Windows 10's free support ended in October 2025, and for most people nothing visibly changed — the desktop still loaded, apps still opened, and it was easy to assume the transition was a non-event. The date that actually matters is October 14, 2026, when Microsoft's consumer Extended Security Updates program runs out, and any newly discovered vulnerability in Windows 10 stops getting fixed at all.

The historical precedent is not reassuring. When Windows 7 reached end of life in January 2020, malware specifically targeting its unpatched vulnerabilities increased 125% within six months, according to security research cited across multiple 2026 analyses. Attackers track end-of-support dates closely and often stockpile exploits ahead of the deadline rather than after it.

There's a second, harder deadline layered on top: Microsoft's original 2011 Secure Boot certificates begin expiring in June 2026, and devices that haven't received the required certificate updates risk boot failures and loss of Secure Boot protection entirely, independent of whether they're enrolled in ESU. An estimated 35% of PCs worldwide are still running Windows 10 as of this year, which is a meaningful population still exposed to both issues.

For businesses, the compliance angle compounds the security one — frameworks like PCI DSS, HIPAA, and GDPR generally require running supported, patched software, so an unpatched fleet after October 2026 isn't just a security risk, it's a potential compliance gap that affects cyber insurance coverage too. If migration to Windows 11 isn't complete by the fall, enrolling eligible machines in ESU now is meaningfully cheaper than waiting, since pricing steps up in later years.