Staying on top of end of life: the gap no patch will close
The most dangerous software in your estate is not the one missing a patch. It is the one that will never get another patch. An unpatched system is a task with a deadline. A system past end of support is a decision you have already made without noticing — and undoing it takes months, not a maintenance window.
Why end of life gets missed
Vulnerabilities announce themselves. There is a CVE, a vendor advisory, sometimes press coverage. End of support does the opposite: it is decided years in advance, published once in a lifecycle table, and then nothing happens. Nothing happens on the day either. The system keeps running, users keep working, monitoring stays green. The only thing that changes is that the next flaw will not be fixed.
That asymmetry is the whole problem. Patch management has a natural rhythm — Patch Tuesday arrives whether you planned for it or not. Lifecycle management has no rhythm at all. It only has a date you either wrote down or did not.
What to do about it
Know the dates before you need them. patchletter cross-references the support cycles from endoflife.date for every product it tracks. The end-of-life page shows what is running out and how much time is left — sorted by remaining runway, not alphabetically, because the order you need is “what bites first”.
Tell us which version you run. A support cycle only means something in relation to your version. On every product page you can record the version you actually have, and the cycle information adjusts to it. Without that, “version 7 is out of support” is trivia; with it, it is a task.
Plan in quarters, not weeks. A database major upgrade, a firewall firmware line, a Windows Server generation — these are projects with test phases and rollback plans. Six months of warning is a plan. Six weeks is an incident with paperwork.
Where end of life and exploitation meet
The two problems are not separate. When a flaw in an unsupported version is actively exploited, there is no patch to apply — only mitigation or migration, under time pressure. patchletter flags actively exploited vulnerabilities from the CISA KEV catalog on the CVE page. Reading it next to the end-of-life list is uncomfortable and useful in equal measure.
The honest limitation
Lifecycle data is only as good as what vendors publish, and not every product has a clean public cycle. patchletter shows what is documented and stays quiet where it is not — rather than inventing a date that looks reassuring. Where the data exists, you get a warning early; where it does not, you at least know that you are on your own.
Tick the tools you run and patchletter emails you when a new version ships — free, without an account, and with one-click unsubscribe. Start with the end-of-life overview to see what is running out first.