Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

What Is Unpatched Software, and Why Does It Actually Matter?

Short answer: Unpatched software is a program with a known, publicly fixed security flaw whose update hasn't been installed, and attackers actively scan the internet for exactly that gap. Turning on automatic updates wherever they're offered closes the door before those scans find it.

Both the ransomware and malware posts named this as a common way in, without fully explaining it. Here's what "unpatched software" actually means, and why the update notification you keep dismissing matters more than it looks like it does.

What's actually happening

No software is written perfectly. A "vulnerability" is just a mistake in the code that creates a way in — every piece of software has them, discovered over time by the company itself, independent security researchers, or sometimes attackers first. When one's found, the company fixes it and ships that fix as an update, often called a "patch."

Here's the part that surprises people: releasing the patch doesn't just fix the problem — it also reveals exactly where the problem was. Security researchers call the period right after a patch comes out "Exploit Wednesday" (a play on "Patch Tuesday," when many companies release monthly updates) — attackers compare the old and new code, work out precisely what changed, and build a working exploit targeting anyone who hasn't installed the update yet. That window between a patch existing and an exploit targeting it has been shrinking for years, in some cases down to a matter of hours. The update isn't just a fix; it's also a public map of exactly what's broken on every system that hasn't installed it.

This is different from a "zero-day" — a vulnerability being actively exploited before any fix exists at all. Zero-days are real but comparatively rare and hard to defend against directly. The much more common, much more preventable risk for most small businesses is the opposite: a fix has existed and been public for weeks or months, and the only thing missing is installing it.

The patch fixes the gap — and shows everyone still unpatched exactly where it was

A local business scenario

(A composite, illustrative pattern — not one specific business's story.)

A small business runs its website on an older version of a common content management system, with a plugin that hasn't been updated in over a year. A security researcher discovers and publicly discloses a vulnerability in that exact plugin version; the plugin's developer ships a fix within days. The business owner never sees the announcement — there's no reason they would — and the update sits unused.

Nobody targeted this business specifically. Automated tools constantly scan large swaths of the internet, checking for the exact software fingerprint that signals "this specific outdated version is running here." One of those scans finds the site weeks later and exploits the known, already-patched gap automatically, no human attacker involved on the other end at any point. The business wasn't singled out — it was simply still running the version the patch was written for.

Best practices

  1. Turn on automatic updates everywhere they're offered — operating system, browser, and any software that supports it. This is the single biggest lever, and it requires nothing ongoing from you once it's set.
  2. Don't let "if it ain't broke, don't fix it" apply to security updates. That instinct is backwards here — a system that looks fine can already be running exactly the version a public exploit targets.
  3. Retire software once it reaches end-of-life. Once a vendor stops releasing security updates for a product, it will never be patched again, no matter what's found in it afterward — upgrade or replace it rather than keep using it.
  4. Prioritize anything internet-facing first — a website, a remote-access tool, a VPN gateway. These are exactly what automated scanners find and probe; an internal-only tool is comparatively lower urgency.
  5. If you're not sure what's out of date on your own site, a free automated check is a reasonable starting point (see below).

Helpful, free resources

A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.