Home/Resources/Security Exposure

Post-EoL Security Exposure

Devices past their security-support date that are named in CISA's Known Exploited Vulnerabilities catalog.

This is not a CVE search tool. Every entry below is a specific device in our catalog that (1) is past the vendor's end-of-vulnerability-security-support or last-date-of-support date and (2) runs a platform listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The vendor is not patching these devices. The vulnerabilities are being exploited in the wild.

Correlation is at the platform level (Junos OS, PAN-OS, BIG-IP, SonicOS, Firebox, etc.). A specific CVE may affect only certain OS versions; the device may or may not have received the patch before the vendor cut off support. Assume exposure unless you've confirmed otherwise.

4
models on affected platforms
198
distinct CVEs
1687
KEV entries tracked

By vendor

Counts reflect post-EoL models running on an affected platform. A specific firmware version may not be vulnerable — verify with the vendor's PSIRT advisory.

Vendor Models on platform Distinct CVEs Ransomware-linked
Juniper 1159 7 0
Cisco 815 61 3
Fortinet 525 25 13
QNAP 217 10 9
Arista 201 1 0
WatchGuard 92 4 0
SonicWall 90 16 12
Check Point 73 2 2
F5 Networks 43 7 4
Sophos 39 3 0
NETGEAR 36 2 0
Palo Alto 19 12 6
D-Link 13 14 1
Zyxel 12 1 0
VMware (Broadcom) 8 16 7
Citrix 4 17 4

Flagged models

Clear filters

4 flagged devices (citrix).

Newest CVE added Device Vendor CVEs Ransom
NetScaler ® 7000 9010 10010 12000 EN Citrix 17 Yes
† NetScaler Application Accelerator 7000 9000/9010 9500 EN Citrix 17 Yes
NetScaler ® Platforms VPX-4 VPX-6 VPX-8 VPX-10 VPX-12 VPX-16 VPX-20 (perpetual release range vCPU based VPX FIPS) EN Citrix 17 Yes
Access Gateway Platforms 10010 9010 7000 All Citrix 17 Yes

Operators running any device in this list should treat it as a compensating-control scenario under NIST SA-22 and the equivalent PCI-DSS, HIPAA, and cyber-insurance guidance. See the Compliance and Insurance page for clause-level context and control options.

Source: CISA Known Exploited Vulnerabilities catalog. Snapshot refreshed weekly.

↑ Top