Unpatched Windows 10 Systems Expose Enterprises to Rising Cyber Threats as Vulnerabilities Multiply
Legacy endpoints host nearly triple the active security vulnerabilities of Windows 11 workstations.
Enterprise endpoints still running Windows 10 face significantly higher security risks than upgraded systems, harboring nearly triple the volume of active security vulnerabilities compared to machines on Windows 11. New cybersecurity telemetry reveals that roughly one in six corporate workstations remains on the aging operating system, leaving organizations open to heightened exploit threats past the platform’s standard support lifecycle.
Data compiled by IT asset management platform Lansweeper indicates that about 17 percent of client machines across enterprise environments continue to run Windows 10, despite Windows 11 securing roughly 78 percent of the managed device market. Independent web analytics data from StatCounter similarly showed Windows 11 maintaining more than 70 percent of desktop market share in early 2026.
The persistence of legacy software creates an expanding security gap. Lansweeper’s assessment found that an average Windows 10 endpoint contains 1,903 active Common Vulnerabilities and Exposures (CVEs), compared to 652 on average for Windows 11 devices. Crucially, 66 percent of the unpatched flaws identified on Windows 10 machines carry severity ratings of high or critical, making them lucrative targets for automated exploitation and ransomware campaigns.
Cybersecurity analysts warn that monthly patch cycles themselves create secondary exposure windows. When vendors publish security fixes for newer operating systems through regular update schedules, reverse-engineers and threat actors frequently analyze those updates to identify identical or derivative flaws that remain unpatched on unsupported legacy installations.
Software lifecycle transitions have historically created operational friction across sectors heavily reliant on certified hardware. Microsoft officially retired mainstream support for Windows 10 in October 2025, establishing an Extended Security Updates (ESU) program to provide critical patches through October 2027. While organizations in the European Economic Area were granted a complimentary interim update option through October 2026, commercial entities in other jurisdictions must purchase annual subscription licenses per device to retain patch coverage.
Sectoral breakdowns highlight where hardware dependency delays operating system upgrades. Healthcare and pharmaceutical organizations lead legacy usage with 23 percent of devices running Windows 10, followed closely by retail and consumer businesses at 22 percent, and manufacturing operations at 18 percent. These industries often rely on specialized medical equipment, point-of-sale terminals, and industrial control systems certified for specific operating environment baselines.
Company size also influences adoption rates. Small and medium-sized businesses maintain a 21.4 percent legacy operating system footprint, compared to 16.6 percent among large enterprises with dedicated IT management teams. Similar retention patterns occurred during previous migration cycles, such as the retirement of Windows XP and Windows 7, where delayed enterprise updates exposed critical infrastructure to widespread malware incidents like the 2017 WannaCry attack.
While enrollment in extended support programs offers immediate mitigation, security experts emphasize that temporary updates do not resolve underlying hardware incompatibilities. Windows 11 enforces strict hardware security baselines—including Trusted Platform Module (TPM 2.0) requirements and modern processor specifications—forcing organizations to balance software security against substantial capital expenditures for fleet hardware refreshes amid sustained enterprise hardware costs.









