Security weaknesses outnumbered complete plans

GAO ranked 69 legacy systems submitted by 24 major agencies and selected the 11 most in need of modernization. Seven operated with known cybersecurity vulnerabilities, eight used outdated programming languages and four had unsupported hardware or software.

Only three systems had modernization plans containing all three key elements: milestones, a description of the work and the planned disposition of the legacy system. Six plans were incomplete; two systems—at Defense and Energy—had no modernization plan.

Eleven critical legacy systems
ConditionSystemsShare
Known cyber vulnerabilities763.6%
Outdated languages872.7%
Unsupported hardware/software436.4%
Plan with all key elements327.3%
Incomplete or no plan872.7%
Sources: GAO-25-107795

The oldest systems supported essential missions

The selected systems ranged from 23 to 60 years old and supported health care, tax processing, national security and critical infrastructure. Treasury systems used COBOL and assembly code, while EPA reported obsolete hardware and vulnerabilities that could not be fixed without modernization.

GAO withheld system names in the public version because of sensitivity concerns. That protects operational detail but limits independent testing of agency claims and prevents the public from tying each weakness to a named service.

$100 billion in IT spending did not solve the planning gap

The federal government spends more than $100 billion a year on IT and cyber investments, with agencies historically reporting about 80% for operations and maintenance. Those totals are government-wide and cannot be assigned to the 11 systems.

A prior 2019 list showed the persistence of the problem: by February 2025, only three of 10 critical modernizations were complete, and one remaining effort had no completion date. As of February 2026, Congress had not acted on GAO’s planning matter.

Analysis boundaries

The newsroom computed shares from GAO’s 11-system sample and cross-checked the plan table, spending context and recommendation status. GAO scored agency submissions on 16 attributes; it did not claim these were the only vulnerable federal systems.

A known vulnerability is not proof of exploitation. The accountability finding is that most of the highest-risk systems combined documented weaknesses with incomplete planning, increasing exposure to overruns, delays and prolonged insecurity.

Sources and further reading

GAO: Agencies Need to Plan for Modernizing Critical Legacy Systems ↗