Cisco AnyConnect Is Now Secure Client: Migrate the Client or Leave the Architecture?

AnyConnect 4.x is unpatched since March 2024 and support ends in 2027. The exact dates, Secure Client 5.x requirements, and the ZTNA path compared.
Network administrator and colleague reviewing a remote-access migration decision on a laptop in a modern office

Cisco AnyConnect 4.x stopped receiving security patches on 31 March 2024, and full support ends on 31 March 2027. If your remote workforce still connects through it, you are running an unpatched client against a headend that is probably end-of-life too. The forced move to Cisco Secure Client 5.x is the moment to ask a bigger question: do you upgrade the client, or do you leave the architecture that keeps producing these deadlines?

Key takeaways

  • AnyConnect 4.x reached end-of-software-maintenance on 31 March 2024; no patches have shipped since, and the final Last Date of Support is 31 March 2027.
  • Active AnyConnect Plus or Apex licence holders can upgrade to Cisco Secure Client 5.x at no extra licence cost, but the headend must run at least ASA 9.14, and 9.17+ for modern SAML authentication.
  • The client upgrade does not fix the hardware problem: ASA 5525-X/5545-X/5555-X firewalls lost all support on 30 September 2025, and the 5506-X/5508-X/5516-X follow on 31 August 2026.
  • The ASA/FTD VPN stack has been exploited continuously since 2020, from Akira ransomware brute-forcing (CVE-2023-20269) to the state-sponsored ArcaneDoor backdoor campaign (CVE-2024-20353).
  • Gartner projected that 70% of new remote-access deployments would run on ZTNA rather than VPN by 2025, up from under 10% in late 2021 — the client swap is optional; the architecture question is not.

What exactly is ending, and when?

Cisco published the formal end-of-life bulletin for AnyConnect 4.x on 30 May 2023, which also marked the end-of-sale date. The operational cut-off came ten months later: since 31 March 2024, Cisco Engineering has issued no updates, bug fixes or security patches for the 4.x train, whose final build is 4.10.x (4.10.08029 as last maintenance release). TAC will still answer configuration questions for contract holders until 31 March 2027, but it cannot patch code. Any vulnerability found in AnyConnect 4.x today stays open on every endpoint that runs it.

Milestone AnyConnect 4.x Cisco Secure Client 5.x
General availability 20 October 2014 31 May 2022
End-of-sale 30 May 2023 Active / orderable
End of software maintenance 31 March 2024 (no patches since) Active releases
Last Date of Support 31 March 2027 Supported
Licensing Plus / Apex (legacy) Advantage / Premier; free upgrade with active Plus/Apex or support contract

What does the Secure Client upgrade actually involve?

Cisco Secure Client 5.x is more than a rebrand: it folds remote-access VPN, Secure Endpoint, the Umbrella roaming client, the Network Visibility Module, ISE Posture and a Zero Trust Access agent into one installer. The upgrade itself is free for organisations with active AnyConnect Plus or Apex terms, or perpetual licences under support, per Cisco’s EOL bulletin.

The catch sits behind the client. Secure Client 5.x requires ASA 9.14 as an absolute minimum. SAML external-browser authentication — the mode you need for modern SSO, FIDO2 and passwordless flows — requires ASA 9.17.x and ASDM 7.17.x. TLS 1.3 requires ASA 9.19.1 or later. Practitioner reports collected in the Secure Client administration guide and community threads add the operational friction: macOS deployments need MDM-approved system extensions, endpoint AV/EDR tools block the self-extracting OPSWAT posture updates unless Cisco’s paths are excluded, and in February 2026 Field Notice FN74373 warned of service interruptions in the ZTA agent versions 5.1.8 through 5.1.12. An upgrade, in other words, is a project — not a checkbox.

Why the client is only half the problem

Most AnyConnect estates terminate on ASA 5500-X hardware, and that hardware is dying on its own schedule. The 5512-X and 5515-X lost all support back in August 2022. The mid-range workhorses — 5525-X, 5545-X, 5555-X and 5585-X — reached their Last Date of Support on 30 September 2025. The smaller 5506-X, 5508-X and 5516-X follow on 31 August 2026. After those dates there are no replacements, no TAC cases and no security fixes for the box that terminates every remote session your company makes.

Staying with Cisco therefore means buying new Secure Firewall 1200/3100/4200 hardware and re-architecting policies — a capital outlay that, as the ASA 5500-X end-of-life guide details, often equals or exceeds the cost of moving to a cloud-native ZTNA platform outright.

How bad is the security track record?

The pattern that pushed Fortinet, Citrix and Ivanti customers toward migration applies here too: an internet-exposed VPN concentrator is a standing target.

Vulnerability Component Key dates Threat context
CVE-2020-3580 (XSS) ASA/FTD web services Published Oct 2020; CISA KEV 3 Nov 2021 Still weaponised by Akira and LockBit ransomware for initial access
CVE-2023-20178 AnyConnect/Secure Client (Windows) NVD 28 June 2023, CVSS 7.8 Local privilege escalation to SYSTEM via the update process
CVE-2023-20269 ASA/FTD remote-access VPN Advisory Aug 2023 Brute-force vector used by Akira to find valid VPN credentials
CVE-2024-20353 (ArcaneDoor) ASA/FTD CISA KEV 24 April 2024 State-sponsored zero-day campaign implanting persistent backdoors
CVE-2024-20474 Secure Client IKEv2 Advisory 23 Oct 2024 Unauthenticated remote DoS against the client
Posture engine DLL hijack Secure Client (Windows) Advisory 5 March 2025 Local SYSTEM-level code execution via HostScan search paths

Note that the last three entries affect the new client, not the old one. Upgrading to Secure Client 5.x keeps you inside the same perimeter model: open inbound ports, full-tunnel network access, and a headend worth attacking. The vendor-by-vendor SSL VPN timeline shows how consistently that model is being retired across the industry.

Path A vs Path B: upgrade the client or change the model?

Dimension Path A: Secure Client 5.x upgrade Path B: ZTNA/SASE migration
Access model Full- or split-tunnel network access Per-application micro-segmentation; user never lands on the LAN
Attack surface Open inbound ports on ASA/FTD No inbound ports; outbound-only TLS to a broker
Hardware Requires supported (often new) Secure Firewall appliances None; lightweight connectors
Deployment friction Headend OS upgrades, macOS extensions, AV exclusions, OPSWAT syncs Agent via MDM for managed devices; browser portal for contractors and BYOD
Lateral movement Possible from an infected client Blocked by design
NIS2 alignment Depends on patch discipline across client and hardware Native least-privilege and segmentation

Cisco’s own strategic answer is Cisco Secure Access, a cloud SSE/SASE platform in which Secure Client becomes the unified agent. It is a credible enterprise product, but it is sold through enterprise-tier bundles with minimum seat commitments and multi-product dependencies such as ISE and XDR — packaging that fits 5,000-seat estates better than a 300-person organisation. For the mid-market, a purpose-built platform reaches the same architecture with far less overhead, and the IPsec-versus-ZTNA migration guide walks through the mapping in detail.

For price context: published list prices among ZTNA alternatives run from $6 to $14 per user per month (NordLayer tiers), $10 at Twingate and Check Point Harmony SASE Essentials, and a $7–$12 benchmark range for Zscaler — all as of August 2026 and typically before add-ons like dedicated gateways.

What does NIS2 say about running EOL remote access?

Under the Belgian NIS2 law of 26 April 2024 (published 17 May 2024), supervised by the Centre for Cybersecurity Belgium, essential and important entities must run continuous vulnerability management. Operating software past its end-of-maintenance date — which describes every AnyConnect 4.x client since 31 March 2024, and every EOSL ASA appliance — sits squarely against that duty. If a breach arrives through an unpatched client or headend, the management board carries personal regulatory exposure. There is also a jurisdictional dimension: US-headquartered cloud security services operate under the US CLOUD Act and FISA 702, which as of August 2026 remains a live data-sovereignty consideration for European organisations routing authentication logs and inspected traffic through US-controlled platforms.

A realistic migration timeline

A 200–500 user organisation typically completes a ZTNA transition in 8 to 12 weeks: identity-provider integration and connectors in weeks 1–2, application mapping and a 50-user pilot in weeks 3–5, full rollout plus agentless portals for contractors in weeks 6–8, then log validation, AnyConnect profile termination and ASA decommissioning in weeks 9–12. Run both systems in parallel during the phase-in; retire the VPN when the logs show it has gone quiet.

Use the deadline once, not twice

The pragmatic test is this: if your ASA hardware is supported, your licences entitle you to Secure Client, and your team absorbs the deployment quirks, the upgrade buys you time — but it re-commits you to hardware refreshes, patch cycles and an exposed perimeter until the next bulletin. If your headend is on the 2025–2026 EOSL list anyway, you are paying for a new architecture either way; choose the one that ends the cycle. For an EU mid-market team, an EU-sovereign platform like Jimber replaces the client, the concentrator and the open ports with per-application access, agentless options for third parties and OT, and one flat, predictable licence — with your data under European jurisdiction. Book a demo to map your AnyConnect estate against a ZTNA rollout, or start with the VPN alternative overview.

Frequently asked questions

Is Cisco AnyConnect 4.x completely end of life?

Software maintenance ended on 31 March 2024, so no patches or bug fixes have shipped since. Limited TAC assistance remains available to contract holders until the Last Date of Support on 31 March 2027, after which the client is fully obsolete.

Do we have to pay to upgrade to Cisco Secure Client 5.x?

No. Organisations with active AnyConnect Plus or Apex term licences, or perpetual licences with an active support contract, are entitled to Secure Client 5.x at no additional licensing charge.

Can Secure Client 5.x run against our existing ASA 5500-X firewalls?

Technically yes, from ASA 9.14 upward — but the hardware itself is the problem. The 5512-X/5515-X lost support in 2022, the 5525-X/5545-X/5555-X on 30 September 2025, and the 5506-X/5508-X/5516-X reach end of support on 31 August 2026. Connecting a supported client to an unsupported headend leaves the perimeter unpatched.

What ASA version do we need for modern SAML authentication?

SAML external-browser mode, which enables SSO in the user’s default browser plus FIDO2 and WebAuthn, requires ASA 9.17.x with ASDM 7.17.x or later. TLS 1.3 support requires ASA 9.19.1 or later.

Why does our antivirus block Secure Client updates?

Secure Client auto-updates its OPSWAT posture engine whenever the headend runs a newer library, using self-extracting executables that endpoint protection tools often block. Cisco’s documented fix is to exclude the Cisco installation paths in your AV/EDR console.

How does the Belgian NIS2 law treat unpatched VPN software?

The law of 26 April 2024 requires continuous vulnerability management and remediation. Running software past end-of-maintenance — AnyConnect 4.x today, or an EOSL ASA — conflicts with that duty, and a resulting incident exposes directors to administrative fines and personal liability under CCB supervision.

How long does a mid-market ZTNA migration take?

Typically 8 to 12 weeks for 200–500 users: identity integration and connectors first, then a pilot group, then phased rollout with agentless portals for third parties, and finally VPN decommissioning once logs confirm the tunnels are unused.

Find out how we can protect your business

In our demo call we’ll show you how our technology works and how it can help you secure your data from cyber threats.

Cybersecurity
Are you an integrator or distributor?

Need an affordable cybersecurity solution for your customers?

We’d love to help you get your customers on board.

checkmark

White glove onboarding

checkmark

Team trainings

checkmark

Dedicated customer service rep

checkmark

Invoices for each client

checkmark

Security and Privacy guaranteed