There are a number of vulnerabilities in all of the aforementioned software.
phpBB based sites have been hit heavily just of late, you need to keep them up to date to try and keep ahead of the hackers.
Sadly, they usually find a way if they are determined enough.
Apache is generally pretty secure, depending on the version, IIS needs to be kept bang up to date for patches else you *will* be hit sooner or later.