Like, take photoshop for an example. If you're a photographer that only ever edits your own photos, the odds of a needing a security update for photoshop are really minimal.
If you regularly edit photos from clients, maybe it's worth considering.
Is it riskier than keeping an updated copy? Sure. Is the expected return period of a hack given your circumstances above a threshold that is acceptable to you? Maybe, maybe not.
That seems like "hey, we develop our software the worst way so that it's always full of bugs, but if you want less bugs, buy our subscription". Complete conflict of interest vs making quality and well-tested software in the first place.
some people still use a 90's version of wordperfect, and that's fine, but if you have software that depends on other software - example Qt3 was dropped everywhere, even though there's plenty of useful Qt3 software around, it needs to be upgraded.
So even if your system wasn't buggy, it may be incompatible or the dependencies no longer are updated (like with Qt3, which had networking and other helper functions), you wouldn't want to keep using it.
With that said it can get problematic fixing old third party packages that are no longer supported.