Several reasons
- If a private key leaks, a shorter certificate lifespan limits the fallout
- Faster upgrades to new cryptographic standards. If some of the crypto methods used get broken, short lived certificates means they get replaced with newer methods faster
- Short lived certificates force sysadmins to automate the renewal process. This prevents expired certificates due to forgetting the manual renewal.
- Certificate lifetime and domain ownership mismatch. You could buy a 2 year certificate for somedomain.com and then sell the domain or just let it expire and have it picked up by someone else. You then have a valid certificate for a domain you no longer ow and you could MitM traffic for the new owner’s website.