Over 45,000 VMware ESXi servers have just reached EOL

Share post:

VMware will no longer provide software and security updates for over 45,000 VMware ESXi servers that have just reached end-of-life (EOL).

Based on the inventory of Lansweeper, which includes the analysis of data from 6,000 customers, 79,000 installed VMware ESXi servers were found. 36.5% (28,835) run version 6.7.0 released in April 2018, and 21.3% (16,830) are on version 6.5.0 released in November 2016. Today, there are a total of 45,654 VMware ESXi servers reaching End of Life today.

As of October 15, 2022, VMware ESXi 6.5 and VMware ESXi 6.7 have reached end-of-life and will only receive technical support without security updates, making the software vulnerable.

The vulnerability risk of these servers is even more alarming when you consider that in addition to the 57% that entered a period of increased risk, another 15.8% are running installations with even older versions ranging from 3.5.0 to 5.5.0 which reached EOL some time ago.

At the moment, only about one in four ESXi servers (28.4%) inventoried by Lansweeper are still supported and will receive regular security updates until April 2, 2025.

Users who wish to continue to use older versions securely are advised to apply for the two-year extension of support, which must be purchased separately. It is important to note that it does not include updates for third-party software packages.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways