we_are_coded.by CODE · The world, decoded
БГ
Who's who

The software that's always full of holes

The BasicsUpdated on 16 August 2026we are coded

Joomla, SharePoint, ColdFusion, curl - four different things with one thing in common: old, everywhere, forgotten.

Checked on16 August 2026
In short: Joomla, SharePoint, ColdFusion and curl are four different things, united by one common trait - they're everywhere, nobody watches them, and that's exactly why they're hackers' favorite doorway. Joomla is a website-building system, like WordPress. SharePoint is Microsoft's tool where companies keep their documents. ColdFusion is an old platform for building web applications. curl is a small, invisible program that pulls data in almost every script in the world. All of them carry holes, because they were built long ago and then forgotten.

Joomla is a content management system - the same idea as WordPress, just with a different logo. With it, someone with zero coding knowledge can put up a site in an hour. The problem is never Joomla itself - its team patches holes regularly. The problem is the thousands of plugins, written by random people around the world, installed once and forgotten forever. Every such plugin is a key left under the doormat. If a breach happens, it almost never comes through the central system - it comes through the plugin someone uploaded in 2016 and hasn't opened the admin panel since.

SharePoint is a much heavier story, because it's not a site for resumes - companies keep contracts, blueprints, HR data, internal correspondence there. Microsoft sells it as the office's "headquarters." When a hole opens in SharePoint, it's not a blog post that leaks - it's the entire inside of the organization. And because SharePoint installs deep in the company's network, a breach in it isn't one site's incident. It's an open door to everything else connected to it.

ColdFusion is something most people have never heard of. Yet it's all around them - government portals, hospital systems, old internal bank applications. It was created in 1995, before Google even existed, and has changed owners three times since. Companies using it rarely replace it - it's too expensive, too risky, it's handled carefully. Result: critical infrastructure held up by technology from another era, with a team that scattered long ago.

curl is the opposite extreme - not a system, but an invisible worker. A small command that pulls and sends data across the internet. Every site, every app, every script in the world uses it somewhere deep in its code, usually without anyone consciously choosing it - it's just there, built in. That's exactly why a hole in curl isn't one product's incident. It's a tremor that runs through millions of systems at once, because they all stand on the same, invisible piece of code.

The software isn't the problem - forgetting is the problem. Everything listed here works fine. Nobody's gone in to check the pipes in years.

This is what catches my eye

All of this reminds me of old buildings with bad wiring. The facade is painted, the elevator works, tenants come and go undisturbed. But behind the wall the pipes are from another decade - nobody has an up-to-date plan of the wiring, and the last time an electrician was inside was before the ownership changed. Nobody did anything wrong - the building is just aging faster than it's being maintained.

The difference with real buildings is that there you at least sense the problem - a leaking pipe, a flickering light. In software, the hole is silent. It sits open for years, until someone decides to walk through it. And because these four things prop up half the internet underneath, when the doorway opens, it's not one room that falls - it's the whole wing.

The visual is generated code art. No third-party images.
Official primary sources
→CISA: the KEV catalog - which software gets exploited most