Unpatched Software: The Open Door You Forgot About

Aug 31, 2026Incognito CyberSecurity

Unpatched Software: The Open Door You Forgot About

🇲🇽 Leer en Español →

There is a computer in almost every small business I walk into that nobody wants to touch. It runs the accounting software, or the label printer, or the camera system. It has worked fine for years. And because it has worked fine for years, nobody has updated it in a very long time.

That machine is usually the way in.

Last week made the point for me. On August 26 and 27, the federal Cybersecurity and Infrastructure Security Agency (CISA) added nine more flaws to its Known Exploited Vulnerabilities catalog — eleven in seven days, and roughly thirty in the last month. “Known exploited” is not a prediction. It means someone has confirmed that criminals are using that flaw right now, against real businesses.

The detail that should get your attention

Look at what actually made the list. Next to a brand-new Citrix NetScaler flaw and a current Linux bug, CISA added a Microsoft SQL Server vulnerability from 2019 and two Red Hat flaws from 2015.

Read that again. Problems that were disclosed and fixed by the vendor more than a decade ago are still working in 2026. Not because the attack is clever, but because plenty of businesses never installed the fix.

Nobody is choosing you. They are scanning.

Owners tell me all the time, “We are too small to be a target.” That was true back when attacks were hand-crafted. It stopped being true when they were automated. A criminal group writes one script, points it at every internet address in North America, and lets it run. The script does not know your revenue. It only knows whether your equipment answers with a version number that has a public exploit attached to it.

A dental office in Oro Valley and a hospital in Phoenix look identical to that script. The difference is that the hospital has someone whose full-time job is patching, and you have a Tuesday.

Why small businesses fall behind

“It works. Do not touch it.”

This is the most expensive sentence in small business IT. The old workstation running the machine on the shop floor, the server the previous IT guy set up in 2017, the router the internet company dropped off — all of it works, so all of it gets skipped. Meanwhile the vendor ended support and stopped shipping fixes entirely.

End-of-life software is a different category of risk than out-of-date software. Out-of-date can be fixed on a Saturday morning. End-of-life will never be fixed. Ever. The only move left is to replace it, and the longer you wait the more expensive that replacement gets.

Nobody owns the list

Most of the businesses we onboard cannot tell me how many computers they have. Not because they are careless — because devices arrive one at a time, over many years, from different people. You cannot patch what you do not know you own, and that is the real reason a 2015 flaw is still sitting on somebody’s network in 2026.

Infographic: three steps to close the patching gap - inventory it, patch fast, retire it

What you can do this week

  1. Write down everything. Every computer, laptop, phone, tablet, printer, router, firewall, camera recorder and server. One spreadsheet. Model, age, and who uses it. This takes an afternoon and it is the single most useful hour of security work most owners will ever do.
  2. Handle the internet-facing gear first. Your firewall, router, VPN and any remote-access tool are the pieces those scanners actually see. If any of them has a pending firmware update, that is your Monday. Everything else can wait a week.
  3. Turn automatic updates back on. Somebody turned them off years ago because a restart interrupted a workday. That trade is no longer worth it. Schedule the restarts for after hours instead, and pair it with real endpoint protection so you are covered between patch cycles.
  4. Circle anything past end-of-life. If the vendor no longer supports it, it goes on a replacement plan with a date on it — not a someday list. Budget for it now while it is a purchase instead of an emergency.
  5. Test a restore, not just a backup. Patching reduces the odds of getting hit. Secure, tested backups decide how bad it is when something gets through anyway. A backup you have never restored from is a hope, not a plan.
  6. Give your team one sentence. “When your computer asks you to restart for updates, say yes today.” That sentence, repeated, closes more holes than any product. A little security awareness training makes it stick, and good spam and virus filtering keeps the junk that exploits old software out of the inbox in the first place.

The bottom line

You do not need a security operations center. You need to know what you own, keep it current, and retire what the manufacturer has walked away from. That is it. The businesses getting hurt right now are not the ones missing some exotic defense — they are the ones running software with a fix that has been available, free, for years.

If reading this made you think of one specific machine in your office, that is not a coincidence. That is the one. Go look at it this week. And while you are at it, it pairs well with our recent piece on the passwords your browser saved, because attackers usually chain the two together.

Not sure what you are running?

We will inventory every device on your network, tell you what is out of date, and flag anything the manufacturer has stopped supporting. No charge, no obligation.

Book a complimentary visit →

Send us a message

Questions about patching, end-of-life equipment, or anything else in this article? Send it over and I will answer it personally. You can also browse more of our cybersecurity articles for small businesses.

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

— Nemuel Cruz, Incognito Cyber Security

About the author

Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News