Windows 10’s Stubborn Grip: Millions Run Unpatched Systems Years After Support Deadline

Windows 10 powers 28% of desktops and 17% of enterprise devices despite ended support. Unpatched systems carry triple the vulnerabilities of Windows 11. Recent extensions and massive July patches highlight ongoing exposure for millions of machines.
Windows 10’s Stubborn Grip: Millions Run Unpatched Systems Years After Support Deadline
Written by Dave Ritchie

Windows 10 refuses to fade away. Nearly a year after Microsoft pulled the plug on free security updates, the operating system powers more than one in four Windows desktops worldwide. And a sizable chunk of those machines sit exposed. Short. Simple fact.

Lansweeper’s latest survey reveals the scale. The asset-tracking firm found Windows 10 on 16.9 percent of monitored devices as of mid-2026. That’s down from nearly 50 percent a year earlier. Yet the decline has slowed to a crawl. In small and midsize businesses the figure hits 21.4 percent. Healthcare and pharmaceutical organizations sit at 23 percent. Consumer and retail environments reach 22.7 percent. (Slashdot).

Statcounter data paints a broader picture. For June 2026 Windows 11 held 69.92 percent of the global desktop market. Windows 10 still commanded 28.1 percent. The drop from prior months looks gradual. Not the mass migration Microsoft hoped to see. And many of those Windows 10 boxes run without the paid Extended Security Updates that keep some enterprises afloat. But even ESU won’t last forever. Microsoft quietly stretched the program for home users through October 2027 after users balked at Windows 11’s hardware demands. (Windows Latest).

Esben Dochy serves as principal technical evangelist at Lansweeper. He pointed out that the Windows 10 average includes devices with ESU patches applied. Only about 14 percent have them. The rest carry an average of 1,903 active common vulnerabilities and exposures. Compare that to 652 on Windows 11. Nearly three times the risk. “The supported OS effectively hands attackers a map into the unsupported one,” Dochy noted. Patch diffing lets researchers study Windows 11 fixes and then craft exploits that strike older builds. Fast.

July 2026 brought the problem into sharp focus. Microsoft shipped fixes for a record 570 flaws. Nearly 60 earned critical ratings. Three zero-days were addressed. Two already saw active exploitation. The volume reflects AI-assisted vulnerability discovery according to company officials. Yet systems that no longer receive those patches face permanent gaps. (Krebs on Security).

Organizations that stay on Windows 10 after the October 2025 cutoff accept known dangers. New flaws surface monthly. They stay open without updates. Ransomware groups target these holdouts because they know fixes won’t arrive. Lateral movement becomes easier once one machine falls. Compliance teams notice too. Insurance carriers grow reluctant to cover environments built on unsupported software. But hardware constraints block upgrades for many. Older medical scanners. Industrial controllers. Retail point-of-sale terminals. None qualified for Windows 11 certification. So they linger.

And the numbers haven’t shifted much lately. Statcounter shows Windows 10 share leveling off around 28 percent after an initial post-support dip. Users cite familiarity. Lower resource needs. Windows 11’s higher memory footprint turns off some. Microsoft responded with the ESU extension. Home users can enroll for free if signed in with a Microsoft account. Or pay a modest fee. The company promised monthly security updates continue. Still the fundamental bargain changed. After 2027 even paid patches disappear. Devices grow more vulnerable the longer enrollment waits. (Windows Latest again).

Security firms warn of the widening attack surface. Unpatched Windows 10 machines serve as beachheads. One recent analysis highlighted a use-after-free bug in older TCP/IP stacks that could let remote attackers run code. Such issues won’t get fixed for non-ESU systems. Enterprises that once relied on free patches now weigh costs. Some buy the extensions. Others accelerate hardware refresh cycles. A few accept the risk and isolate legacy devices behind strict network controls. None of those choices feel perfect.

But the data keeps coming. Lansweeper’s report shows the holdouts cluster in specific sectors. Those with specialized applications. Tight budgets. Or simple inertia. The CVE count gap tells its own story. Nearly 1,900 known issues against roughly 650. Attackers don’t need novel zero-days when so many older ones remain open. Patch diffing accelerates the process. Researchers dissect a Windows 11 update. They identify the exact code change. Then they write working exploits for Windows 10 variants. The cycle repeats each month.

Microsoft delivered on its ESU promise so far. Every month since October 2025 brought security content for enrolled machines. The extension to 2027 buys time. It also signals that user resistance ran higher than expected. Windows 11 adoption climbed. Yet not fast enough to clear the old base. So the company adjusted. Home users gained another year. Commercial customers already had multi-year options. The message stays consistent. Upgrade when you can. The unsupported road leads to higher risk.

Experts recommend inventory first. Identify every Windows 10 asset. Check ESU status. Map dependencies that block migration. Then weigh the options. Pay for continued patches. Replace hardware. Or virtualize and isolate. Each path carries trade-offs. None remove the underlying exposure completely until the last machine moves off the platform. And that day still looks distant. 28 percent in June. 16.9 percent in enterprise samples. The stubborn grip persists. Short term. Long term consequences mount.

Recent discussions on X echo the same concerns. IT teams in healthcare and retail report they can’t swap systems without recertifying equipment that costs hundreds of thousands. SMB owners cite budget limits. Meanwhile threat actors scan for exposed legacy endpoints. The July patch wave reminded everyone how many bugs lurk in modern code. Multiply that by the CVE disparity and the picture sharpens. Unpatched Windows 10 doesn’t just endanger the owner. It threatens every connected network.

So the situation stands. Windows 10 runs on tens of millions of devices. Many lack current protections. Microsoft extended the safety net once more. Yet the clock ticks. Attackers study the maps handed to them. Organizations that delay action invite trouble. The numbers don’t lie. The risk gap widens. Time to face the data.

Subscribe for Updates

ITManagementNews Newsletter

IT management news, trends and updates.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us