Enterprise fleets still running Windows 10 are carrying significantly higher security risk than Windows 11 systems after Microsoft ended support for Windows 10 on 14 October 2025. Data cited from Lansweeper shows Windows 10 still accounts for 16.9% of Windows client devices, while Windows 11 has reached 78.8% adoption, yet Windows 10 endpoints average 1,903 active CVEs per device compared with 652 on Windows 11. About 66.6% of Windows 10 vulnerabilities are rated high or critical, and 2.4% are known to be actively exploited, with exploitability reported as 1.7 times higher than on Windows 11.
The exposure is concentrated in organizations and sectors where migration has lagged, particularly SMBs and industries with long-lived or specialized hardware such as healthcare and pharmaceuticals, retail, and manufacturing. Researchers said hardware incompatibility is not the main barrier to upgrading, while nearly one-fifth of monitored Windows devices still run end-of-life operating systems including Windows 7, Windows 8.1, and Windows XP. Although Microsoft offers Extended Security Updates as a temporary bridge for some Windows 10 users, coverage is limited and consumer ESU expires on 12 October 2027, leaving organizations facing growing operational, compliance, insurance, and regulatory risk if legacy systems remain in production.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Help Net Security reports that Microsoft ended support for Windows 10, leaving remaining users without regular security updates and increasing security and compliance risk for organizations that have not migrated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.