Is Python 2.7.18 patched?
Current stable (3.14.6): 89/100
Summary iPlain-English security status for Python 2.7.18, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Python 2.7.18 is part of the 2.7 release line. 32 known vulnerabilities affect it. The 2.7 line reached end-of-life on 2020-01-01, so it no longer receives security patches. The latest supported Python release is 3.14.6.
Known issues affecting 2.7.18
Exploited first, then by exploitation probability.
CVE-2021-23336 MEDIUM EPSS 37% → fixed in 3.9.2 CVE-2007-4559 CRITICAL EPSS 27% → fixed in 3.11.4 CVE-2023-24329 HIGH EPSS 20% → fixed in 3.11.4 CVE-2022-0391 HIGH EPSS 8% → fixed in 3.9.5 CVE-2021-3733 MEDIUM EPSS 5% → fixed in 3.9.5 CVE-2022-48565 CRITICAL EPSS 4% → fixed in 3.9.1 CVE-2017-17522 HIGH EPSS 4% → see advisory CVE-2023-27043 MEDIUM EPSS 3% → fixed in 3.12.6 CVE-2022-45061 HIGH EPSS 2% → see advisory CVE-2024-7592 HIGH EPSS 2% → fixed in 3.12.6 CVE-2024-6232 HIGH EPSS 2% → fixed in 3.12.6 CVE-2022-48560 HIGH EPSS 2% → fixed in 3.8.2 CVE-2025-13836 HIGH EPSS 1% → fixed in 3.13.11 CVE-2022-48564 MEDIUM EPSS 1% → fixed in 3.9.1 CVE-2022-26488 HIGH EPSS 1% → see advisory CVE-2017-18207 MEDIUM EPSS 1% → see advisory CVE-2023-36632 HIGH EPSS 1% → see advisory CVE-2022-48566 MEDIUM EPSS 1% → fixed in 3.9.1 CVE-2023-40217 MEDIUM EPSS 1% → fixed in 3.11.5 CVE-2026-7210 HIGH EPSS 1% → fixed in 3.15.0Other Python versions
Check another release line of Python.
Frequently asked
Is Python 2.7.18 patched?
Python 2.7.18 is end-of-life and no longer receives security patches. Move to 3.14.6.
When does Python 2.7 reach end-of-life?
Python 2.7 reached end-of-life on 2020-01-01 and no longer receives security patches.
What is the latest version of Python?
The latest supported Python release is 3.14.6.
Is Python 2.7.18 still receiving security updates?
No — Python 2.7.18 is on the 2.7 line, which reached end-of-life on 2020-01-01 and no longer receives security updates. Upgrade to 3.14.6 or later to stay supported.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Python's official advisory before you patch or upgrade — Python official site ↗