It isn't necessarily the board software that is the problem. The fact that its "purchased" or "free" board software is irrelevant. There are many ways to get into a server OTHER than through the board software to do damage.
CK5 could have the latest and greatest board software, but if the rest of the server that the board is hosted on has vulnerabilities, then the board software isn't going to help jack.
EVERYTHING on a server needs to be consistently updated, patched, and unused services need to be shut down. It takes time, knowledge, and a diligent admin to stay on top of an entire server.