I recently read a statement from the Cybersecurity and Infrastructure Security Agency (CISA) highlighting an urgent advisory from the National Security Agency (NSA) about the risks that come with running unpatched versions of older Windows operating systems. That advisory centered on BlueKeep (CVE-2019-0708), a critical flaw in Remote Desktop Services that left millions of legacy Windows systems open to remote takeover with no user interaction required. While BlueKeep is no longer new, the warning it delivered still applies to any organization running software past its Windows end of life date.
First, you know it’s serious if the NSA, an entity in the US who depends on the collection and processing of information, is worried that your personal information is at risk. Second, it’s another in a long line of reasons to not allow your network to fall into such disarray that you can no longer protect it.
Why Are Windows Updates So Important?
Microsoft Windows is complex software. It needs to be. In order to do everything we need it to do every day, and work with everything we need it to work with, it contains a lot of features and capabilities baked in.
The more complex your software is, the more chances there are that someone out there could find a vulnerability. This happens all the time, and when vulnerabilities are discovered, good software developers will quickly build an update that fixes them before they are exploited. That’s why proactive threat detection and response matters so much: staying ahead of bad actors who are constantly scanning for systems that haven’t been patched.
That’s what Windows updates are. Sure, there are new features being added in many of the updates as well, but the security patches are what is truly critical.
Please note that sometimes it isn’t a good idea to just let Windows updates run automatically. Sometimes an update can break something else (like a third-party application or internal workflow). It’s best to test updates before deploying them across your network.
Problems Get Exposed as They Are Fixed
Let me give you a more old-school example. Way back in the day, you used to be able to “hack” a vending machine with fake coins called slugs. To combat this, new vending machines were created that had multiple sensors to measure and analyze the coin in real time to determine if it were real. When these new machines were released, they were also noticeably newer-looking than the old, hackable vending machines. Word got out about how easily the older machines could accept a slug and encouraged people to seek them out to get free beverages.
What can we take away from this?
- If you owned an old vending machine, you were at risk of being hacked.
- Older vending machines were targeted by people who knew that they were hackable, as opposed to the new vending machines that weren’t as easily exploitable.
- Risk increased as time went on if you owned an older vending machine.
- How often do you see vending machines that even take coins these days?
When Microsoft releases security updates, this exposes the vulnerability to the world. This includes hackers. This means everyone is on borrowed time once an update comes out, because hackers know that not everyone will update.
Older Operating Systems Have the Highest Risk
If you are running a version of Windows (or any software) that has reached the end of its developmental and support life, you are playing with fire. Your security and compliance posture depends entirely on your software being actively maintained and patched.
For example, if you are still running Windows Vista (please, I hope you aren’t), then Microsoft’s mainstream support ended in April 2012. They offered extended support up until April 2017.
Mainstream support is when Microsoft is still providing features, security updates, patching bugs, and more. Extended support is when Microsoft stops adding new features and only provides bug fixes and patches, and only provided that you are on the exact version of the software or operating system that Microsoft says they are supporting.
Back to our example of running Windows Vista: it’s pretty clear that Windows Vista was not the shining example of a perfect operating system, and by the end of its life there were no shortage of flaws for hackers to target. If you are running Vista now, you are constantly wide open for any threats that the operating system doesn’t have protections against.
Microsoft’s Support Lifecycle End Dates
Here is a reference list of current and historical operating system and server support end dates. For the most current information on any product, always consult Microsoft’s official product lifecycle page. Note that several entries are reaching end of support in 2026, including SQL Server 2016 (SP1) and SharePoint 2016, both on July 14, 2026.
Windows Operating System
- Windows XP – April 8, 2014 (Reached EOL)
- Windows Vista – April 11, 2017 (Reached EOL)
- Windows 7 – January 14, 2020 (Reached EOL)
- Windows 8 – January 10, 2023 (Reached EOL)
- Windows 10 – October 14, 2025 (Reached EOL)
- Windows 11 – Currently supported (see Microsoft’s lifecycle page for version-specific servicing dates)
Microsoft Server Operating Systems
- Windows Server 2008 – July 12, 2011 (Reached EOL)
- Windows Server 2008 (SP2) – January 14, 2020 (Reached EOL)
- Windows Server 2008 R2 – April 9, 2013 (Reached EOL)
- Windows Server 2008 R2 (SP1) – January 14, 2020 (Reached EOL)
- Windows Server 2012 – October 10, 2023 (Reached EOL)
- Windows Server 2012 R2 – October 10, 2023 (Reached EOL)
- Windows Server 2016 – January 11, 2027 (Extended Support through January 2027)
- Windows Server 2019 – January 9, 2029 (Extended Support)
- Windows Server 2022 – October 13, 2026 (Mainstream Support ends; Extended Support begins)
- Windows Server 2025 – Currently supported
Microsoft SQL Server
- SQL Server 2005 (SP4) – April 12, 2016 (Reached EOL)
- SQL Server 2008 (SP4) – July 9, 2019 (Reached EOL)
- SQL Server 2008 R2 – July 10, 2012 (Reached EOL)
- SQL Server 2008 (SP3) – July 9, 2019 (Reached EOL)
- SQL Server 2012 – January 14, 2014 (Reached EOL)
- SQL Server 2012 (SP3) – July 12, 2022 (Reached EOL)
- SQL Server 2014 – July 12, 2016 (Reached EOL)
- SQL Server 2014 (SP2) – July 9, 2024 (Reached EOL)
- SQL Server 2016 – January 9, 2018 (Reached EOL)
- SQL Server 2016 (SP1) – July 14, 2026 (Reaching EOL)
- SQL Server 2017 – October 12, 2026 (Approaching EOL)
Exchange Server
- Exchange 2007 – January 13, 2009 (Reached EOL)
- Exchange 2007 (SP3) – April 11, 2017 (Reached EOL)
- Exchange 2010 – October 11, 2010 (Reached EOL)
- Exchange 2010 (SP3) – January 14, 2020 (Reached EOL)
- Exchange 2013 – April 11, 2023 (Reached EOL)
- Exchange 2013 (SP1) – April 11, 2023 (Reached EOL)
- Exchange 2016 – October 14, 2025 (Reached EOL)
SharePoint
- SharePoint 2010 – July 10, 2012 (Reached EOL)
- SharePoint 2010 (SP2) – October 13, 2020 (Reached EOL)
- SharePoint 2013 – April 14, 2015 (Reached EOL)
- SharePoint 2013 (SP1) – April 11, 2023 (Reached EOL)
- SharePoint 2016 – July 14, 2026 (Reaching EOL)
If you are running outdated software, you are putting yourself, your business, your employees, and your clients at risk. Want help planning your next upgrade? Take a look at our vulnerability testing services to understand where your current environment stands.
Outdated Software Is a Business Risk You Can Eliminate Today
The pattern repeats itself with every version of this story: when software reaches its Windows end of life, so does your protection. No more patches means no more fixes for newly discovered vulnerabilities, and attackers know exactly which systems are no longer defended. Whether it is a workstation still running Windows 10, a server on an unsupported build, or a database instance that passed its SQL Server end-of-support date months ago, the exposure is real and the risk compounds every day that passes without action.
The good news is that you don’t have to figure this out alone. WheelHouse IT works with businesses across South Florida and New York to assess their current environment, identify outdated or unsupported software, and build a realistic upgrade plan that protects operations without disrupting them. Our complimentary network risk assessment is the right first step, and our managed IT services team handles ongoing patch management and lifecycle planning as part of your monthly support.
Ready to find out where your network stands? Reach out to WheelHouse IT today:
- Florida: (954) 474-2204
- New York: (516) 536-5006



