XOOMAR
Aging office PCs under cyber threat with strained digital shields and security cost imagery.
CybersecurityJuly 18, 2026· 8 min read· By XOOMAR Insights Team

Windows 10 Security Updates Now Trap One in Six PCs

Share
Updated on July 20, 2026

Microsoft expected Windows 10 to age out. Instead, the remaining machines are turning into a hard security bill that neither Microsoft nor many customers can cleanly pay down.

XOOMAR Intelligence

Analyst Take

71/ 100
High
4 sources analyzedMedium confidenceTrend10Freshness98Source Trust85Factual Grounding88Signal Cluster20

That is the real signal in new Lansweeper data cited by The Register Security: Windows 10 security updates are no longer just a consumer annoyance or an IT housekeeping item. They are becoming a long-tail exposure problem, especially for organizations that can’t move because of cost, certified hardware, vendor dependencies, or accepted risk.

Windows 10 has become the operating system Microsoft can't retire cleanly

The clean version of the Windows 10 story was simple: Microsoft ends standard support, users move to Windows 11, and the installed base keeps shrinking.

The actual version is messier. Lansweeper says Windows 10 still runs on 16.9 percent of the Windows devices it monitors, or "roughly one in six." That is down sharply from a year ago, when Windows 10 represented about half of the machines in Lansweeper’s dataset. It fell into the low-to-mid 40 percent range by the time Microsoft ended standard support, then dropped to 18.6 percent in June.

Now the easy part appears to be over.

"The easy migrations are done. What's left is the hard core: devices that haven't moved because they can't or won't."

That sentence matters because it reframes the issue. The remaining Windows 10 estate is not just laziness. In many cases, it is trapped infrastructure. Microsoft can offer Extended Security Updates, or ESU, but ESU buys time. It does not solve certification, hardware, or replacement economics.

The contradiction is sharp: Windows 10 is still useful enough to keep, but old enough to become a progressively weaker security bet.


The numbers behind Windows 10's stubborn market share and the looming patch deadline

The headline number is 16.9 percent, but the more important detail is the stall. Lansweeper’s data shows the migration curve slowing after the post-support drop. That means the remaining Windows 10 population may be harder to move than the percentage suggests.

The Windows 10 security updates timeline now looks like this:

  • Consumer devices: Security updates can continue until October 12, 2027.
  • Commercial customers: Paid coverage can run until October 10, 2028.
  • After that: Microsoft Patch Tuesday fixes stop, based on the current deadlines cited in the source material.

Microsoft describes ESU this way:

"the ESU program helps reduce the risk of malware and cybersecurity attacks by providing access to critical and important security updates."

That is true as far as it goes. But Lansweeper says only 14 percent of Windows 10 assets have ESU patches applied. Even among enrolled machines, the risk does not disappear. Esben Dochy, principal technical evangelist at Lansweeper, told The Register that "the Windows 10 average also includes devices that have ESU patches applied."

The vulnerability gap is already large. Lansweeper says:

OS Average active CVEs per device
Windows 10 1,903
Windows 11 652

That is a 2.9x gap.

The attack surface does not require Windows 10 to dominate the market. It only requires enough unpatched or poorly isolated machines to make targeting worthwhile. A one-in-six footprint is not a legacy footnote. It is still a mainstream endpoint population.

TPM 2.0, old CPUs, and the hardware wall blocking millions of Windows 11 upgrades

Part of the stall comes from the Windows 11 hardware gate. The related source material cites requirements around TPM 2.0, Secure Boot, newer CPUs, and modern RAM and chipsets. That matters because many Windows 10 PCs still feel perfectly usable for browsing, Office work, retail terminals, healthcare workflows, or industrial software.

For households, schools, small businesses, and cash-constrained firms, replacing working machines can feel irrational. For regulated or vendor-managed devices, it may not even be a customer decision.

Dochy’s explanation is the clearest part of the story:

"I think a meaningful share of the remaining Windows 10 estate isn't being actively unpatched by neglect," Dochy said. "It's being held in place by vendor dependency, certification gaps, cost, or accepted risk."

He gave two specific examples: medical devices and industrial systems where the OS is tied to vendor certification, and retail devices locked to specific OS versions for compliance or warranty reasons.

That is the trap. Microsoft can tighten the baseline for newer Windows machines, but stricter hardware rules can strand older ones faster. Unsupported installs and bypasses may keep some PCs alive, but they complicate support, compliance, and patch reliability. For separate XOOMAR coverage of PC upgrade friction and user trust issues, see Windows 11 8GB RAM Flops on Microsoft’s Own Laptop and LG Gaming Monitors Trigger Revolt Over PC Adware Scare.

From Windows XP to Windows 7, Microsoft has seen this retirement drama before

Microsoft has dealt with slow Windows retirements before. The supplied data does not provide comparable Windows XP or Windows 7 migration figures, so the useful comparison here is structural rather than statistical.

The pattern is familiar: organizations delay until the cost of staying exceeds the cost of moving. That cost can come from support contracts, customer questionnaires, internal audits, application testing, or security incidents. Lansweeper’s Windows 10 data suggests this cycle has reached the hard phase.

The difference now is the visibility of the vulnerability gap. A Windows 10 device averaging 1,903 active CVEs against 652 on Windows 11 gives IT teams a concrete way to rank the debt. It also gives attackers a clearer target list when old systems remain exposed.

Lansweeper also flags patch diffing, where attackers compare Windows 11 fixes to infer flaws that may still exist in Windows 10.

"The supported OS effectively hands attackers a map into the unsupported one," Lansweeper said.

That is the mechanism that turns an end-of-life calendar into a security event. Each Windows 11 fix can become a clue for where to look on machines that are slower to patch or no longer patchable.


Microsoft, IT departments, consumers, and attackers all see the Windows 10 deadline differently

Microsoft’s interest is straightforward. It wants users on Windows 11 and on newer hardware with stronger security assumptions. ESU softens the transition, but it also makes clear that Windows 10 is living on borrowed time.

Enterprise IT sees a different problem. Migration is not just clicking upgrade. It means procurement, app testing, device management, employee disruption, vendor timelines, and risk signoff. In some sectors, the source data shows heavier exposure:

Sector or group Windows 10 share cited by Lansweeper
SMBs 21.4 percent
Healthcare and pharmaceutical systems 23 percent
Consumer and retail devices 22.7 percent

Small and medium-sized businesses look especially exposed because cost is usually the constraint keeping Windows 10 alive, according to Lansweeper.

Consumers may see no cliff at all. The machine still boots. The browser opens. Email works. Banking works. That is exactly why Windows 10 security updates are a slow-burn issue rather than an obvious failure.

Attackers read the same situation differently. Old OS, uneven ESU adoption, vendor-locked systems, and isolated machines with accepted risk all create predictable pockets of weakness.

Windows 10 holdouts face higher security costs, compliance pressure, and forced PC replacement

The end of standard support shifts cost away from Microsoft and toward the owner of the device.

That cost can take several forms:

  • Paid coverage: ESU for organizations that need more time.
  • New hardware: Replacement where Windows 11 requirements block upgrade.
  • Managed controls: Stronger monitoring, segmentation, and endpoint protection.
  • Operational risk: More exposure where devices stay unpatched or only partly protected.

Dochy also warned that ESU may not fix the deeper issue when vendors control the device.

"For a lot of this hardware, the vendor is contractually responsible for maintaining the device, including any OS changes, so simply enrolling in ESU as a customer may not resolve the underlying problem."

That line should worry buyers of certified or vendor-locked systems. If the vendor has not certified a Windows 11 path, the customer may be stuck paying for mitigation while waiting for someone else’s roadmap.

XOOMAR analysis: the most exposed organizations are not necessarily the least sophisticated. They may be the ones with the most specialized equipment, where a generic Windows migration plan breaks against certification, warranty, or operational constraints.

Windows 10 won't vanish in 2025, and that creates the next PC security fault line

Windows 10 usage will keep declining, but the source data does not support the idea of a clean collapse. Lansweeper’s stall points to a long tail.

The practical test now is not whether Microsoft can persuade ordinary users to prefer Windows 11. It is whether the remaining Windows 10 machines can be identified, patched where possible, isolated where necessary, and replaced when there is no safe path left.

Evidence that would strengthen the risk thesis: ESU adoption remains low, Windows 10’s CVE gap widens, and sector exposure in healthcare, pharmaceuticals, retail, and SMBs stays elevated.

Evidence that would weaken it: faster Windows 11 certification by vendors, a visible rise in ESU coverage, and continued decline from 16.9 percent without another plateau.

Operating system deadlines do not secure devices by themselves. The Windows 10 security updates clock is now testing whether hardware policy, customer economics, and real security urgency can finally line up.

Impact Analysis

  • The remaining Windows 10 machines are likely the hardest and most expensive to replace.
  • Extended Security Updates reduce short-term risk but do not solve hardware or certification blockers.
  • Organizations that delay migration may face rising security exposure as Windows 10 ages out.

Windows 10 Migration Reality

AreaWindows 10Windows 11 / Migration Path
Current statusStill runs on 16.9% of Lansweeper-monitored Windows devicesAbsorbed the easier migrations already
Main issueRemaining devices may be blocked by cost, hardware, certifications, or vendor dependenciesRequires replacement, validation, or operational change
Security outlookExtended Security Updates can buy time but do not fix underlying constraintsPreferred long-term path for supported security coverage

Windows 10 Share of Lansweeper-Monitored Windows Devices

June
%18.6
Now
%16.9
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Text 'Cyber Attack' on textured dark paper highlights digital security threat concept.Cybersecurity

Hackers Mass-Exploit Patched SharePoint Flaw After Public PoC

Attackers are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) using public proof-of-concept code, targeting organizations tha

Aug 13, 20265 min
Person holding tablet with VPN connection screen for secure internet browsing.Cybersecurity

Windows and macOS Users Face Hidden Security Gaps in 2026

While operating system security has improved, blind spots persist. Specific threat vectors still exploit them.

Aug 13, 202615 min
Cybersecurity control hub shielding small businesses from AI and security risksCybersecurity

$110M Inforcer Series C Run Crowns the MSP Security Bet

Inforcer’s $50M Series C lifts its 18-month haul to $110M, backing MSPs as the control layer for SMB AI and security risk.

Jul 30, 20267 min
AI chip protected by a glowing cybersecurity alliance network, with closed labs in the distance.Cybersecurity

Nvidia AI Security Alliance Leaves OpenAI Off Roster

Nvidia's 37-member AI security push puts open tools against closed labs, with OpenAI, Anthropic and Google missing from the launch.

Jul 27, 20267 min
Cyber security concept shown on grunge-style background highlights the importance of digital protection.Cybersecurity

XDR Clash: CrowdStrike, Microsoft, Palo Alto Vie for Market

A true XDR platform cuts breach detection times from 29 days to under 10, and only three vendors currently deliver the unified telemetry and automation required

Aug 13, 202613 min
Colorful lines of code on a computer screen showcasing programming and technology focus.Technology

QueryStory Raises $6M to Fix AI's Broken Truth Problem

QueryStory raised $6 million to build an AI reporting tool that proves where its conclusions come from, aiming to solve enterprise trust issues with data audits

Aug 30, 20269 min
Photorealistic, cinematic scene of a damaged military barracks under a dramatic sky, suggesting a geopolitical incident.Global Trends

Pyrotechnic Depot Blast Hits Bolivian Barracks

An explosion at a Bolivian military barracks storing fireworks killed at least two people, with officials warning the death toll could reach 15 and that the sit

Sep 5, 20264 min
Conceptual global map with light and shadow, symbolizing complex international legal proceedings.Global Trends

Deadlocked Jurors Force Mistrial In Clancy Child Killings

A judge declared a mistrial after jurors deadlocked, unable to decide whether Lindsay Clancy is criminally responsible for killing her three young children.

Sep 4, 20268 min
A cinematic golden hour view of a modern trading floor with glowing Bitcoin and data visualizations.Trading

BITB Adds 303.88 BTC on Friday

Bitwise's Bitcoin ETF recorded a $24.2 million inflow on Friday, as the market awaits critical flow data from BlackRock's iShares funds, highlighting ongoing vo

Sep 4, 20265 min
Modern trading floor with Bitcoin futures analytics and financial data screens showing market activity shifts.Trading

Leveraged Funds Trim Bitcoin Shorts by 469 Contracts

Leveraged funds reduced their net short position in Bitcoin futures last week, while total market open interest fell, signaling a cautious, retreating stance am

Sep 4, 20266 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.