu Pro, with a fixed date to finish the move.
  • Isolate what cannot be replaced yet: take it off the internet, restrict who can reach it and keep it away from email and web browsing.

Leaving it as it is should be a recorded decision with an end date, not a default.