Old patches showing up

Old patches showing up

I am currently evaluating DC for my organization. One question is about the patch management. Many of my systems are showing up as Highly Vulnerable (some with as many as 60 needed patches!). I was trying to find out what was happening because SCCM says nothing about those patches and when I manually run Windows update off domain, it does not find those patches. These are patches from as far back as 2011 and 2012. I wonder if these have been superseded. I'm just wondering how I can known which is correct? WSUS or DC?

                New to ADSelfService Plus?