End-of-life software

Unsupported software does not stay as secure as it was on its last day of support. It gets less secure every month.

Nothing changed in the software. What changes is that new flaws keep being found in the components it uses, and nobody is issuing fixes any more. The exposure accumulates and cannot be removed. It also stops being a patching problem and becomes a replacement project, which is why it slips: the answer is no longer an afternoon's work, and so it keeps not happening.

Checked against the primary source.

More on Vulnerability management