EOSL Alerts

VMware Cloud Foundation 4.5 EOL May 31, 2025 – Action Plan

Updated 3rd Party Support Team

Last-Call Action Plan: VMware Cloud Foundation 4.5 End of Life Is May 31, 2025

VMware Cloud Foundation (VCF) version 4.5 reaches end of life on May 31, 2025 — that is roughly three months from today. After that date, Broadcom will no longer provide patches, security fixes, bug resolutions, or support SLAs for any 4.5 deployment. This is not a long-term-support (LTS) release, and the latest available build is 4.5.2.

For most estates, a full migration to 5.x before May 31 is no longer realistic. Gaps in planning, resource contention, and testing cycles make a safe move unlikely inside 90 days. The priority now shifts to what you can do in the time that remains to protect your production environments.

What Changes on the EOL Date

On June 1, 2025, Broadcom stops all active support for VCF 4.5:

  • No security patches — any CVE discovered after May 31 will not be addressed.
  • No critical or recommended fixes — defects stay open permanently.
  • No vendor SLAs — your support contract for 4.5 effectively ends at 23:59 UTC on May 31.
  • No access to updates — the 4.5.2 patch set is the final bundle.

Existing licenses remain valid, but the product receives no maintenance. Any new vulnerability becomes an unpatched risk that you must manage yourself.

Immediate Action Checklist (Week-by-Week)

Use this timeline to harden your position before the deadline.

Weeks 1–2: Inventory and Exposure Scan

  • List every VCF 4.5 stack: SDDC managers, vCenter instances, ESXi hosts, vSAN clusters, NSX-T controllers.
  • Note which workloads are business-critical, which are dev/test, and which are already scheduled for decommission.
  • Identify dependencies: Is anything inbound/outbound that relies on a supported-by-vendor status for compliance or insurance?
  • Run your audit tool (e.g., vRealize Log Insight queries, 3rd-party scanner) to find stale or orphaned hosts.

Weeks 3–4: Isolate and Harden

  • Segment unsupported 4.5 management networks from any upgraded 5.x or higher stacks.
  • Restrict administrative access to the SDDC manager cluster via firewall rules and jump-box only.
  • Apply the final 4.5.2 patch if you haven’t already — this is the last known good state.
  • Review backup and DR configurations. Confirm that backups of 4.5 VMs can be restored independently of a newer VCF version.
  • Disable any unused features or plugins that might introduce attack surface.

Weeks 5–6: Document Exposure for Auditors and Insurers

  • Create a single-page risk register that lists every 4.5 component and states “End-of-life, no vendor support after May 31, 2025.”
  • Attach a remediation plan or migration target window (even if it’s Q3 or Q4 2025).
  • Brief your compliance officer and cyber-insurance provider. Some policies require disclosure of unsupported software.
  • If your industry mandates patching cadence (PCI-DSS, HIPAA, SOC 2), document the compensating controls you intend to use.

Weeks 7–8: Secure Day-One Support

  • Evaluate third-party support for VCF 4.5 after EOL. A provider such as 3rd Party Support can continue to deliver security patches and fixes for the lifecycle of your contract, even after Broadcom stops.
  • Get a statement of work in place before May 31 so that coverage begins June 1 with zero gap.
  • If possible, extend your current hardware maintenance to match the third-party support term — unsupported firmware on the same cluster multiplies risk.

Weeks 9–10: Final Sandbox and Test

  • Validate your restoration procedures in a lab that mirrors the 4.5 production set.
  • Confirm that any scripts, automation, or monitoring tools still target this build after the last patch.
  • Run a fire-drill for “no vendor support” — what happens if you hit a critical bug? Who will you call? Document the answer.

Weeks 11–12: Cutover Readiness

  • Update your IT disaster recovery plan to flag the EOL status of VCF 4.5.
  • Set calendar reminders for quarterly re-assessment of the risk (the product doesn’t magically become safer after EOL).
  • Communicate the final status to all stakeholders: supported by 3rd Party Support as of June 1; no Broadcom SLAs remain.

The Only Realistic Options Now

You have two practical paths:

  1. Accelerate migration to VCF 5.x — only if you already have a partially built 5.x stack and can hit May 31 with confidence. Do not start from scratch now.
  2. Secure third-party support for 4.5 — keeps your environment stable while you plan a measured, less-risky migration later in 2025 or early 2026.

A vendor hard stop in 90 days does not have to mean panic. Inventory, isolate, document, and make sure you have a support contract that starts on June 1. That’s the achievable goal.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep VMware Cloud Foundation 4.5 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

VMware software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.