Windows 10 vs Windows 11 Security: Why Millions Can't Upgrade
Windows 10 devices carry an average of 1,903 active vulnerabilities compared to 652 on Windows 11, a nearly three-to-one gap in Windows 10 vs Windows 11 security exposure, according to asset-tracking firm Lansweeper. Lansweeper says its Windows 10 average includes devices with ESU patches applied, suggesting extended security updates narrow but do not eliminate the gap. That number deserves both attention and context.
This is primarily a story about organizations, not home users. The roughly one-in-six Windows devices still running Windows 10, per Lansweeper and Statcounter data cited by PCWorld, are concentrated in healthcare, retail, and small businesses where migration is expensive, technically constrained, or blocked by vendor certification requirements.
The 1,903-versus-652 figure measures comparative vulnerability exposure, not a prediction of imminent compromise. Lansweeper's public summaries do not spell out its full methodology for counting active CVEs per device, and whether the tally covers OS-level flaws alone or extends to applications, drivers, and firmware affects how the raw numbers should be read. The gap is real. Its exact magnitude warrants measured interpretation.
What the vulnerability numbers actually show
Lansweeper's 2.9x gap rounds cleanly to "nearly three times," and Lansweeper principal technical evangelist Esben Dochy confirmed to The Register this month that the Windows 10 average already factors in devices with ESU patches applied. Extended security updates narrow the disparity; they do not erase it.
The composition of those vulnerabilities matters as much as the raw count. Of the CVEs tracked on Windows 10 systems, 66.6% are rated high or critical severity, and 2.4% are confirmed as actively exploited in the wild. Put those three numbers together: 1,903 average vulnerabilities per device, two-thirds of them high or critical, with roughly 1 in 40 already being used in live attacks. That last figure is the operationally significant one for any security team doing triage.
The gap is also self-reinforcing. Lansweeper describes a technique called "patch diffing," where attackers reverse-engineer fixes released for Windows 11 to identify equivalent unfixed flaws in Windows 10. As The Register reported Lansweeper's framing: "The supported OS effectively hands attackers a map into the unsupported one." Lansweeper argues that each Windows 11 patch cycle can reveal equivalent weaknesses in Windows 10, meaning the exposure gap widens with every update Microsoft ships.
Higher vulnerability counts mean a larger potential attack surface, not a certainty of breach. The distinction shapes how organizations should prioritize response, but it does not make the numbers academic.
One benchmarking note: Lansweeper's figure of 16.9% Windows 10 share is the most reliable primary measure here, drawn from enterprise asset inventory. Statcounter's 19.28%, based on US consumer web traffic as of June 2026, and The Register's June figure of 18.6% reflect different methodological vantage points. They corroborate rather than contradict each other.
Windows 10 vs Windows 11 security: why ESU doesn't close the gap
Microsoft ended standard Windows 10 support on October 14, 2025, cutting off security patches, feature updates, and technical support for all unenrolled devices, per Microsoft's lifecycle documentation. The Extended Security Updates program restores only critical and important security patches. No new features, no general support, no non-security fixes, per Microsoft Learn.
Consumer ESU runs through October 12, 2027; commercial and educational organizations can extend to October 10, 2028. The subscription price doubles each consecutive year, and organizations that delay enrollment pay retroactively. ESU coverage is cumulative, meaning late entrants must pay for years they skipped, according to Microsoft Learn. Only devices running Windows 10 version 22H2 are eligible to install ESU updates.
The program's practical reach is more limited than its existence implies. Only 14% of Windows 10 assets in Lansweeper's monitored base actually have ESU patches applied. Lansweeper's Laura Libeer was direct about what that means: ESU is "a temporary solution, not a destination," according to Help Net Security.
The support picture extends beyond the OS. Formal support for Microsoft 365 Apps on Windows 10 ended alongside the OS on October 14, 2025, though Microsoft is continuing to deliver security updates for Microsoft 365 on Windows 10 until October 10, 2028, per Microsoft Support. Organizations relying on everyday productivity software face a layered support timeline, not a single clean cutoff.
One important nuance for organizations running cloud infrastructure: ESU is available at no additional cost for Windows 10 virtual machines on Azure Virtual Desktop, Windows 365, Azure virtual machines, and several other Microsoft cloud platforms, per Microsoft Learn. The cost and eligibility constraints apply primarily to on-premises and domain-joined configurations.
Why the remaining Windows 10 devices are the hardest to move
Migration has stalled because the straightforward upgrades are finished. Windows 10 represented roughly half of Lansweeper's monitored device estate a year ago, fell to the low-to-mid 40% range around the October 2025 end-of-support date, and has since dropped to approximately 16-17%. But The Register reports Lansweeper now says the pace has "slowed to a crawl." Their characterization is blunt: "The easy migrations are done. What's left is the hard core: devices that haven't moved because they can't or won't."
Sector data shows where the holdouts are concentrated. Healthcare and pharmaceutical systems show 23% Windows 10 penetration; retail and consumer devices sit at 22.7%. In healthcare specifically, equipment OS versions are often tied directly to vendor certification, and in some cases a Windows 11-certified version of the device software does not yet exist. Upgrading the OS would void the certification; waiting means carrying the full vulnerability load indefinitely. Retail faces the same bind: devices are frequently locked to specific OS versions for compliance or warranty reasons, per The Register.
Hardware incompatibility creates a separate category of stuck devices. Roughly 2.8% of Windows 10 systems cannot meet Windows 11's hardware requirements, making hardware replacement the only upgrade path. That burden falls disproportionately on smaller organizations: 21.4% of Windows devices at SMBs still run Windows 10, compared to 16.6% at large organizations, with cost the primary constraint keeping legacy systems in place.
The regulatory and insurance dimensions are sharpening too. Frameworks generally require organizations to run supported software or formally document and demonstrate mitigation for unsupported systems, per Help Net Security. Cyber insurers are scrutinizing unsupported operating systems more closely, and running unpatched systems at the time of a security incident can result in higher premiums, coverage exclusions, or denied claims, per Help Net Security. These consequences are documented as risk exposure by security practitioners; specific enforcement outcomes involving named insurers are not captured in the available research.
Dochy's own framing is worth preserving here: "I think a meaningful share of the remaining Windows 10 estate isn't being actively unpatched by neglect," he told The Register. "It's being held in place by vendor dependency, certification gaps, cost, or accepted risk." That distinction matters considerably for what solutions actually look like.
What this means before 2027
The ESU expiration problem is not self-resolving. When consumer ESU lapses in October 2027, enrolled devices do not automatically migrate to anything. They roll straight into the unsupported count. "When it lapses, the devices that it is holding up do not migrate on their own," Libeer noted, via Help Net Security. For commercial organizations on the extended track, the same cliff arrives in October 2028. Libeer's conclusion is stark: two in five Windows machines are either already out of support or will be shortly, per Help Net Security.
The reporting points to three distinct buckets of Windows 10 devices, each with a different practical path. Devices that meet Windows 11 hardware requirements and carry no vendor dependency have no good reason to remain on Windows 10; ESU is a delay tactic at this point, and the subscription cost doubles annually. Devices that cannot meet Windows 11 hardware requirements face a capital expenditure decision, not a software update, and Lansweeper's data suggests that timeline is running out faster than many SMBs have planned for. Devices tied to vendor certification or compliance requirements, medical equipment, locked retail systems, need a documented mitigation plan, because that is increasingly what regulators and insurers want to see when migration is not immediately feasible.
The nearly 3x vulnerability gap between Windows 10 and Windows 11 does not mean every Windows 10 machine is actively under attack. It means the attack surface is substantially larger and expanding with every Windows 11 patch cycle. The unsupported count is set to rise again in October 2027, then again in October 2028. For organizations that haven't sorted their remaining Windows 10 estate into those three buckets, the window to do it on their own terms is narrowing.



Comments
Be the first, drop a comment!