// OSSeva Blog
OperationsWho Supports VMware GemFire 9.x Besides Broadcom, and Is There Commercial Support for Apache Geode?
The short answer
Broadcom no longer supports any GemFire 9.x release: 9.15, the last 9.x line, left general support on 31 October 2025, and 10.0 followed on 30 April 2026. Outside Broadcom, OSSeva publishes CVE coverage for GemFire 9.x and 10.x, including 9.15 and 10.0, and Perforce OpenLogic lists GemFire among the technologies it supports. For Apache Geode, OSSeva is the provider that publishes commercial support for Geode 1.x and 2.x; Broadcom supports GemFire only, and OpenLogic's list does not name Geode.
Broadcom remains the right answer for GemFire if you can move to 10.2 or 10.3, which it supports to 31 October 2028 and 31 July 2029.
Where GemFire and Geode stand
Broadcom's own knowledge base says that after Geode 1.15.0, Apache Geode and GemFire "branched into two distinct products with separate versioning tracks". So the two now have separate life cycles.
| Line | Status on 6 October 2026 | Latest release |
|---|---|---|
| GemFire 10.3 | Broadcom general support to 31 July 2029 | 10.3.2 (22 September 2026) |
| GemFire 10.2 | Broadcom general support to 31 October 2028 | 10.2.8 (22 September 2026) |
| GemFire 10.1 | Broadcom general support to 28 February 2027 | 10.1.9 (18 August 2026) |
| GemFire 10.0 | Ended 30 April 2026 | 10.0.8 (17 March 2026) |
| GemFire 9.15 | Ended 31 October 2025 | 9.15.16 (8 July 2025) |
| Apache Geode 2.0 | Main development line; no published support window | 2.0.3 (September 2026) |
| Apache Geode 1.15 | The project's support line; no published support window | 1.15.5 (September 2026) |
Geode's recent history explains why buyers ask about it. Its May 2025 board report described the project as "Dormant to Low", with stale pull requests and security reports. Contributors then shipped 1.15.2, the first release in three years, and Geode 2.0.0 in December 2025, which requires Java 17 and moves to the jakarta namespace. The August 2026 report lists the project as ongoing, but notes "a general decline in community activity" and that some releases struggle to get enough votes. The GemFire and Geode chart tracks every line, and GemFire and Geode vulnerabilities by version lists the advisories.
GemFire and Geode support providers compared
Each row reflects what the provider publishes on its own site as of 6 October 2026.
| Provider | What it covers | Versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| Broadcom (VMware Tanzu GemFire) | GemFire releases and technical support, plus GemFire Search, Vector Database, Session Management and Management Console add-ons | GemFire 10.1, 10.2 and 10.3; no 9.x or 10.0. Geode is not covered | Broadcom subscription | Yes |
| OSSeva | CVE patches as signed artifacts for GemFire and Geode, with priority for serialization and deserialization flaws; Spring Data GemFire and Geode coverage; GemFire to Geode migration assessment and 24/7 operations on higher tiers | GemFire 9.x and 10.x, including 9.15 and 10.0; Geode 1.14, 1.15 and 2.x | Signed Maven artifacts and Docker images | Yes |
| Perforce OpenLogic | Technical support for GemFire at Silver and Bronze levels | No version list published; Geode not listed | Support subscription | Yes |
One row needs care. OpenLogic lists GemFire without naming versions or saying whether it supplies fixes for releases Broadcom has retired, so ask for that in writing before relying on it for 9.15.
How the providers differ
Broadcom
Broadcom is the only source of GemFire's own releases and of its commercial extensions, such as GemFire Search and the Vector Database. If your licence is in place and you can upgrade, GemFire 10.2 or 10.3 gives you supported releases into 2028 or 2029, and 10.3.0 added JDK 25 support. A line whose support date has passed does not come back: GemFire 9.15 and 10.0 get no further Broadcom patches. The move from 9.15 to 10 changes classloading for deployed JARs and drops Tomcat 7 and 8 from the session modules; our GemFire 9.15 to 10 upgrade guide covers it.
Perforce OpenLogic
OpenLogic lists GemFire as supported at its Silver and Bronze levels, as part of a catalogue of more than 400 technologies. It suits a team that wants help running GemFire under a broader contract. See OSSeva vs OpenLogic.
OSSeva
OSSeva for GemFire and Geode covers both the commercial and the community builds: GemFire 9.x and 10.x, including the 9.15 and 10.0 lines Broadcom has retired, and Geode 1.x and 2.x. Java serialization flaws, which can mean remote code execution on an exposed grid, are handled as a priority class. Spring Data GemFire and Spring Data Geode are included for applications that embed a client. Assure adds a cluster topology and security audit, region access review, WAN replication review and a GemFire to Geode migration assessment that inventories the GemFire-only features you use. Operate adds 24/7 cluster and memory monitoring, a 15-minute P1 response and execution of the migration. Pricing is per cluster, not per node or stored gigabyte.
How to choose
| Situation | Usual answer |
|---|---|
| On GemFire 9.15 or 10.0, licence renewing and upgrade possible | Broadcom, moving to 10.2 or 10.3 rather than 10.1 |
| On GemFire 9.15 or 10.0 and not ready to upgrade | OSSeva CVE coverage while the next step is chosen |
| Leaving GemFire for open source | Apache Geode 2.0 or 1.15, with OSSeva support and a migration assessment first |
| Already on Geode and needing a vendor behind it | OSSeva |
| Using GemFire Search, Vector Database or Management Console | Broadcom, since those features have no Geode equivalent in the box |
Moving from GemFire to Geode is a migration rather than an upgrade, because GemFire's commercial features need replacing and the two codebases have diverged since 1.15.0. Leaving Tanzu GemFire for Geode covers that route, and Exiting Tanzu covers the wider Broadcom picture.
Where OSSeva fits
OSSeva covers the GemFire lines Broadcom has retired and the Geode lines Apache releases without a support window, under one contract, and can run the grid while a migration is planned. See the extended support vendor roundup for how OSSeva compares across other technologies.
Frequently asked questions
Who supports VMware GemFire 9.x besides Broadcom?
Broadcom itself no longer supports any 9.x release; 9.15 ended on 31 October 2025. OSSeva publishes CVE coverage for GemFire 9.x, including 9.15, and OpenLogic lists GemFire among its supported technologies without naming versions.
Is there commercial support for Apache Geode?
Yes. OSSeva publishes support and CVE patches for Geode 1.14, 1.15 and 2.x. Broadcom supports GemFire, not Geode, and says the two are separate products since Geode 1.15.0. OpenLogic's published list names GemFire but not Geode.
Which GemFire versions does Broadcom still support?
GemFire 10.1 to 28 February 2027, 10.2 to 31 October 2028 and 10.3 to 31 July 2029, according to Broadcom's product lifecycle table.
Is Apache Geode still maintained?
Yes, though thinly. After three years without a release, the project shipped 1.15.2 in 2025, Geode 2.0.0 in December 2025 and further 2.0 and 1.15 maintenance releases through September 2026. Its August 2026 board report notes a decline in community activity, and the project publishes no support window for any line.
Can we run Geode instead of GemFire?
Often, if you do not depend on GemFire-only features such as GemFire Search, the Vector Database or the Management Console. Plan it as a migration with an inventory of those features, since GemFire and Geode have diverged since 1.15.0.
Tags
Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.