Yes. This is why relying on "patching" is a bound to fail at some point. Maybe it's a 0-day, or maybe the attackers are just quicker.
The solution to this is defence in depth, and it's very easy for most services, especially when self-hosting personal things. Few tips most people can do is.
Put up a firewall in front or put it behind VPN/tailscale.
Hide it in a subfolder. The automated attacks will go for /phpmyadmin/ , putting it in /mawer/phpmyadmin/ means 99.9% of the attackers won't find it. (This is sometimes called security by obscurity and people correctly say you should not rely on it, but as a additional layer it's very useful).
Sandbox the app, and isolate the server. If the attackers get in, make it hard or impossible for them to get anywhere else.
Keep logs, they allow you to check if and how you got attacked, if the attack succeeded and so on.
Depending on the service, pick one or more of these. Add more as necessary.
The key thing is that you should not rely on any ONE defence, be it keeping it patched or firewalled, because they will all fail at some point.