Windows 10 Security Risks: 17% of PCs Still Run End-of-Life OS

17% of Windows devices still run Windows 10 after end of support. Lansweeper data shows these systems average 1,903 active CVEs, posing significant security risks.

Windows 10 Security Risks: 17% of PCs Still Run End-of-Life OS

Microsoft ended official support for 10 in October 2025, leaving a significant portion of the market running an unpatched operating system. Security researchers warn that this transition creates a high-risk environment for businesses and individual users who have not yet upgraded. Our editorial desk tracks these shifts closely because staying on an unsupported OS exposes systems to known exploits without vendor fixes.

Windows 10 logo on a computer screen
Windows 10 reached end of support in October 2025, leaving many devices unpatched.

Legacy Windows 10 devices average nearly three times the vulnerabilities of Windows 11

Data from Lansweeper shows that approximately 17% of all Windows devices still operate on Windows 10. This legacy software lingers in small and medium businesses, where adoption stands at 21.4%, and in the healthcare and pharmaceutical sectors at 23%. Enterprise environments show lower retention at 16.6%, but the absolute number of affected machines remains substantial.

The security gap between the two operating systems is stark. Windows 10 devices average 1,903 active Common Vulnerabilities and Exposures (CVEs), compared to just 652 on Windows 11. Furthermore, 66% of the vulnerabilities found on Windows 10 are rated as High or Critical severity, whereas Windows 11 devices face a significantly lower risk profile.

Microsoft offers Extended Security Updates (ESU) for organizations that cannot migrate immediately, available until October 2027 for a fee. While this provides a temporary bridge, it does not eliminate the underlying architectural risks present in the older codebase. Users relying on ESU should monitor patch cycles closely to mitigate the higher volume of critical flaws.

We looked at the last Windows 10 update earlier while tracking Microsoft security releases, noting that patching alone cannot close the gap created by end-of-life status. Organizations must weigh the cost of ESU against the risk of maintaining a system with nearly three times the vulnerability count of its successor.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion