Earlier quoted context omitted.
Most likely your "hasn't been updated for years". Given all the security vulnerabilities that have been disclosed, including things like Heartbleed, I hope you meant your "setup hasn't been changed in years".
No, I run nothing like apt update. Why would I fix something not broken? And no, I do not run ssl. I like to limit the number of moving parts. Anyway, if someone can manage to access my servers with only nginx serving static files, they deserve to 0wn it :-)
While your setup stays the same, major security flaws are found in different parts of the stacks.
Security is a process, by neglecting it you're paying for resources that are abused by attackers in order to harm other users.