There’s an interesting proposal on the Make Core blog by Ian Dunn. The proposal suggests to auto-update all older or equal than 3.7 – the version that introduced auto-updates – WordPress instances to 4.7.
The reason for wanting to do this is actually best summarized by Otto in a comment:
If we simply said “we’re not backporting fixes anymore” and left it at that, then that changes nothing except now we’re intentionally leaving a huge portion of the web vulnerable to undiscovered threatsSamuel “Otto” Wood
Read the rest of the post on the Core blog and weigh in. It’s a bit of a read, but I would include the comments before asking your questions or adding your comments.