Microsoft has extended the consumer Windows 10 Extended Security Updates (ESU) program by an additional year, allowing enrolled personal devices running Windows 10 22H2 to continue receiving critical and important security updates until October 12, 2027. The change appeared in updated Microsoft documentation rather than a formal announcement, and applies to home-user systems after Windows 10 reached end of support in October 2025.
Microsoft said users already enrolled in consumer ESU will receive the extension automatically with no further action required. Enrollment remains available through a Microsoft account settings sync, 1,000 Microsoft Rewards points, or a $30 one-time fee, while eligibility is limited to personal devices and excludes domain-joined or MDM-managed systems. The extension preserves access to monthly security fixes, including updates such as Secure Boot certificate-related patches, for users who have not yet migrated to Windows 11.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft updated its documentation to extend the consumer Windows 10 Extended Security Updates program by one additional year, moving the end date from October 2026 to October 12, 2027. Existing enrolled users were stated to remain covered automatically under the new timeline.
Microsoft ended standard support for Windows 10, after which regular users no longer received technical support, feature updates, or security updates unless covered by LTSC or ESU.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourceblogs.windows.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.