DEV Community

endoflife-ai
endoflife-ai

Posted on Originally published at endoflife.ai

The Backport Myth: We Tried to Prove 624 EOL Versions Were Unpatchable. Vendors Kept Proving Us Wrong.

We cross-referenced CISA’s exploited-vulnerabilities catalog against verified end-of-life data — 624 candidate pairs, 98 verified line-by-line against vendor advisories. Roughly 88% failed, mostly because vendors quietly patch “dead” versions far more than anyone believes. Here are the receipts, and where unpatchable truly lives.

Where unpatchable is real

Cluster Verified examples The tell
Hard-cutoff policy vendors JetBrains TeamCity (CVE-2026-63077: nine affected lines, fix only in the current two) · Atlassian Confluence (three separate exploited CVEs, EOL lines never fixed) A published support policy that fix history follows without exceptions
Appliance vendors saying the quiet part loudly Broadcom/VMware ESXi 7.0 × CVE-2024-37085: the advisory states "No Patch Planned" · FortiOS 6.4/7.0 × CVE-2025-68686: remediation reads "Migrate to a fixed release" Advisory language — the gold standard of proof
Single-line open source Exim 4.91 × CVE-2019-10149 · Apache Solr 5/6/7 × two exploited CVEs · Roundcube 1.2–1.4 · MLflow 2.x × CVE-2026-64849 · Ray below 2.52.0 No lifecycle policy at all — fixes land in the newest release only, and old versions simply stop existing

What's covered

  • The experiment
  • The result: the myth failed almost 9 times in 10
  • Where unpatchable is real
  • Both wrong lessons, preempted
  • Methodology, so you can check us

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-backport-myth

Top comments (0)