Four Cisco ASA models stop getting security patches in 14 days.
Not end of sale. Not “reduced support.” The actual last day of support for the ASA 5506-X, 5508-X, 5515-X and 5516-X is 2026-08-31, and after that date a vulnerability found in your firewall stays open forever. No TAC case, no patch, no signature update.
You’ve probably known this was coming. Cisco announced it years ago and it’s been sitting in a spreadsheet somewhere. The thing is, most people found out the date was this close by reading something like this.
Here’s what this covers: exactly which models die and when, which ones already died, what Cisco says replaces each one, how the migration actually goes, and what to do if you genuinely can’t swap hardware in two weeks.
Everything below was checked on 2026-08-17.
The short answer: four models, one date
| Model | Last day of support | Status |
|---|---|---|
| ASA 5506-X | 2026-08-31 | Dies in 14 days |
| ASA 5508-X | 2026-08-31 | Dies in 14 days |
| ASA 5515-X | 2026-08-31 | Dies in 14 days |
| ASA 5516-X | 2026-08-31 | Dies in 14 days |
| ASA 5512-X | 2022-08-31 | Already dead |
| ASA 5525-X | 2023-05-31 | Already dead |
| ASA 5545-X | 2023-05-31 | Already dead |
| ASA 5555-X | 2023-05-31 | Already dead |
| ASA 5585-X | 2023-05-31 | Already dead |
Look at the bottom half of that table. If you’re running a 5525-X or a 5555-X, you haven’t been getting patches for over three years. That’s the more common situation than people admit.

After 2026-08-31, none of the nine main ASA 5500-X models are supported. Source: Cisco EOL notices, collated by EOSL.date.
The 5506-X is the one that matters most by volume. It was the cheap desktop model that went into thousands of branch offices, dental practices and small manufacturing sites, and a lot of them were installed by someone who’s since left the company.
What “end of life” actually means here
Cisco uses three terms and they get mixed up constantly.
End of sale is when you can’t buy it anymore. For the 5508-X and 5516-X that was 2021-08-02. Long gone.
End of software maintenance is when bug fixes stop. Feature work already ended before that.
Last day of support is the one that matters. It’s the final date Cisco will do anything at all: no security patches, no TAC, no RMA, no signature releases. For these four models that’s 2026-08-31, per Cisco’s own EOL notice.
Think of it like a car manufacturer discontinuing parts. The car still drives on September 1st. But the day something breaks, nobody’s making the replacement piece.
One more thing that trips people up. The hardware EOL is separate from the software EOL. ASA software releases have their own dates, and 9.18 and 9.19 run to 2027-11-30. So you might read “supported until 2027” somewhere and think you’re fine. You’re not, if the box underneath is a 5506-X.
Why this one is worse than a normal EOL
Most end-of-life dates are a budgeting problem. This one is a security problem, and the difference is timing.
Cisco ASA has been under active attack. CVE-2026-20349, rated 8.6, is being exploited in the wild right now and CISA added it to the Known Exploited Vulnerabilities catalogue with a federal remediation deadline of 2026-08-14. That deadline was three days ago.
Then there’s ArcaneDoor. That’s the campaign that’s been targeting ASA and FTD devices since 2024, and the part that should worry you is the persistence. The group built a mechanism that survives upgrading to fixed releases. A bootkit in ROM, so reflashing doesn’t clear it.
Put those two facts next to each other. Attackers are actively hunting these boxes, and in two weeks four models stop receiving the patches that would close the next hole.

Around 113K ASA devices face the public internet, and close to half expose a login panel. Source: Eclypsium.
Both the US and UK cyber agencies have told organisations to replace end-of-life security appliances rather than keep running them. Not “plan to replace.” Replace.
Here’s the uncomfortable version. A firewall that can’t be patched isn’t a firewall. It’s a device with a public IP and a permanent open door, sitting exactly where you put your most trusted boundary.
Want to understand why these boxes get owned? Our Cisco ASA Lab Workbook covers hardening and ASA configuration with labs you run yourself, so the concepts stick past exam day.
What replaces each ASA model
Cisco’s mapping is the Firepower 1000 Series for the small models. Rough equivalents:
| If you have | Cisco’s replacement | Notes |
|---|---|---|
| ASA 5506-X | Firepower 1010 | Desktop, built-in switch ports, same footprint |
| ASA 5508-X | Firepower 1120 | 1RU |
| ASA 5516-X | Firepower 1140 | 1RU, more throughput |
| ASA 5525-X | Firepower 1150 or Secure Firewall 3105 | Depends on throughput needs |
| ASA 5555-X | Firepower 1150 / FPR 3100 series |
The 1010 is the direct swap for a 5506-X. Desktop form factor, integrated switch, aimed at exactly the small-site deployments the 5506-X owned.

The replacement is not a sidegrade. Source: Cisco ASA 5500-X and Firepower 1000 Series datasheets.

VPN capacity is where the gap is widest. Source: Cisco ASA 5500-X and Firepower 1000 Series datasheets.
But there’s a decision hiding in this table that nobody flags clearly enough.
ASA software or FTD? Pick before you buy
The Firepower 1000 boxes run either ASA software or Firepower Threat Defense. Two different operating systems on the same hardware.
Running ASA software on new hardware means your config mostly carries over, your team keeps working the way they always have, and the migration is short. It also means you’re extending a platform Cisco is clearly winding down.
Running FTD means learning a new management model, rebuilding policy, and probably a longer project. It’s where Cisco is putting its effort.
Say you’re a two-person IT team at a 60-person company with one firewall and no change window until December. Load ASA software, buy yourself the runway, and plan FTD properly next year. Say you’re a managed service provider with 40 of these across clients. Bite the bullet on FTD now, because doing this twice costs more than doing it once slowly.
Your call. Just make it deliberately instead of discovering it during the cutover.
How the migration actually goes
Cisco ships a Secure Firewall Migration Tool that converts ASA configs to Threat Defense. It supports every 5500-X model from the 5506-X up to the 5585-X.
It handles the mechanical parts well: interfaces, objects, NAT rules, access lists. It gives you a pre-migration report so you can see what won’t convert before you commit.
What it doesn’t do is think for you.
The rules it can’t translate cleanly are usually the ones that matter. Anything relying on ASA-specific inspection behaviour. VPN configs with unusual crypto. That one access list somebody hand-wrote in 2017 with a comment that says “do not remove, ask Dave.” Dave left.
A realistic sequence:
- Inventory first.
show versionon every ASA you can reach. You will find at least one you’d forgotten about. This is the step people skip and it’s the step that saves the project. - Export configs and run the pre-migration report. Before you order hardware, so throughput sizing is based on real rule counts.
- Order with lead time in mind. This is the part that makes the 14-day thing painful.
- Build and test in a lab. Not on the production box at 2am.
- Cut over with the old unit still racked. Powered off, cabled, ready to bring back.
- Watch for a week. The failures show up in the traffic nobody thought about, printing, a site-to-site tunnel that only runs monthly, a vendor VPN.
Step 4 is where most of the risk gets removed, and it’s the step that gets cut when the date is close. You can build the whole topology in an emulator and test the converted policy before hardware arrives. Our guide on home lab setup for network engineers covers the build, and the emulator comparison helps you pick which one runs ASAv and FTDv comfortably.
You can’t migrate in 14 days. Now what?
Realistically, most people reading this in mid-August aren’t racking new firewalls before the 31st. Hardware lead times alone rule it out.
So here’s the honest fallback. None of this makes the device supported. All of it reduces how exposed you are while you fix the real problem.
Patch it now, while you still can. Anything Cisco has released, apply it before the 31st. After that date the well is dry. This is the single highest-value thing you can do this week.
Kill remote management on the outside interface. No SSH, no ASDM, no HTTPS management from the internet. Management goes through a jump host or a VPN, full stop. Most of the exploitation activity targets exactly these services.
Turn off WebVPN if you’re not using it. The clientless SSL VPN portal has been the entry point in multiple ASA campaigns. If nobody’s using it, it shouldn’t be listening.
Check whether you’re already compromised. CISA’s ED 25-03 has the detection guidance. Given that ArcaneDoor persists through upgrades, “we patched it” isn’t the same as “we’re clean.”
Write down the date you’re actually migrating. With a name against it. An unsupported firewall with no migration date becomes a permanent unsupported firewall, and everyone tells themselves otherwise.
Anyway. Two weeks of mitigation is a bridge, not a destination.
Quick answers
Is Cisco ASA obsolete? The hardware line is being retired, yes. ASA software still gets releases and 9.18/9.19 run to 2027-11-30, but the 5500-X appliances are ending model by model. New deployments go to Secure Firewall, not ASA.
What is replacing Cisco ASA? Cisco Secure Firewall, previously called Firepower. Firepower 1000 Series for small sites, 3100 and 4200 Series as you scale up. The software side moves from ASA to Firepower Threat Defense.
What if my ASA still has an active support contract past August 31? The contract doesn’t extend the product’s last day of support. After 2026-08-31 there’s nothing left to deliver on these four models.
Can I keep running it if it’s behind another firewall? You can, and it’s better than nothing. But you’ve now got an unpatchable device inside your perimeter, which is a different risk rather than no risk. Treat it as temporary.
Which ASA models are still supported? None of the 5500-X hardware line after 2026-08-31. The 5512-X went in 2022, the 5525-X through 5585-X went in 2023, and these last four go this month.
Bottom line
Four models, one date, 14 days out. The 5506-X, 5508-X, 5515-X and 5516-X all lose support on 2026-08-31.
What to do this week, in order: inventory every ASA you own, apply every available patch before the 31st, pull management off the outside interface, and put a real date and a real name against the migration.
The Firepower 1010, 1120 and 1140 are the direct replacements. Decide whether you’re loading ASA software or going to FTD before you order, not during the cutover.
And if you want to practise the migration before you do it for real, that’s what a lab is for. The Cisco ASA Lab Workbook covers the platform you’re leaving and the Cisco FTD Lab Workbook covers the one you’re moving to, both with topologies that run in EVE-NG. SMEnode Academy’s CCNP Security course has the live version if you’d rather learn it with an instructor.
Migrations like this are the reason the certification matters. The people who handle them calmly are the ones who’ve built it before, in a lab, where breaking things costs nothing.