When Microsoft shipped its final free security update for Windows 10 in October 2025, it ended more than a decade of routine patching for an operating system that still runs on a substantial share of the world’s desktops and laptops. Security researchers warned that the cutoff would leave an enormous installed base without the monthly fixes that quietly block newly discovered flaws. The scale of the exposure, rather than any single vulnerability, is what alarmed them most.
The size of the abandoned installed base
Estimates of how many machines were still running Windows 10 at the cutoff varied, but analyses at the time placed the figure in the hundreds of millions. One accounting warned that as many as 400 million personal computers could be left without security updates, a population large enough to represent a standing target for criminals and hostile governments alike. Many of those machines were not old or broken. They simply lacked the specific hardware that Windows 11 requires, most notably a security chip called a Trusted Platform Module, or TPM 2.0, and a compatible processor generation. Owners who tried to upgrade were often told their otherwise capable computers were ineligible, which is how a functioning laptop ends up stranded on software the manufacturer no longer defends.
What losing support actually changes
A machine running Windows 10 did not stop working on the cutoff date. It still boots, still opens a browser, still runs the same programs it did the day before. What changed is invisible from the desktop. Microsoft’s own guidance spells out that after the deadline the company no longer provides security updates, feature updates, or technical support for Windows 10. Those monthly security patches are the mechanism by which the operating system closes newly found holes before attackers can exploit them at scale. Without them, every flaw discovered from that point forward stays open indefinitely on unpatched systems. Over months and years, the list of known but unfixed weaknesses only grows, and the risk compounds rather than staying flat.
The Extended Security Updates lifeline
Recognizing that hundreds of millions of users could not or would not move immediately, Microsoft opened a consumer version of its Extended Security Updates program, a paid safety valve it had previously reserved mostly for businesses. The company confirmed that critical and important security fixes would continue to flow to enrolled Windows 10 machines for a limited period past the October 14, 2025 support deadline. For individuals, Microsoft offered enrollment routes that included syncing PC settings to a Microsoft account, redeeming loyalty points, or paying a modest one-time fee, buying roughly a year of continued protection. For organizations, the program stretches longer but grows more expensive each year it is renewed, a deliberate structure meant to push large fleets toward newer software rather than let them linger on Windows 10 forever.
Why unpatched systems draw attackers
The danger is not hypothetical, and part of the reason lies in how modern operating systems share code. Windows 10 and Windows 11 descend from a common lineage, so a flaw fixed in a Windows 11 update can point attackers straight at the same weakness sitting unpatched in Windows 10. Each month that Microsoft ships fixes for the supported system, researchers and criminals alike can study those patches, work backward to understand the underlying bug, and then hunt for it on machines that will never receive the corresponding repair. That dynamic effectively hands adversaries a roadmap. It is one reason the end of support for a widely deployed system tends to trigger a slow rise in successful intrusions rather than an immediate spike, as attackers methodically pick off the machines least likely to be defended.
The stakes beyond home users
Consumer laptops are only part of the concern. Windows 10 remained embedded across small businesses, medical offices, point-of-sale terminals, industrial controllers, and countless specialized devices whose software was never designed to be replaced on a corporate schedule. Sectors such as healthcare have historically been slow to migrate because their equipment is expensive, certified for specific software versions, and difficult to take offline. Those environments hold exactly the kind of sensitive data that makes ransomware operators pay attention, and an unpatched operating system is a common entry point. The cost of a single breach at a clinic or a municipal office can dwarf the price of new hardware many times over, which is why security professionals treat lingering Windows 10 deployments in critical settings as a priority rather than a nuisance.
The choices facing the holdouts
For the people and organizations still on Windows 10, the practical options narrow to a handful. Machines that meet the hardware bar can upgrade to Windows 11 at no cost, which remains the path Microsoft prefers. Those that fall short face a harder decision: pay for Extended Security Updates as a bridge, buy new hardware, or move to an alternative operating system such as a Linux distribution or a lightweight browser-based system that can breathe life into older devices. Each route carries trade-offs in cost, effort, and familiarity, and the environmental math is not trivial either, since forcing hundreds of millions of working computers toward replacement raises the prospect of a wave of electronic waste. What security experts agree on is that doing nothing is the one choice that guarantees the risk keeps climbing, because an operating system that is no longer patched does not hold steady. It only grows more exposed with time.
This article was produced with the assistance of AI and reviewed by the Morning Overview editorial team.
More from Morning Overview