73% of Tracked Software Versions Are End-of-Life, But the Real Risk Lies Elsewhere
A analysis of end-of-life.org's database of 8,307 software and hardware versions finds that 73% have passed their end-of-life date, but experts caution this figure is largely misleading. The statistic is inflated by historical versions no longer in active use, making it a denominator problem rather than a meaningful risk indicator. What actually matters is the intersection of end-of-life software and versions still actively deployed in an organisation's environment, data that no public dataset can provide. Teams are also warned against sorting upgrade priorities by total CVE count, as older versions naturally accumulate more vulnerabilities, skewing focus away from higher-severity risks. A more actionable approach involves ranking dead-and-deployed software by critical CVEs per year and flagging the 142 branches set to reach end-of-life within 90 days, when upgrades are still routine maintenance rather than emergency remediation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in