Welcome to the first issue of The EOL Digest — a monthly roundup of the most critical software end-of-life dates, CVE blind spots, and lifecycle changes worth knowing about.
This Month's Critical Dates
Node.js 20 — EOL April 2026
Node.js 20 reached end of life last month. If your applications are running Node 20, upgrade to Node 22 or 24 immediately. Every CVE disclosed against Node 20 after April 2026 accumulates with no patch path.
PHP 8.1 — EOL December 2025
Already past EOL. PHP 8.1 is no longer receiving security patches. Migrate to PHP 8.3 or 8.4 before year-end.
PHP 8.2 — EOL December 2026
Seven months out. Start planning your migration to PHP 8.3 or 8.4 now.
Python 3.10 — EOL October 2026
Five months remaining. Any production application running Python 3.10 should have a migration to 3.11 or later on the roadmap.
Redis 7.2 — EOL July 2026
Two months out. Teams running Redis 7.2 should plan their upgrade to Redis 8.x or evaluate Valkey as an open-source alternative.
CVE Blind Spot of the Month
Windows 10 — 6 months past EOL
Windows 10 reached EOL in October 2025. Six months later, millions of enterprise endpoints globally are still running it. Every CVE disclosed against Windows 10 since that date will never be patched.
Microsoft is actively patching Windows 11 for vulnerabilities that exist in both operating systems. Your Windows 10 machines are exposed to every one of those unaddressed flaws.
If your organization is still running Windows 10, read our complete migration guide at endoflife.ai/article-windows10-eol.html
From the Resource Hub
Check Your Stack
The endoflife.ai Stack Scanner lets you upload a requirements.txt, package.json, or Gemfile and get a full EOL report for your entire dependency tree in seconds. Free, no account required, runs in your browser.
You're receiving this because you signed up at endoflife.ai. Unsubscribe anytime.