Windows 10, one year on: the security fixes a non-ESU PC did not receive
Microsoft fixed every one of them. The question this study answers is which machines received the fix, how many of the flaws were already being exploited when it shipped, and what a UK household actually has to do differently from an EEA one.
Updated 20 September 2026 · CVE Program v5 bulk release and the CISA KEV catalogue, frozen at 2026-09-20 · method and dataset below
What this counts, and what it does not say
- The word 'unpatched' is not used. Microsoft shipped a fix for every CVE counted here. The only accurate framing is 'fixes a non-ESU machine did not receive'.
- No ransomware framing. None of the exploited flaws carries CISA's 'Known' ransomware-campaign flag.
- No superlatives and no 'first ever' claim. See the novelty note.
- The population is Windows 10 Home and Pro 22H2 without ESU. Nothing here describes 21H2 or the LTSC editions.
- As at 20 September 2026. CVE records are revised continuously, so counts for past months rise over time. Everything here is computed from a frozen, hashed snapshot of the CVE Program's bulk release of 20 September 2026 and the CISA KEV catalogue v2026.09.18. Re-running the same filter on a later release will give a larger number, which is a property of the source, not a correction to this one.
The pre-registered floor of 1,204 does not survive. 8 of the 11 months match it within one CVE; November 2025 and December 2025 are two out; and September 2026 is 285 out, where the brief expected 283 and the CVE records give 568. The brief's own alternative estimate, about 1,500 from Microsoft's affected lists, is what the data supports. The published figure is 1,486. Every month is set out against the brief below. This is recorded rather than quietly corrected, because the brief was written before the data was pulled and the filter is published so anyone can recount.
| Month | Pre-registered in the brief | This analysis | Difference |
|---|---|---|---|
| 2025-11 | 34 | 32 | -2 |
| 2025-12 | 31 | 29 | -2 |
| 2026-01 | 70 | 70 | 0 |
| 2026-02 | 24 | 24 | 0 |
| 2026-03 | 42 | 43 | +1 |
| 2026-04 | 104 | 105 | +1 |
| 2026-05 | 53 | 53 | 0 |
| 2026-06 | 91 | 91 | 0 |
| 2026-07 | 313 | 313 | 0 |
| 2026-08 | 159 | 158 | -1 |
| 2026-09 | 283 | 568 | +285 |
Scroll the table sideways to see every column →
What was measured
Support for Windows 10 Home and Pro ended on 14 October 2025. From 15 October 2025 the monthly Windows security update for version 22H2 went only to machines enrolled in Extended Security Updates. This study counts the fixes in those updates.
The unit is one CVE. The population is every CVE published by the Microsoft CNA between 2025-10-15 and 2026-09-20 whose CVE Program v5 'affected' array names "Windows 10 Version 22H2" as a vulnerable component, minus those the last free update of 14 October 2025 had already fixed.
Microsoft shipped a fix for every one of them. The question is only which machines received it. Nothing here says Windows 10 was left without a patch.
| Figure | Count | Out of | Share |
|---|---|---|---|
| fixes a non-ESU 22H2 PC did not receive | 1,486 | 3,101 (Microsoft-CNA CVE records published in the window) | 47.9% |
| CVEs that named 22H2 but were already fixed by the free 14 October 2025 update | 4 | 1,490 (CVEs naming Windows 10 Version 22H2 as a vulnerable component) | — |
Scroll the table sideways to see every column →
Inclusion test, published so the count can be re-run: cveMetadata.assignerShortName == 'microsoft' AND cveMetadata.state == 'PUBLISHED' AND containers.cna.datePublic >= 2025-10-15 AND containers.cna.affected[] contains an entry with product == 'Windows 10 Version 22H2' (exact string, case-insensitive) carrying a versions[] item with status 'affected'. Every percentage states its denominator. No percentage is published on a count below 10; those cuts say so. Percentages are rounded to one decimal place and may not sum to 100.
The count, month by month
1486 fixes across 11 months. The monthly bars are the observations; the curve above them is only their running total. Both are published because the running total is what a machine accumulates and the bars are what the series actually looks like.
Monthly counts run from 24 (February 2026) to 568 (September 2026), with a median of 70. That is a factor of 23.7 between the smallest and largest month, so this study publishes the median and the range and makes no claim about a monthly rate.
The large months are broad across components, not one component arriving in a batch. September 2026 alone is 568 of the 1486, spread over 184 distinct components: its largest single block is Windows Biometric Service at 64, 11.3 per cent of the month, and its five largest components together are 140. July 2026 is the same shape - Windows Kernel is the largest at 25 of 313. No component accounts for more than a fifth of any month in the series. Why September 2026 is as large as it is cannot be answered from the CVE records, and no explanation is offered here.
These are distinct CVE identifiers, checked for duplicates, not one flaw counted many times.
Scroll the chart sideways to see all of it →
Source: CVE Program v5 bulk release cve_2026-09-20_0300Z, published 2026-09-20T03:28:48Z, Microsoft CNA affected array. Each point is the cumulative count of distinct CVEs naming Windows 10 Version 22H2 as a vulnerable component. As at 2026-09-20.
Scroll the chart sideways to see all of it →
Monthly values run from 24 to 568, a factor of 23.7. A single 'growing by N a month' figure would misdescribe the series, so the median and the full range are published instead and no rate is claimed. The window is about eleven and a quarter months, but October 2025 contributes nothing - its Patch Tuesday fell on the 14th, the last day of free support - so the median, mean and range are computed over the eleven months that carry a Patch Tuesday inside the window. September 2026 is drawn lighter: it is a part month, covering the 8 September Patch Tuesday only.
| Month | Fixes missed | Share of the total | Running total | Microsoft’s own figure | Difference |
|---|---|---|---|---|---|
| November 2025 | 32 | 2.2% | 32 | 36 | +4 |
| December 2025 | 29 | 2.0% | 61 | 31 | +2 |
| January 2026 | 70 | 4.7% | 131 | 72 | +2 |
| February 2026 | 24 | 1.6% | 155 | 24 | 0 |
| March 2026 | 43 | 2.9% | 198 | 43 | 0 |
| April 2026 | 105 | 7.1% | 303 | 106 | +1 |
| May 2026 | 53 | 3.6% | 356 | 54 | +1 |
| June 2026 | 91 | 6.1% | 447 | 93 | +2 |
| July 2026 | 313 | 21.1% | 760 | 313 | 0 |
| August 2026 | 158 | 10.6% | 918 | 160 | +2 |
| September 2026 | 568 | 38.2% | 1,486 | 568 | 0 |
Scroll the table sideways to see every column →
“Microsoft’s own figure” is the count of CVEs Microsoft’s Security Update Guide lists as affecting Windows 10 Version 22H2 in that month. Cited from Microsoft's Security Update Guide, not reproduced: aggregate counts only. No per-CVE row from that source appears in the published dataset or here. Across the eleven months it totals 1,500 against this study’s 1,486. All 14 of them are individually accounted for and none is a filter error. 10 are not Microsoft-CNA records at all: their CVE records are assigned by CERT/CC (3), MITRE (3), GitHub (2), AMD (1) and Arm (1), and Microsoft relays them because a Microsoft update carries the fix. The other four were already fixed by the free 14 October 2025 update. The CVE Program set is a strict subset of Microsoft's: nothing is in this study's population and absent from Microsoft's list. All fourteen are named below, in the dataset README and in this study's JSON.
Breaks in the series, stated rather than smoothed
- The series opens in November 2025, not October 2025. The window opens on 15 October 2025 but Microsoft published no CVE naming Windows 10 22H2 between then and the November Patch Tuesday, so there is no October point. Microsoft's own October 2025 document lists 97 CVEs affecting 22H2, every one of them first published before 15 October and therefore fixed by the free update.
- July 2026 has two publication dates: the Patch Tuesday of 14 July 2026 and an out-of-band record dated 16 July 2026.
- September 2026 is a part month. It covers the 8 September Patch Tuesday but the month was not over at the snapshot date, and October 2026's Patch Tuesday is not in the series.
- One CVE published on 14 April 2026 was first fixed at the July 2026 build, so April shows two first-fixed builds. It is still counted as missed, because no non-ESU machine received that build either.
What kind of flaws
By Microsoft's own CVSS v3.1 scoring inside the CVE records, 38 of the 1486 are Critical and 1102 are High.
By vulnerability class, elevation of privilege dominates: these are mostly flaws that let code already running on the machine gain more control, rather than flaws an attacker reaches across the internet unaided.
The largest component family is Networking and protocols, 286 of 1486 (19.2 per cent).
Scroll the chart sideways to see all of it →
Families are assigned by an ordered rule list published in stage2_filter.py so the classification can be disputed and re-run. Microsoft spells some components several ways across months - 'Windows Win32k' and 'Win32k', 'Windows GDI+' and 'GDI+' - and the family column merges them while the component column does not. Some assignments are arguable: Windows Network File System is filed under file systems rather than networking, and Windows Biometric Service under authentication and identity.
Families with fewer than ten fixes are left off the chart and listed here with counts but no share, in line with the study’s rule against percentages on small counts: Office file handling in Windows (3); Third-party silicon mitigations (2); Other Windows component (1).
By vulnerability class
| Class | Fixes | Share |
|---|---|---|
| Elevation of Privilege | 888 | 59.8% |
| Remote Code Execution | 235 | 15.8% |
| Information Disclosure | 225 | 15.1% |
| Denial of Service | 61 | 4.1% |
| Security Feature Bypass | 47 | 3.2% |
| Tampering | 17 | 1.1% |
| Spoofing | 13 | 0.9% |
Scroll the table sideways to see every column →
Parsed from Microsoft's own CVE titles. Every record in the population parsed to a type.
By CVSS v3.1 severity
| Severity | Fixes | Share |
|---|---|---|
| Critical | 38 | 2.6% |
| High | 1,102 | 74.2% |
| Medium | 343 | 23.1% |
| Low | 3 | — |
Scroll the table sideways to see every column →
CVSS v3.1 as scored by the Microsoft CNA inside each CVE record. This is not NVD's score and it is not Microsoft's own Critical/Important rating, which is a separate scale reported in the ESU section. 1,140 of the 1,486 are Critical or High on that scale.
The ten components with the most missed fixes
| Component, as Microsoft names it | Fixes | Share |
|---|---|---|
| Windows Biometric Service | 65 | 4.4% |
| Windows NTFS | 60 | 4.0% |
| Windows Kernel | 54 | 3.6% |
| Windows Ancillary Function Driver for WinSock | 40 | 2.7% |
| Windows Win32k | 33 | 2.2% |
| Windows Routing and Remote Access Service (RRAS) | 23 | 1.5% |
| Windows TCP/IP | 21 | 1.4% |
| Win32k | 20 | 1.3% |
| Windows Hyper-V | 20 | 1.3% |
| Remote Desktop Client | 19 | 1.3% |
Scroll the table sideways to see every column →
The raw component string is kept in the dataset alongside the merged family, because Microsoft spells some of these several ways across months.
Flaws already being exploited
12 of the 1486 fixes are for flaws CISA has since listed in its Known Exploited Vulnerabilities catalogue.
For 9 of those 12, CISA listed the flaw as actively exploited on the same calendar day the fix shipped. CISA adds an entry only on evidence of active exploitation, so same-day listing means exploitation was already known when the update went out. It does not establish that any particular machine was attacked, and the arithmetic is date-only - it cannot resolve hours.
None of these carries CISA's 'Known' ransomware-campaign flag. All are flagged 'Unknown', which means not established rather than not used.
Scroll the chart sideways to see all of it →
Source: CISA Known Exploited Vulnerabilities catalog, catalogVersion 2026.09.18, released 2026-09-18T19:00:05Z, 1,716 entries (CC0 1.0), joined on CVE identifier. Exact match on CVE identifier between the published dataset and the cveID field of the CISA KEV catalogue. Lag is KEV dateAdded minus CVE datePublic in whole days; it is date-only arithmetic and cannot resolve hours. The join was cross-checked against the CISA-ADP SSVC Exploitation field carried inside the CVE records, and against a hand check of every entry against the raw catalogue.
| CVE | What it is | Component | Class | Fix published | CISA listed it | Days | CVSS |
|---|---|---|---|---|---|---|---|
| CVE-2025-62221 | Microsoft Windows Use After Free Vulnerability | Windows Cloud Files Mini Filter Driver | Elevation of Privilege | 9 Dec 2025 | 9 Dec 2025 | 0 | 7.8 high |
| CVE-2026-20805 | Microsoft Windows Information Disclosure Vulnerability | Desktop Window Manager | Information Disclosure | 13 Jan 2026 | 13 Jan 2026 | 0 | 5.5 medium |
| CVE-2026-21510 | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | Windows Shell | Security Feature Bypass | 10 Feb 2026 | 10 Feb 2026 | 0 | 8.8 high |
| CVE-2026-21513 | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | MSHTML Framework | Security Feature Bypass | 10 Feb 2026 | 10 Feb 2026 | 0 | 8.8 high |
| CVE-2026-21519 | Microsoft Windows Type Confusion Vulnerability | Desktop Window Manager | Elevation of Privilege | 10 Feb 2026 | 10 Feb 2026 | 0 | 7.8 high |
| CVE-2026-21525 | Microsoft Windows NULL Pointer Dereference Vulnerability | Windows Remote Access Connection Manager | Denial of Service | 10 Feb 2026 | 10 Feb 2026 | 0 | 6.2 medium |
| CVE-2026-21533 | Microsoft Windows Improper Privilege Management Vulnerability | Windows Remote Desktop Services | Elevation of Privilege | 10 Feb 2026 | 10 Feb 2026 | 0 | 7.8 high |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Windows Ancillary Function Driver for WinSock | Elevation of Privilege | 11 Aug 2026 | 11 Aug 2026 | 0 | 7 high |
| CVE-2026-85880 | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Windows Advanced Local Procedure Call (ALPC) | Elevation of Privilege | 8 Sept 2026 | 8 Sept 2026 | 0 | 7.8 high |
| CVE-2025-62215 | Microsoft Windows Race Condition Vulnerability | Windows Kernel | Elevation of Privilege | 11 Nov 2025 | 12 Nov 2025 | 1 | 7 high |
| CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability | Windows Shell | Spoofing | 14 Apr 2026 | 28 Apr 2026 | 14 | 4.3 medium |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | Windows Internet Key Exchange (IKE) Service Extensions | Remote Code Execution | 14 Apr 2026 | 18 Aug 2026 | 126 | 9.8 critical |
Scroll the table sideways to see every column →
Two independent routes give the same set: the CISA-ADP SSVC Exploitation field carried inside the CVE records, and a direct join to the KEV catalogue. They are different signals by definition and agreeing here is a result, not a guarantee. Both routes return the same 12 identifiers. Microsoft’s own “exploited” flag, cited from the Security Update Guide, marks 11 of them; the two overlap on 11.
- KEV is a floor, not a census. Absence from KEV is not evidence that a flaw was not exploited.
- KEV listings are retroactive. One entry here, CVE-2026-33824, was added 126 days after publication, so the figure for recent months will rise after this snapshot.
- Each KEV entry carries a dueDate. That is a United States federal compliance deadline under CISA Binding Operational Directive 22-01. It has no force for a UK household and is not presented here as one.
Does paying for ESU deliver all of them?
On the evidence available, yes - with one documented boundary that cannot be tested from public data. Every one of the 1500 CVEs in Microsoft's own Windows 10 22H2 list for these months carries a shipped 22H2 vendor-fix KB in Microsoft's Security Update Guide, with no exceptions in any of the eleven months. There is no set of fixes that simply never shipped.
That boundary is the stated severity scope. Microsoft states that ESU delivers Critical- and Important-rated security updates only, and the Microsoft Security Response Center rates on four levels. In this window Microsoft rates 2 of the 1500 as Moderate, outside that stated scope - too few to express as a share. Those two fixes ship in the same monthly cumulative update as the rest, so whether ESU withholds them is not observable from anything Microsoft publishes. No claim is made here that an ESU subscriber misses anything.
| Microsoft’s own severity rating | CVEs | Share | Inside ESU’s stated scope? |
|---|---|---|---|
| Important | 1,399 | 93.3% | Yes |
| Critical | 99 | 6.6% | Yes |
| Moderate | 2 | — | No |
Scroll the table sideways to see every column →
Microsoft's own Critical/Important/Moderate/Low rating, from the Security Update Guide. Cited, not reproduced: this source carries no open licence and its rows are not in the published dataset. Denominator is Microsoft's own total, which is larger than this study's CVE Program population. This is why the word 'unpatched' does not appear in this study. Microsoft fixed all of them. The finding is about delivery, not about whether a fix exists.
“ESU includes critical and important security updates only. It does not include new features, customer-requested non-security updates, or design change requests. ESU does not include technical support for Windows 10, except for assistance with ESU license activation and installation of ESU updates. No other technical support is available.”
“The ESU program helps reduce the risk of malware and cybersecurity attacks by providing access to critical and important security updates as defined by the Microsoft Security Response Center (MSRC) for devices running Windows 10, version 22H2. ESU enrollment does not provide other types of fixes, feature improvements, or product enhancements. It also does not come with technical support.”
An angle this study tested and dropped
“Even ESU subscribers miss some of these fixes” — not supported. All 1500 CVEs in Microsoft's own list carry a shipped 22H2 fix. The only bounded thing is the stated severity scope, and the two Moderate-rated fixes in this window ship in the same cumulative update, so no measurable gap was found. Reported as a negative finding rather than replaced with something weaker.
The UK and the EEA: what actually differs
The study set out to test whether a UK household pays for updates an EEA household gets free. As published by Microsoft on 20 September 2026, that is not what the difference is. Both regions have a route into consumer ESU that costs no money. What differs is the condition attached to it.
In the United Kingdom there are three routes: no additional cost if you sync your PC settings to Microsoft's cloud; 1,000 Microsoft Rewards points; or a one-off payment Microsoft prices as 30 US dollars or the local currency equivalent plus tax.
In the EEA there are two: no additional cost if you sign in with a Microsoft account and stay signed in, with no settings sync and no Rewards requirement; or the same one-off payment if you would rather keep a local account. The EEA free route also lapses - stop signing in and updates stop within up to 60 days, and you have to enrol again.
So the defensible statement is about the price in data and conditions, not the price in money: a UK household reaches the free route by syncing its PC settings to Microsoft's cloud or by spending Rewards points, where an EEA household only has to stay signed in. Microsoft does not name the destination of that sync on the UK page, and none is asserted here. On the updates themselves Microsoft states that they are 'applied consistently across all supported areas' - a sentence it carries on its US page but not, in this snapshot, on its UK or Irish ones.
Microsoft publishes no sterling figure. The UK page gives only '$30 USD or local currency equivalent plus applicable tax', so no pound figure is published here. One consumer licence covers up to ten devices, which matters to any per-household cost framing.
United Kingdom: 3 routes into consumer ESU
- No additional cost, conditional on syncing PC settings to Microsoft's cloud
- 1,000 Microsoft Rewards points
- One-off purchase, priced as 30 US dollars or local currency equivalent plus tax
European Economic Area: 2 routes
- No additional cost, conditional on signing in and staying signed in with a Microsoft account
- One-off purchase, for people who want to keep a local account
“You can enroll in ESU in one of the following three ways: At no additional cost if you are syncing your PC Settings. Redeem 1,000 Microsoft Rewards points. One-time purchase of $30 USD or local currency equivalent plus applicable tax.”
“Consumers in the European Economic Area can enroll in ESU through one of the following ways after signing in with a Microsoft account: Users who stay signed in to the eligible PC with a Microsoft account [...] will enable Extended Security Updates on the device through 12 October, 2027, as long as you continue signing in to Windows with your Microsoft account used to enrol.”
Microsoft's own list of countries subject to the EEA terms has 36 entries. It includes Switzerland, which is in EFTA but not the EEA, and five French overseas territories. The United Kingdom is not on it. That endnote is the cleanest sourced basis for saying the UK sits outside the EEA terms.
- The brief for this study assumed the UK route costs money and the EEA route does not. Microsoft's published pages do not support that, and the claim is not made.
- The Euroconsumers letter cited here mis-cites the Digital Markets Act as Regulation (EU) 2022/2065, which is the Digital Services Act. The DMA is Regulation (EU) 2022/1925. The error is flagged so this study does not repeat it, and its companion citation, Directive (EU) 2019/770, is correct.
- A device-count figure in the same letter is sourced to a commercial reseller's blog rather than to any measurement, and its sentence is garbled in the original. It is not used.
- Individuals named in that letter are deliberately not carried into this study or its dataset.
What a non-ESU PC still gets, and what it does not
A Windows 10 22H2 machine without ESU is not cut off from everything. Microsoft Defender Antivirus security intelligence updates continue through October 2028. Microsoft Edge and the WebView2 Runtime keep updating on 22H2 until at least October 2028 and do not require ESU. Microsoft 365 Apps keep receiving security updates to 10 October 2028, though feature updates stop, and the OneDrive desktop app keeps updating on 22H2 to the same date.
Microsoft itself makes the point that antivirus definitions are not a substitute for operating system fixes. What stops without ESU is technical support, feature updates and quality updates including security and reliability fixes - which is exactly the 1486 fixes counted here.
“Devices running Windows 10 will be more vulnerable, even with ongoing security intelligence updates (SIUs).”
“Windows 10 PCs will continue to function. However, Microsoft no longer provides the following for Windows 10 devices: Technical support; Feature updates or new features; Quality updates (including security and reliability fixes).”
The dates, and what changes next
Consumer ESU was extended by a year in June 2026 and now runs to 12 October 2027. The extension was announced as an editor's note appended to a blog post from June 2025 rather than as a standalone announcement, which is why older write-ups still give 13 October 2026.
Commercial ESU runs in three purchasable years: Year 1 ends 13 October 2026, Year 2 ends 12 October 2027, Year 3 ends 10 October 2028. It is cumulative - buying Year 2 means paying for Year 1 as well.
So nothing counted here expires in the weeks after publication. The next date that changes the picture for a household is 12 October 2027, when consumer ESU ends and these monthly fixes stop reaching consumer machines entirely. For a business the next date is 13 October 2026, the end of commercial Year 1.
One thing the count does not mean: that these fixes are gone for good. Microsoft's UK consumer page states that a device can be enrolled at any time up to 12 October 2027, and Microsoft states that Windows quality updates are cumulative, each one built on the updates before it. So the figure here is what a machine has not received to date, not a permanent hole in it. What this study does not test is whether any particular enrolment delivers any particular earlier fix - that would need the update itself, which is not measured here.
| Date | What happens |
|---|---|
| 14 October 2025 | Windows 10 Home and Pro, and version 22H2, retired |
| 15 October 2025 | consumer ESU coverage begins; this study's window opens |
| 13 October 2026 | commercial ESU Year 1 ends |
| 12 October 2027 | consumer ESU ends; commercial ESU Year 2 ends |
| 10 October 2028 | commercial ESU Year 3 ends |
Scroll the table sideways to see every column →
Microsoft’s lifecycle tables are timestamped in a United States time zone, so some of these dates read a day later in the source row. Where that happens the row is quoted in the dataset README rather than a bare date being asserted. Planning an estate around these dates: the Windows 10 end-of-life calculator splits a fleet into what can move and what has to be carried.
Other Windows versions, and a footnote on Windows 11
1478 of the 1486 fixes also apply to Windows 11, which is 99.5 per cent of them. Only 8 are Windows 10 only - too few to express as a share. A Windows 11 machine on a version still in support received these same fixes as part of its ordinary monthly update. Windows 11 versions that are themselves out of support did not, and this study does not test which version any machine was on.
The traffic runs the other way too. In the same window Microsoft published 263 CVEs affecting Windows 11 whose records do not name Windows 10 22H2 at all, out of 1,745 affecting Windows 11 in total. That is absence from Microsoft's affected list, not a statement that Windows 10 is unaffected. They are not counted as fixes a Windows 10 machine missed, because Microsoft does not name it as affected.
1485 of the 1486 also name Windows 10 Version 21H2 (build 19044, which is also Enterprise and IoT LTSC 2021). Those products are not in this study's population, and for good reason in both directions: Home and Pro 21H2 went out of support on 14 June 2023 and cannot enrol in ESU at all, because ESU requires 22H2; Enterprise LTSC 2021 is still supported into January 2027 and IoT Enterprise LTSC 2021 into January 2032, so those machines are getting the fixes free.
| Overlap with other Windows products | Fixes | Out of | Share |
|---|---|---|---|
| also affects Windows 11 | 1,478 | 1,486 | 99.5% |
| Windows 10 only, not Windows 11 | 8 | 1,486 | — |
| also affects Windows 10 Version 21H2 or LTSC 2021 | 1,485 | 1,486 | 99.9% |
| also affects a Windows Server product | 1,465 | 1,486 | 98.6% |
Scroll the table sideways to see every column →
An earlier draft of this study's brief excluded 21H2 on the grounds that it is 'supported free to 12 January 2027'. That is wrong. 21H2 is excluded because it is out of support entirely and cannot enrol in ESU. The 12 January 2027 date belongs to Enterprise LTSC 2021, which is excluded for the opposite reason. Absence of a product from a CVE record’s affected array is absence from Microsoft’s own affected list, not a claim that the product is unaffected. Nothing here says Windows 10 does not have a flaw; it says Microsoft does not name it.
How the count was made, and how to check it
How these figures were produced
- Unit of analysis: One CVE. Population: Every CVE published by the Microsoft CNA between 15 October 2025 and 20 September 2026 whose CVE Program v5 record names "Windows 10 Version 22H2" as a vulnerable component, excluding those the free update of 14 October 2025 had already fixed.
- Inclusion test: cveMetadata.assignerShortName == 'microsoft' AND cveMetadata.state == 'PUBLISHED' AND containers.cna.datePublic >= 2025-10-15 AND containers.cna.affected[] contains an entry with product == 'Windows 10 Version 22H2' (exact string, case-insensitive) carrying a versions[] item with status 'affected'.
- Why the CVE Program and not NVD: primary - the affected-product claim comes from Microsoft's own CNA record, with no enrichment lag. Deliberately not used. NVD's configurations data lags and would have undercounted the most recent month by roughly half. No NVD API key was registered.
- Schema semantics: Across all 33,881 affected[] entries in the 3,101 in-window Microsoft records, the only version status Microsoft uses is 'affected' and defaultStatus is never set. Presence of the exact product string in containers.cna.affected is therefore itself the vulnerable-component claim. Every Windows 10 Version 22H2 entry - all 1,490 of them - uses versionType 'custom', with version = the first affected build and lessThan = the first fixed build. 231 of the 33,881 entries carry no versionType at all: they are cloud-service products such as Microsoft Entra and Azure Key Vault, written as version '-' with no lessThan. None of them is a Windows 10 entry, so a recount is unaffected, but a recounter who assumes versionType is always present will hit them.
- The boundary build: The boundary build 10.0.19045.6456 is derived inside the CVE data, not taken from an outside claim: 91 Microsoft-CNA CVEs dated 14 October 2025 give that value as the Windows 10 22H2 lessThan. September 2025 gives 6332 and July 2025 gives 6093, confirming the progression.
- Exploitation overlay: Exact match on CVE identifier between the published dataset and the cveID field of the CISA KEV catalogue. Lag is KEV dateAdded minus CVE datePublic in whole days; it is date-only arithmetic and cannot resolve hours. The join was cross-checked against the CISA-ADP SSVC Exploitation field carried inside the CVE records, and against a hand check of every entry against the raw catalogue.
- Classification: Component family and vulnerability type are parsed from Microsoft's own CVE titles by an ordered rule list published in stage2_filter.py.
- Cross-check: Monthly totals were recounted against Microsoft's own Security Update Guide, by three independent routes within that source: matching on product id, matching on product name string, and counting CVEs carrying a 22H2 vendor-fix KB. All three agree for every month.
- Percentages: Every percentage states its denominator. No percentage is published on a count below 10; those cuts say so. Percentages are rounded to one decimal place and may not sum to 100.
- Revisions: Both primary sources are revised continuously. This study freezes and hashes them at 2026-09-20 and carries that date on every figure. The analysis script performs no network access. It reads the frozen local snapshot only, so it produces identical output on every run.
The five exclusion rules, and what each removed
| Rule | Test | CVEs removed |
|---|---|---|
| E1 - named but not affected | 22H2 named in affected[] but no versions[] item with status 'affected' | 0 |
| E2 - wrong build family | 22H2 first-fixed build outside the 10.0.19045.* family, i.e. a data artefact | 0 |
| E3 - already fixed before support ended | first fixed at or below build 10.0.19045.6456, the free 14 October 2025 update, so a non-ESU PC did receive the fix — This rule was not in the study brief and is necessary. Any recount that skips it lands on 1,490 rather than 1,486. | 4 |
| E4 - serviced outside ESU | component delivered outside the Windows monthly cumulative update AND first fixed at a build other than that Patch Tuesday's — Yield zero, and the zero is the finding. Ten candidates exist - SQL Server ODBC driver, Windows WebView, Defender Firewall Service, some Office-named entries, WDAC OLE DB, Device Health Attestation. Every one carries the same Windows 10 22H2 first-fixed build as the rest of its Patch Tuesday, so all ten ship in the Windows monthly cumulative update, which is exactly what ESU delivers. Excluding them on component name alone would have silently dropped ten in-scope fixes. Microsoft Defender Antivirus proper, Edge and WebView2 never name Windows 10 Version 22H2 at all and so never entered the set. | 0 |
| E5 - running-on artefact | every windows_10_22H2 cpeMatch marked vulnerable:false, i.e. 22H2 is only the host platform — Yield zero. All 3,101 in-window records carry cpeApplicability and every 22H2 cpeMatch across the matched set is vulnerable:true. Running-on artefacts do exist elsewhere in the data, such as Internet Explorer 11 on Windows 10 Version 1903, which is why a substring match on '22H2' would be wrong: it would also pull in 'Windows 11 version 22H2'. | 0 |
Scroll the table sideways to see every column →
4 of the 5 rules removed nothing, and those zeros are reported because a recount that assumes otherwise will not match this one.
Recounts that will not land on 1,486, and why
| A recount done this way | Gives | Why |
|---|---|---|
| A recount that omits exclusion rule E3 | 1,490 | four CVEs published in November and December 2025 were already fixed by the free 14 October 2025 update, so a non-ESU PC did receive them |
| A recount against Microsoft's Security Update Guide | 1,500 | Microsoft also relays fixes whose CVE records belong to other CNAs. The CVE Program set is a strict subset; all fourteen differences are named on the page. |
| A recount using NVD 'configurations' rather than the CVE v5 CNA affected array | materially lower, roughly half for the most recent month | NVD enrichment lags behind publication. This study does not use NVD. |
| A recount against a later CVE Program release | higher | CVE records are revised continuously and past-month counts rise. |
Scroll the table sideways to see every column →
Where this study’s own publication gate tripped
| Month | Microsoft’s figure | This study | Difference | Divergence | Which CVEs | Over the 2% gate? |
|---|---|---|---|---|---|---|
| 2025-11 | 36 | 32 | 4 | 11.11% | CVE-2025-62208, CVE-2025-62209, CVE-2025-64720, CVE-2025-65018 | Yes |
| 2025-12 | 31 | 29 | 2 | 6.45% | CVE-2025-64679, CVE-2025-64680 | Yes |
| 2026-01 | 72 | 70 | 2 | 2.78% | CVE-2023-31096, CVE-2024-55414 | Yes |
| 2026-02 | 24 | 24 | 0 | 0% | — | No |
| 2026-03 | 43 | 43 | 0 | 0% | — | No |
| 2026-04 | 106 | 105 | 1 | 0.94% | CVE-2026-25250 | No |
| 2026-05 | 54 | 53 | 1 | 1.85% | CVE-2025-54518 | No |
| 2026-06 | 93 | 91 | 2 | 2.15% | CVE-2025-10263, CVE-2026-8863 | Yes |
| 2026-07 | 313 | 313 | 0 | 0% | — | No |
| 2026-08 | 160 | 158 | 2 | 1.25% | CVE-2026-6726, CVE-2026-6727 | No |
| 2026-09 | 568 | 568 | 0 | 0% | — | No |
Scroll the table sideways to see every column →
“Divergence” is the difference as a share of Microsoft’s figure for that month — the basis the 2 per cent gate is written against — not as a share of its 1,500 total. This gate was set before the data was pulled, as a condition that would block publication. It tripped on four months. On months of 24 to 36 CVEs a single record is worth 3 to 4 per cent, so the percentage gate is tripped by arithmetic on small denominators, not by a defect: the absolute differences are 4, 2, 2 and 2 CVEs. Every divergent CVE is named in the table below, in the dataset README and in this study's JSON, and all fourteen are accounted for. Publication proceeded on that basis. The gate is reported as tripped and the reason published, rather than the gate being quietly restated. Of the 14, 4 were removed by exclusion rule E3 and 10 are records the Microsoft CNA does not own: CVE-2023-31096 (mitre); CVE-2024-55414 (mitre); CVE-2025-10263 (Arm); CVE-2025-54518 (AMD); CVE-2025-64720 (GitHub_M); CVE-2025-65018 (GitHub_M); CVE-2026-25250 (mitre); CVE-2026-6726 (certcc); CVE-2026-6727 (certcc); CVE-2026-8863 (certcc).
Limits
- As at 20 September 2026. CVE records are revised continuously, so counts for past months rise over time. Everything here is computed from a frozen, hashed snapshot of the CVE Program's bulk release of 20 September 2026 and the CISA KEV catalogue v2026.09.18. Re-running the same filter on a later release will give a larger number, which is a property of the source, not a correction to this one.
- Microsoft's own monthly documents are living documents too. All twelve carry a current release date in September 2026 while their version field still reads 1.0 - the October 2025 document was last revised on 19 September 2026.
- 1,486 is a floor. It counts Microsoft-CNA records only; Microsoft's own list for the same months is 1,500, and the difference is fully explained but not folded in.
- 12 is a floor. The CISA KEV catalogue lists only what CISA has confirmed and chosen to publish, it is US-centric, and listings are retroactive.
- Absence of a product from a CVE record's affected array is absence, not a claim that the product is unaffected. This matters for any reasoning about what Windows 10 does not have.
- Monthly counts swing from 24 to 568, so no monthly rate is published. The median and the full range are published instead, computed over the eleven months that carry a Patch Tuesday inside the window; October 2025 contributes nothing, because its Patch Tuesday fell on the 14th, the last day of free support.
- September 2026 is a part month: it covers the 8 September Patch Tuesday, not the whole calendar month, and October's Patch Tuesday falls after the snapshot.
- The severity figures come from two different scales. CVSS v3.1 in the dataset is the Microsoft CNA's own score inside the CVE record, not NVD's. Microsoft's Critical/Important rating is a separate scale and is cited from the Security Update Guide, not reproduced.
- NVD was not used. The National Vulnerability Database's 'configurations' data lags and undercounts affected products - applying it to September 2026 would have halved that month. No NVD API key was registered and no NVD data is in this study.
- Component families are assigned by a rule list parsed from Microsoft's own CVE titles. The rule list is published in the analysis scripts so the classification can be disputed. Some assignments are defensible but arguable.
- Microsoft spells some component names several ways across months, and seven CVE titles in this set contain Microsoft's typo 'Vulernability'. Both are handled, and the raw component string is kept in the dataset alongside the merged family.
- This study can say which build first carried each fix, because Microsoft states it in the CVE record. It does not map builds to KB numbers or release dates: that would need the Security Update Guide, which is cited here rather than reproduced.
- Nothing here says Windows 10 was left without a patch. Microsoft shipped a fix for every CVE counted. The measurement is about which machines received it.
- This is a count of what a machine has not received to date, not a permanent gap. Microsoft's UK consumer page states that a device can be enrolled in consumer ESU at any time until the programme ends on 12 October 2027, and Microsoft states that Windows quality updates are cumulative. Whether any particular enrolment delivers any particular earlier fix is not tested here.
- This is a count of fixes, not a measure of risk to any individual machine. Most of these flaws require code already running on the device. No claim is made that any particular PC was attacked.
- No personal data is present. The dataset contains CVE identifiers, Microsoft product and component strings, builds, dates and scores. Researcher acknowledgements in Microsoft's source documents were never read into any output, and individuals named in a cited consumer-group letter are not carried into the dataset or the page.
What is new here, and what is not
The individual pieces are public. Microsoft's Security Update Guide has a product filter, so a determined person could approximate this count by hand month by month; the CISA KEV catalogue is a free download; and third-party services already list Windows 10 CVEs with a KEV overlay. What this study adds is the combination, dated and hashed: a single published filter over the CVE Program's own records rather than NVD's enrichment, scoped to the exact affected-array string 'Windows 10 Version 22H2', with the fixes the free 14 October 2025 update already delivered removed, the exploitation overlay joined on with days from publication to listing, and the whole dataset downloadable so the count can be disputed.
No claim is made that this is the first count of its kind, and none that the study is maintained: it is a single frozen snapshot, and no refresh cadence is committed to here. A search for a published series of this kind - a cumulative count of post-end-of-support Windows 10 22H2 fixes with an exploitation overlay - was run on 20 September 2026 and found none. That is the claim: none was found, not that none exists.
| Prior work that measures something similar | How this study differs |
|---|---|
| Microsoft Security Update Guide | Microsoft publishes the monthly documents and a product filter, but no cumulative count since end of support, no exploitation overlay, and no downloadable frozen series. Its rows also carry no open licence. |
| CISA Known Exploited Vulnerabilities catalogue | CISA publishes exploitation status across all vendors, not scoped to a Windows version and not joined to publication dates, so it does not answer how many of one product's missed fixes were for flaws already under attack. |
| CVE Program cvelistV5 bulk release | The bulk release is the raw material used here. It is not filtered to any product and carries no analysis. |
| OpenCVE, Microsoft Windows 10 product listing | Checked on 20 September 2026: OpenCVE lists 7,456 CVEs for Microsoft Windows 10, with a query builder that filters on KEV status, EPSS, CVSS and date, and a CSV export. It matches on the NVD/CPE product 'windows_10' rather than on Microsoft's own affected-array string 'Windows 10 Version 22H2', so it does not separate 22H2 from 21H2 and the LTSC editions; it is not scoped to the window that opens when support ended; it does not remove the fixes the free 14 October 2025 update already delivered; and it is a live index rather than a frozen, hashed series carrying days from publication to KEV listing. |
| Senserva, Microsoft Patch Tracker | Checked on 20 September 2026: Senserva tracks 1,088 Microsoft security updates fixing 3,880 CVEs, of which it says 319 close a vulnerability CISA lists as under active attack, refreshed twice a day with CSV and JSON export. It ranks Microsoft's updates across products rather than counting one Windows version, is not scoped to the post-end-of-support window, and does not exclude fixes a non-ESU machine did receive, so its counts answer a different question from this one. |
Scroll the table sideways to see every column →
Sources: CVE Program, CVE List V5 daily bulk release (CVE Program Terms of Use (SPDX: cve-tou)) · CISA Known Exploited Vulnerabilities catalog (CC0 1.0 Universal) · Microsoft Security Update Guide, CVRF v3.0 monthly documents (No open licence. Microsoft site terms.) · Microsoft Learn and microsoft.com - Extended Security Updates, lifecycle and end-of-support pages (Microsoft documentation and website terms) · Euroconsumers, letter to Microsoft Ireland Operations Ltd, 22 September 2025 (No open licence stated). Snapshot hashes: CVE Program bulk release cve_2026-09-20_0300Z, published 2026-09-20T03:28:48Z, sha256 3f226d290571eee431b48efd26cf5e7efbd5a1dc11c224e835e8c087edaadbc0; CISA KEV catalogVersion 2026.09.18, released 2026-09-18T19:00:05Z, 1,716 entries, sha256 7b770a6f5eb1d47a7176ef2f1428594551399912c8f3b5d2bf0f562b7e745e06. Quoted and attributed, not redistributed: aggregate counts only. No per-CVE row from this source is reproduced. The per-month lists of divergent CVE identifiers are derived by diffing Microsoft's list against this study's, and are identifiers, not Microsoft's rows. Fully redistributable. Does not authorise use of the CISA logo or DHS seal and is not an endorsement. CISA and Euroconsumers are named only to identify the organisations whose published material is cited. No Microsoft logo or device mark is used or licensed here, and the illustration on this page is Servnet’s own. Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation. Downloads: CSV, 1,486 rows · README and attribution · CVE Program licence, to keep with any copy · JSON. Built by scripts/research/windows-10-missed-security-fixes-2026/analyse.py; 21 automated assertions run, 0 failed.
Questions
How many security updates has Windows 10 missed since support ended?
1,486 Microsoft security fixes between 15 October 2025 and 20 September 2026, counting every CVE published by the Microsoft CNA whose CVE Program record names Windows 10 Version 22H2 as a vulnerable component, minus 4 that the free update of 14 October 2025 had already fixed. Microsoft's own Security Update Guide lists 1,500 for the same months; the 14-CVE difference is explained in the method. Both are floors, for different reasons: 1,486 counts Microsoft-CNA records only and CVE records are revised after publication, so a later re-run of the same filter returns more; 1,500 is Microsoft's own monthly documents, which are living documents that Microsoft continues to revise.
Has Windows 10 been left without security patches?
No, and this study does not say so. Microsoft shipped a fix for every one of these flaws: 0 of the 1,500 CVEs in Microsoft's own Windows 10 22H2 list for these months lacks a shipped 22H2 fix. What changed on 15 October 2025 is who receives the fix. Machines enrolled in Extended Security Updates get the monthly update; machines that are not, do not.
How many of the missed fixes are for flaws attackers are already using?
At least 12 of the 1,486. Those are the ones in CISA's Known Exploited Vulnerabilities catalogue, which CISA adds to only on evidence of active exploitation. For 9 of the 12, CISA listed the flaw on the same calendar day the fix shipped. 12 is a floor: CISA adds entries retroactively, and one here was added 126 days after publication. None of the 12 carries CISA's "known ransomware campaign use" flag.
Does Windows 10 Extended Security Updates cost money in the UK but not in the EEA?
Not as Microsoft's pages read on 20 September 2026. Both regions have a route into consumer ESU that costs no money; what differs is the condition attached. Microsoft lists 3 enrolment routes on its UK consumer page and 2 on its EEA one. The UK no-cost route requires syncing PC settings to Microsoft's cloud, or 1,000 Microsoft Rewards points; the EEA no-cost route requires only staying signed in with a Microsoft account. Microsoft publishes no sterling price, only "$30 USD or local currency equivalent plus applicable tax", so no pound figure is given here.
When does Windows 10 Extended Security Updates end?
Consumer ESU ends on 12 October 2027. 13 October 2026: commercial ESU Year 1 ends. 12 October 2027: consumer ESU ends; commercial ESU Year 2 ends. 10 October 2028: commercial ESU Year 3 ends. Microsoft extended consumer ESU by a year in June 2026, which is why older write-ups still give October 2026, and commercial ESU is cumulative, so buying a later year means paying for the earlier ones too. Enrolment itself stays open until the programme ends, so a machine that has not had these fixes is not permanently shut out of them.
Does this apply to Windows 10 21H2 or the LTSC editions?
No. The population is Windows 10 Home and Pro version 22H2 only. An earlier draft of this study's brief excluded 21H2 on the grounds that it is 'supported free to 12 January 2027'. That is wrong. 21H2 is excluded because it is out of support entirely and cannot enrol in ESU. The 12 January 2027 date belongs to Enterprise LTSC 2021, which is excluded for the opposite reason. Enterprise LTSC 2021 runs to January 2027 and IoT Enterprise LTSC 2021 to January 2032, so those machines are still receiving these fixes at no extra cost.
Are these Windows 10 problems, or do they affect Windows 11 too?
Almost all of them affect both. 1,478 of the 1,486 (99.5%) also name Windows 11, so a Windows 11 machine on a version still in support received the same fixes in its ordinary monthly update. Only 8 are Windows 10 only, too few to express as a share. Separately, 263 of the 1,745 Windows 11 CVEs in the window do not name Windows 10 22H2 at all, so they are not counted as fixes a Windows 10 machine missed. That is absence from Microsoft's affected list, not a statement that Windows 10 is unaffected.
Can I reuse this data?
Yes. Servnet's analysis and derived tables are free to reuse under CC BY 4.0, crediting "Servnet Windows 10 Missed Security Fixes 2026" with a link to this page. The dataset itself is built from the CVE Program's records and CISA's KEV catalogue. The CVE Program licence authorises a copy only if MITRE's copyright designation — "Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation." — and the licence text itself are both reproduced with it: the designation is on the first line of the CSV, and the licence is in the README and in a separate file published beside the CSV, so take one of those with any copy you make. The KEV columns are CC0 1.0, which does not authorise use of the CISA logo or DHS seal and is not an endorsement. Aggregate counts attributed to Microsoft's Security Update Guide are cited, not redistributed; no per-CVE row from that source is in the download.
Working out what to do about it
Servnet Research publishes dated observations from public sources for information only. It is not legal, security, financial or investment advice, and data are provided without warranty. Spotted an error, or want something re-measured or reviewed? See our corrections and takedown policy.
Related studies: what UK public bodies’ own FOI answers say about Windows end of support · which servers are certified for Windows Server 2025 and ESXi 9 · seven years of UK data breach reports to the ICO · more Servnet research.
About this study
- What it is: a count of the distinct CVEs published by the Microsoft CNA between 15 October 2025 and 20 September 2026 whose CVE Program v5 record names Windows 10 Version 22H2 as a vulnerable component, overlaid with the CISA Known Exploited Vulnerabilities catalogue, computed from a frozen hashed snapshot taken on 20 September 2026. It counts fixes a machine without Extended Security Updates did not receive. Microsoft shipped a fix for every one of them, and nothing here says any particular PC was attacked. CVE records are revised continuously, so a later re-run of the same filter will return a larger number.
- Licence and attribution: The download is mixed-licence, so no single licence covers it. Servnet’s own analysis, classification and derived tables are free to reuse under CC BY 4.0, crediting “Servnet Windows 10 Missed Security Fixes 2026” with a link to this page. The underlying records come from the CVE Program and from CISA: CVE Program Terms of Use (SPDX cve-tou) for CVE-derived columns; CC0 1.0 for CISA KEV columns. The CVE Program licence authorises a copy only if MITRE's copyright designation AND the licence itself are reproduced with it. The designation is on the first line of the CSV; the licence text is in the README and in windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt, published beside the CSV. A copy shipped without both breaches the licence. That designation is: “Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.” The licence text is published beside the CSV and reproduced in the README. Aggregate counts attributed to Microsoft’s Security Update Guide, and quotations from Microsoft’s documentation and from the Euroconsumers letter, are cited under those sources’ own terms and are not licensed by Servnet; no per-CVE row from them appears in the download, and the JSON endpoint carries each quotation’s claim and source without the quoted wording.
- Third-party names: Microsoft, Windows, Windows 10, Windows 11, Windows Server, Microsoft Defender, Microsoft Edge, OneDrive and CVE are trade marks of their respective owners, used only to identify products and organisations. Servnet is not affiliated with, endorsed by or acting for them.
- Our interest: Servnet sells and maintains IT hardware and services, including some of the products and platforms this study measures. The study reports what the sources show; it is not a recommendation to buy anything, and no organisation paid for, sponsored or approved it.
- Errors and takedown: tell us at webmaster@servnetuk.com and we will check it; see the corrections and takedown policy.
Talk to a UK specialist
Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.