End-of-Life Software Support

Extended Support for End-of-Life Open Source Software

End-of-life (EOL) software is a version its maintainers no longer patch. It keeps running, but every vulnerability found after that date stays open, and auditors notice. AceMQ keeps end-of-life open source safe while you plan the upgrade: backported CVE patches through OSSeva, AceMQ's security patching platform, 24/7 support on the exact versions you run with a 15-minute response for P1 incidents, and an upgrade path with a date on it.

Senior End-of-Life Software engineers on call right now — 24/7/365
15 min emergency SLA24 /7 global coverage130 + enterprise customers26 + countries served

Trusted for Mission-Critical End-of-Life Software by Teams in Finance, Healthcare, Defense, Telecom, and More

What's Included

Everything in your End-of-Life Software support contract

No add-on pricing for incidents. No per-ticket charges. One contract covers the whole surface.

Backported CVE Patches

Security fixes for versions upstream has stopped patching (or is about to), backported by OSSeva to the release line you run so nothing else changes. Coverage spans Redis and Valkey, PostgreSQL 11 to 13, Kafka 2.8 to 3.7, ActiveMQ Classic and Artemis, GemFire and Apache Geode, Spring Boot, Spring Framework and Spring Security, Apache Tomcat, Node.js 14 to 20 and Apache Pulsar.

24/7 Support on End-of-Life Versions

Upstream has moved on; your production cluster has not. A senior engineer joins a live bridge within 15 minutes for P1 incidents on the version you actually run, with workarounds and mitigations where no upstream fix will ever ship.

CVE Exposure Assessment

Which published CVEs affect your exact versions and configuration, which are reachable in your deployment, and which need a patch now rather than at the next upgrade. The output is a prioritized list, not a scanner dump.

Evidence for Auditors

Auditors ask how a version past end of life is being kept secure. We document the patch source, the CVEs addressed and the upgrade plan, which is the evidence trail PCI DSS assessors and SOC 2 auditors ask for when a version is past end of life.

Upgrade Planning and Execution

Extended support buys time, not a permanent home. We plan the move to a maintained release from the release notes, rehearse it with a rollback, and run the cutover in your window, whether that is PostgreSQL 13 to 17, Kafka with ZooKeeper to KRaft, or Spring Boot 2 to 3.

RabbitMQ Extended LTS

RabbitMQ has its own route. AceMQ's Extended LTS support delivers backported security patches for RabbitMQ 3.8.x through 3.13.x after community support ends, from the team that supports RabbitMQ every day.

Escalation Path

Your first hour of an End-of-Life Software outage

Most vendors publish an SLA number. This is what actually happens, minute by minute, when you page a senior AceMQ engineer.

T+0

You page us

Phone, email, or Slack — any channel reaches the on-call senior engineer directly. No web form, no tier-1 queue.

T+15

Named engineer live

A senior engineer who already knows your environment joins a live bridge. Zero cold-start, no re-explaining your topology.

T+30

Root cause isolated

Direct broker access, log and metric review, and a working hypothesis with a rollback plan before we touch anything.

Post

Written RCA

Documented root cause, the fix applied, and the prevention steps — delivered after every P1, not just when asked.

Response Times

SLA tiers, contractually guaranteed

Every tier reaches a senior End-of-Life Software engineer. There is no tier-1 triage layer to get through.

P1 — Emergency
15 min

Production down on an end-of-life version: outage, data not flowing, cluster or node failure, or an actively exploited CVE

P2 — Critical
1 hour

Severe degradation, rising error rates, approaching capacity limits

P3 — High
4 hours

Performance issues, configuration problems, non-critical failures

P4 — Standard
Next day

Questions, guidance, best practices, non-urgent improvements

49+ Platforms Supported

We Support Your Entire Tech Stack

End-of-Life Software rarely fails in isolation. AceMQ covers the full surrounding infrastructure — so one team owns the whole path instead of pointing at each other.

Anywhere You Run It

We support End-of-Life Software wherever it's deployed

Cloud, Kubernetes, bare metal, hybrid, and air-gapped — including environments where you can't give us outbound network access.

Self-managed Linux virtual machinesKubernetes and OpenShiftOn-premises data centersAir-gapped / no outbound accessAWS, Azure and Google Cloud VMsVMware vSphere and TanzuBare metalHybrid cloud
Coverage by technology

End-of-life open source: status and where to go

Upstream status as published by each project or vendor, checked 9 October 2026. OSSeva supplies backported security patches; AceMQ supplies 24/7 support and the upgrade. Links for every row are at the bottom of this page.

TechnologyVersions in scopeUpstream statusWhere to go
Redis6.2, 7.0, 7.27.0 is no longer listed as supported; 6.2 is supported to 1 April 2027 and 7.2 to 1 December 2029OSSeva patches, plus AceMQ Redis support
Valkey7.2, 8.0Still maintained upstream: 7.2 to 16 April 2027 (security fixes to 16 April 2029), 8.0 to 15 September 2027OSSeva patches, plus AceMQ Valkey support
PostgreSQL11, 12, 13, and 14 from 12 November 2026End of life: 11 on 9 November 2023, 12 on 21 November 2024, 13 on 13 November 2025; 14 follows on 12 November 2026OSSeva patches, plus AceMQ PostgreSQL support
Apache Kafka2.8 to 3.7Not maintained: Apache patches only its three most recent release lines (4.1, 4.2 and 4.3); 3.8, 3.9 and 4.0 are archived tooOSSeva patches, plus AceMQ Kafka support
ActiveMQ Classic5.15 to 5.18Inactive (end of life) on the Apache download page; 5.19.x and 6.3.x are the active seriesOSSeva patches, plus AceMQ ActiveMQ support
ActiveMQ ArtemisOlder 2.x releasesNo published support window; Apache lists only the current release (2.57.0)OSSeva patches, plus AceMQ ActiveMQ support
GemFire and Apache GeodeGemFire 9.x and 10.x, Geode 1.xGemFire support dates are set by Broadcom per release; Apache Geode is still active (1.15.5 and 2.0.3 released September 2026)OSSeva patches, plus AceMQ GemFire support
Spring Boot2.6, 2.7Open source support ended: 2.6 on 30 November 2022, 2.7 on 30 June 2023OSSeva patches, or Tanzu Spring commercial support through AceMQ
Spring Framework and Spring SecurityFramework 5.3, Security 5.8Open source support ended: Framework 5.3 on 31 August 2024, Security 5.8 on 31 December 2023OSSeva patches, or Tanzu Spring commercial support through AceMQ
Apache Tomcat8.5, 9.0, 10.0End of life: 10.0 on 31 October 2022, 8.5 on 31 March 2024; 9.0 support ends 31 March 2027OSSeva patches
Node.js14, 16, 18, 20End of life: 14 on 30 April 2023, 16 on 11 September 2023, 18 on 30 April 2025, 20 on 30 April 2026OSSeva patches
Apache Pulsar2.10.x and 3.xApache supports the last two LTS and feature releases (now 5.0 and 4.0 LTS); 3.0 LTS security support ended 2 May 2026OSSeva patches, plus AceMQ Pulsar support
RabbitMQ3.8.x to 3.13.xOut of community support: 3.13 ended 30 September 2024, and only 4.3 is community supported nowAceMQ Extended LTS support (not OSSeva)
MySQL5.7, 8.0Moved to Oracle Sustaining Support, with no new fixes: 5.7 on 25 October 2023, 8.0 on 21 April 2026OSSeva patched builds, plus AceMQ MySQL support and the upgrade to 8.4 LTS
MariaDB10.4, 10.5, 10.6Community end of life: 10.4 on 18 June 2024, 10.5 on 24 June 2025, 10.6 on 6 July 2026OSSeva patches
MongoDB4.2 to 6.0 (self-managed)End of life: 4.2 on 30 April 2023, 4.4 on 29 February 2024, 5.0 on 31 October 2024, 6.0 on 31 July 2025OSSeva patches, plus AceMQ MongoDB support
Elasticsearch7.10.2, 7.177.x reached end of life on 15 January 2026OSSeva patches, plus AceMQ Elasticsearch support
Other open sourceAny version past upstream supportVaries by projectAceMQ support for the technology, with an upgrade plan

Sources: each project's own release or lifecycle page, listed in full in the page sources. Dates move when projects extend support, so check the linked page for your version before an audit.

Why AceMQ

What you get that you don't get elsewhere

We Own the Patch Pipeline

OSSeva is AceMQ's own platform, so the people backporting the fix and the people answering your P1 call work for the same company. No reseller in the middle, and no gap between patch and support.

One Contract for the Patch and the Incident

Security patches for the EOL version, 24/7 incident response on it, and the upgrade off it, under one agreement. Nobody argues about whose problem a crash on an unpatched release is.

Upgrade on Your Schedule, Not the Calendar's

Project end-of-life dates have nothing to do with your change freezes, certification cycles or vendor dependencies. Extended support lets the upgrade happen when it can be done properly, with an end date agreed up front.

No Tier-1 Triage Layer

You reach a senior engineer directly by phone, email or Slack. Nobody collects details to pass along while an unpatched version is misbehaving in production.

Follow-the-Sun Coverage

Engineers across 26+ countries and every time zone, so a 3am incident on a legacy cluster reaches someone who is already at work.

FAQ

End-of-Life Software support questions

Keep End-of-Life Versions Patched While You Upgrade

Tell us what you run and which versions are past end of life. We will map each one to a patch source and an upgrade path, and staff it with named senior engineers. Support quotes returned within 24 hours.

Get in Touch

Talk to a Support Expert

Send us a message and we'll follow up within one business day — or book a free 30-min consultation directly.

305-204-2607
info@acemq.com
66 W. Flagler St. 9th Floor
Miami, FL 33130

Prefer to talk now? Call us directly or use the consultation tab to find a time that works.

We respond within 1 business day.

Pick a time that works — no pressure, no pitch. Just 30 minutes with an expert.

We respond within 1 business day.