WannaCry isn’t the headline grabbing monster it was in 2017. But saying it’s completely gone would be a mistake, Microsoft still detects WannaCry-related malware in its security products, with detections updated as recently as 2025 and 2026.
The important part is knowing who’s actually exposed. A fully updated modern Windows computer isn’t sitting there waiting for the original attack to happen. The real problem’s old or badly maintained systems still carrying the weaknesses WannaCry was built to exploit.
Why WannaCry Can Still Matter
The original attack leaned heavily on a Windows SMB vulnerability, CVE-2017-0145. Microsoft had already released a patch before the outbreak, but plenty of machines never got it. WannaCry used that gap to jump from one vulnerable computer to another without needing much user interaction at all.
And that basic lesson hasn’t aged a bit. Unpatched software’s still a common way into networks. Microsoft’s 2025 Digital Defense Report says attackers keep favoring unpatched assets and exposed services, while CISA guidance still tells organizations to prioritize fixing known exploited vulnerabilities. So WannaCry itself is old. The weakness it exposed isn’t.
Who Is Still At Risk?
Say Raj works at a small company where one old Windows machine stays connected to the office network because it runs some ancient software nobody wants to replace. Nothing dramatic happens most Mondays. That’s exactly why the machine gets forgotten.
Unpatched and running vulnerable software, that computer can become a much bigger problem than its age suggests. Old Windows systems are the obvious concern, especially machines that haven’t gotten critical updates in years. SMB exposure matters too, particularly if an outdated system is reachable from others on the network. A forgotten computer can become the weak link even when everything else has been properly maintained.
Is WannaCry Still Infecting Computers?
Yes, detections still exist. Microsoft lists multiple WannaCry and WannaCrypt entries, some updated in 2025, and Microsoft Defender still detects and removes the malware.
Important distinction though, seeing a detection today doesn’t mean another 2017-style global outbreak is coming. The original worm relied on a specific vulnerability patched years ago. Modern ransomware’s a different game entirely, attackers now use newer vulnerabilities and other entry points, then spend time moving through networks before encrypting or stealing data. Microsoft reported in 2025 that ransomware and destructive activity showed up in 19% of its incident response engagements.
What Should You Do?
Don’t spend your afternoon worrying specifically about WannaCry. Spend it making the kind of mistake WannaCry punished much harder to make.
Keep Windows and other software patched, sounds boring because it is, but boring security works. Turn off unnecessary SMB exposure, especially on machines with no good reason to use it. Backups matter enormously too, as long as they’re kept separate from the systems they protect so ransomware can’t reach them as well.
So, Should You Still Worry About WannaCry?
Properly updated computer, not something worth losing sleep over. Situation changes fast with unsupported systems, forgotten servers, or machines that never got patched properly. The malware is old, but the habit that let it spread so far isn’t. Somewhere, there’s always a machine everyone assumes somebody else is looking after.