Rented, Word

A Rented Word Processor, a Bloated C: Drive and a Looming EU Deadline: Why Software Security Is Now a Legal Obligation

Published on 09/28/2026 at 02:20 | Editorial boerse-global.de

Case study says outdated security patches alone make rented software legally defective, as EU reporting duties under the Cyber Resilience Act now apply.

Software Rental Defect: Stale Security Updates Breach Contract
A Rented Word Processor, a Bloated C: Drive and a Looming EU Deadline: Why Software Security Is Now a Legal Obligation Illustration mit AI erstellt.

A consumer rents a word processing program. Five years in, the security updates have fallen hopelessly out of date — yet the software still opens, still saves, still does everything she needs it to do. According to a legal case study from the learning platform Jurafuchs reported on 27 September 2026, that gap between smooth everyday performance and stale security patches is enough, on its own, to constitute a legal defect.

The reasoning rests on how lawyers now read digital product contracts. Protection against security risks counts as a contractually owed characteristic of the product, not an optional extra. Vendors are therefore on the hook for maintaining a digital product across the entire rental period, whether or not users ever notice the shortfall in daily use. A program that runs without a hitch can still be riddled with exploitable vulnerabilities — and under this reading, that is a breach, full stop.

What Happens When Device Management Slips

Practice offers plenty of evidence for how costly update and system-control lapses can be. A security analysis published on 26 September 2026 described how unsecured Android scanners and kiosk terminals opened doors into point-of-sale systems, warehouse Wi-Fi and clinical remote-access services running over RDP. In one case, a device reported lost stayed live on the network because nobody had locked it down through mobile device management.

Update mechanisms themselves are not immune. Security researcher Abdelhamid Naceri, in a report dated 27 September 2026, demonstrated a proof of concept called BigDiskBuster that temporarily fills the C: drive during a Defender update. According to Naceri, the flaw affects every currently supported version of Windows. Microsoft had not commented at the time of the report.

Brussels Tightens the Screws

Europe's regulatory ratchet keeps turning. The reporting duties under the EU's Cyber Resilience Act (CRA) have applied since 11 September 2026, with the full set of requirements binding from 11 December 2027 — a timeline reported on 27 September 2026.

How ready is German industry? Not very, judging by PwC's Product Security Survey 2026, which polled 100 German industrial companies in spring 2026. Awareness is high: 88% know the CRA at least in outline. Capabilities look respectable on paper too — 94% of respondents offer updatable products, 84% have documented development processes, 83% carry out a formal risk assessment and 58% run continuous security testing.

Then the numbers turn. Only half of those surveyed have actually started implementing the rules, and a mere 3% consider themselves fully compliant. Half have no dedicated external reporting channel for product security issues, and 27% have no internal process for handling them at all. Software bills of materials (SBOMs) are produced for most or all of the portfolio by just 27% of companies, while 30% receive such lists from suppliers.

Size matters, and not in a flattering way. Among companies with 500 or more employees, 59% have begun implementation work, compared with 37% of smaller firms. And while 13% of the larger companies have not started at all, that figure rises to 34% among smaller industrial businesses.

Disclaimer...

en | boerse | 70190759 |