We cross-referenced CISA’s exploited-vulnerabilities catalog against verified end-of-life data — 624 candidate pairs, 98 verified line-by-line against vendor advisories. Roughly 88% failed, mostly because vendors quietly patch “dead” versions far more than anyone believes. Here are the receipts, and where unpatchable truly lives.
Where unpatchable is real
| Cluster | Verified examples | The tell |
|---|---|---|
| Hard-cutoff policy vendors | JetBrains TeamCity (CVE-2026-63077: nine affected lines, fix only in the current two) · Atlassian Confluence (three separate exploited CVEs, EOL lines never fixed) | A published support policy that fix history follows without exceptions |
| Appliance vendors saying the quiet part loudly | Broadcom/VMware ESXi 7.0 × CVE-2024-37085: the advisory states "No Patch Planned" · FortiOS 6.4/7.0 × CVE-2025-68686: remediation reads "Migrate to a fixed release" | Advisory language — the gold standard of proof |
| Single-line open source | Exim 4.91 × CVE-2019-10149 · Apache Solr 5/6/7 × two exploited CVEs · Roundcube 1.2–1.4 · MLflow 2.x × CVE-2026-64849 · Ray below 2.52.0 | No lifecycle policy at all — fixes land in the newest release only, and old versions simply stop existing |
What's covered
- The experiment
- The result: the myth failed almost 9 times in 10
- Where unpatchable is real
- Both wrong lessons, preempted
- Methodology, so you can check us
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-backport-myth
Top comments (0)