{"name":"Microsoft security fixes a Windows 10 22H2 PC without Extended Security Updates did not receive, 15 October 2025 to 20 September 2026","publisher":"Servnet","url":"https://www.servnetuk.com/research/windows-10-missed-security-fixes-2026","licence":{"servnetAnalysis":"Servnet’s analysis, classification and derived tables: CC BY 4.0 (attribute \"Servnet Windows 10 Missed Security Fixes 2026\" with a link to the study page).","cveProgram":"CVE-derived fields are used under the CVE Program Terms of Use (SPDX: cve-tou), which authorise a copy only if MITRE’s copyright designation AND the licence text are reproduced with it. Both are carried below in cveProgramLicence and attribution, and are published at /research/windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt.","cisaKev":"CISA Known Exploited Vulnerabilities fields are CC0 1.0. That does not authorise use of the CISA logo or the DHS seal and is not an endorsement by CISA or DHS.","microsoftSecurityUpdateGuide":"Aggregate counts attributed to Microsoft’s Security Update Guide (data.microsoftOwnFigures, and the per-month divergent CVE identifiers under disagreements) are cited from that source, not redistributed. No per-CVE row from it appears here or in the CSV.","thirdPartyQuotations":"Quotations from Microsoft’s documentation and from the Euroconsumers letter are quoted on the study page under those sources’ own terms and are not licensed by Servnet. Their wording is omitted from this payload; each entry carries its claim, sourceUrl and licence instead."},"attribution":"Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.","cveProgramLicence":{"id":"cve-program-v5","name":"CVE Program, CVE List V5 daily bulk release","role":"primary - the affected-product claim comes from Microsoft's own CNA record, with no enrichment lag","url":"https://github.com/CVEProject/cvelistV5","release":"cve_2026-09-20_0300Z, published 2026-09-20T03:28:48Z","retrieved":"2026-09-20T04:18Z","sha256":"3f226d290571eee431b48efd26cf5e7efbd5a1dc11c224e835e8c087edaadbc0","records":"395,554 CVE records scanned; 15,414 Microsoft-CNA at all dates; 3,101 PUBLISHED in the window","licence":"CVE Program Terms of Use (SPDX: cve-tou)","licenceUrl":"https://www.cve.org/Legal/TermsOfUse","redistributable":true,"condition":"Perpetual, worldwide, royalty-free, irrevocable licence to reproduce, prepare derivative works of, display and distribute, including commercial use, conditional on reproducing MITRE's copyright designation AND this licence in any copy. Both ship with the download: the designation on the CSV's first line, the licence text in the README and in windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt beside the CSV.","licenceText":"CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge,\nroyalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly\ndisplay, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE(R)).\nAny copy you make for such purposes is authorized provided that you reproduce MITRE's copyright\ndesignation and this license in any such copy.\n\nDISCLAIMERS\n\nALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN PROVIDED BY MITRE ARE PROVIDED ON AN \"AS IS\"\nBASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE\nCORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS\nOR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL\nNOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR\nPURPOSE.","licenceFile":"/research/windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt"},"study":"windows-10-missed-security-fixes-2026","title":"Windows 10, one year on: the security fixes a non-ESU PC did not receive","question":"How many Microsoft security fixes has an ordinary Windows 10 Home or Pro 22H2 PC without Extended Security Updates not received since support ended on 14 October 2025, how many of those flaws is CISA already listing as actively exploited, and what actually differs between the UK and the EEA?","snapshotAsAt":"2026-09-20","asAtLine":"All figures as at 20 September 2026.","window":{"from":"2025-10-15","to":"2026-09-20"},"built":"2026-09-20","builder":"scripts/research/windows-10-missed-security-fixes-2026/analyse.py","dataset":{"csv":"/research/windows-10-missed-security-fixes-2026.csv","readme":"/research/windows-10-missed-security-fixes-2026-README.txt","rows":1486,"licence":"CVE Program Terms of Use (SPDX cve-tou) for CVE-derived columns; CC0 1.0 for CISA KEV columns","copyrightDesignation":"Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.","licenceFile":"/research/windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt","condition":"The CVE Program licence authorises a copy only if MITRE's copyright designation AND the licence itself are reproduced with it. The designation is on the first line of the CSV; the licence text is in the README and in windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt, published beside the CSV. A copy shipped without both breaches the licence."},"preRegisteredMetrics":[{"id":"N","metric":"Microsoft security fixes a Windows 10 Home or Pro 22H2 PC without ESU did not receive","value":1486,"unit":"distinct CVEs","denominator":3101,"denominatorLabel":"Microsoft-CNA CVE records in PUBLISHED state with datePublic on or after 15 October 2025, in the frozen bulk release","shareOfDenominatorPct":47.9,"window":"2025-10-15 to 2026-09-20","howToRecompute":"From the published CSV: count the rows. From source: filter the CVE Program v5 bulk release to assignerShortName == 'microsoft', state == 'PUBLISHED' and containers.cna.datePublic >= 2025-10-15, keep records whose containers.cna.affected[] contains an entry with product == 'Windows 10 Version 22H2' carrying a versions[] item with status 'affected', then drop records whose lessThan build is <= 10.0.19045.6456.","isFloor":true,"floorReason":"The CVE Program v5 population counts Microsoft-CNA records only. Microsoft's own Security Update Guide lists 1500 for the same months because it also relays fixes whose CVE records belong to other CNAs. Both figures are published below."},{"id":"K","metric":"of those fixes, flaws CISA lists in its Known Exploited Vulnerabilities catalogue","value":12,"unit":"distinct CVEs","denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","shareOfDenominatorPct":0.8,"howToRecompute":"Join the published CSV's cve_id to the cveID field of the CISA KEV catalogue and count matches. The CSV's in_cisa_kev column is that join, frozen at the snapshot date.","isFloor":true,"floorReason":"KEV lists only what CISA has confirmed and chosen to publish, it is US-centric, and listings are retroactive - one entry here was added 126 days after publication. K will rise after this snapshot. Read it as 'at least 12'."},{"id":"zeroLag","metric":"of those KEV entries, ones CISA listed on the same day the fix shipped","value":9,"unit":"distinct CVEs","denominator":12,"denominatorLabel":"KEV entries in the population","pctWithheld":true,"pctWithheldReason":"denominator is 12, fewer than 10; no percentage is published","howToRecompute":"Count rows in the published CSV where kev_days_publication_to_listing = 0."},{"id":"monthlyMedian","metric":"median fixes missed per month","value":70,"unit":"distinct CVEs per month","denominator":11,"denominatorLabel":"months with at least one publication date in the window","range":[24,568],"howToRecompute":"Group the published CSV by patch_month, count rows, take the median.","rateClaimWithheld":true,"rateClaimWithheldReason":"Monthly values run from 24 to 568, a factor of 23.7. A single 'growing by N a month' figure would misdescribe the series, so the median and the full range are published instead and no rate is claimed. The window is about eleven and a quarter months, but October 2025 contributes nothing - its Patch Tuesday fell on the 14th, the last day of free support - so the median, mean and range are computed over the eleven months that carry a Patch Tuesday inside the window."},{"id":"microsoftOwnTotal","metric":"Microsoft's own count of CVEs affecting Windows 10 Version 22H2 for the same months","value":1500,"unit":"distinct CVEs","denominator":1500,"denominatorLabel":"self","source":"Microsoft Security Update Guide CVRF v3.0 monthly documents, cited not reproduced","howToRecompute":"Read the eleven monthly CVRF documents from November 2025 to September 2026 and count distinct CVEs whose ProductStatuses 'Known Affected' list names a Windows 10 Version 22H2 product id. This figure is a citation: the underlying rows carry no open licence and are not in the published dataset."}],"page":{"headline":"A Windows 10 Home or Pro 22H2 PC with no Extended Security Updates has not received 1,486 Microsoft security fixes since support ended on 14 October 2025 - 12 of them for flaws CISA lists as actively exploited, 9 of which CISA listed on the day the fix shipped. Microsoft's own Security Update Guide puts the figure at 1,500 for the same months.","standfirst":"Microsoft fixed every one of them. The question this study answers is which machines received the fix, how many of the flaws were already being exploited when it shipped, and what a UK household actually has to do differently from an EEA one.","wordingRules":["The word 'unpatched' is not used. Microsoft shipped a fix for every CVE counted here. The only accurate framing is 'fixes a non-ESU machine did not receive'.","No ransomware framing. None of the exploited flaws carries CISA's 'Known' ransomware-campaign flag.","No superlatives and no 'first ever' claim. See the novelty note.","The population is Windows 10 Home and Pro 22H2 without ESU. Nothing here describes 21H2 or the LTSC editions."],"keyFigures":[{"value":"1,486","label":"Microsoft security fixes a non-ESU Windows 10 22H2 PC did not receive","denominator":"of 3,101 Microsoft CVEs published in the window","period":"15 October 2025 to 20 September 2026"},{"value":"12","label":"of those are flaws CISA lists as actively exploited","denominator":"of 1,486 missed fixes","note":"a floor: KEV listings are added retroactively"},{"value":"9","label":"were listed as exploited on the day the fix shipped","denominator":"of 12 KEV entries","note":"denominator under 10, so no percentage is given"},{"value":"70","label":"median fixes missed per month","denominator":"over the 11 months with a Patch Tuesday in the window","note":"range 24 to 568; no monthly rate is claimed"},{"value":"1,140","label":"rated Critical or High by Microsoft's own CVSS score","denominator":"of 1,486 missed fixes"},{"value":"1,500","label":"Microsoft's own count for the same months","denominator":"Security Update Guide, cited not reproduced"}],"sections":[{"id":"what-was-measured","heading":"What was measured","body":["Support for Windows 10 Home and Pro ended on 14 October 2025. From 15 October 2025 the monthly Windows security update for version 22H2 went only to machines enrolled in Extended Security Updates. This study counts the fixes in those updates.","The unit is one CVE. The population is every CVE published by the Microsoft CNA between 2025-10-15 and 2026-09-20 whose CVE Program v5 'affected' array names \"Windows 10 Version 22H2\" as a vulnerable component, minus those the last free update of 14 October 2025 had already fixed.","Microsoft shipped a fix for every one of them. The question is only which machines received it. Nothing here says Windows 10 was left without a patch."],"findings":[{"label":"fixes a non-ESU 22H2 PC did not receive","n":1486,"denominator":3101,"denominatorLabel":"Microsoft-CNA CVE records published in the window","pct":47.9,"pctWithheld":false},{"label":"CVEs that named 22H2 but were already fixed by the free 14 October 2025 update","n":4,"denominator":1490,"denominatorLabel":"CVEs naming Windows 10 Version 22H2 as a vulnerable component","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 4, fewer than 10; no percentage is published on a count this small"}]},{"id":"the-count","heading":"The count, month by month","body":["1486 fixes across 11 months. The monthly bars are the observations; the curve above them is only their running total. Both are published because the running total is what a machine accumulates and the bars are what the series actually looks like.","Monthly counts run from 24 (February 2026) to 568 (September 2026), with a median of 70. That is a factor of 23.7 between the smallest and largest month, so this study publishes the median and the range and makes no claim about a monthly rate.","The large months are broad across components, not one component arriving in a batch. September 2026 alone is 568 of the 1486, spread over 184 distinct components: its largest single block is Windows Biometric Service at 64, 11.3 per cent of the month, and its five largest components together are 140. July 2026 is the same shape - Windows Kernel is the largest at 25 of 313. No component accounts for more than a fifth of any month in the series. Why September 2026 is as large as it is cannot be answered from the CVE records, and no explanation is offered here.","These are distinct CVE identifiers, checked for duplicates, not one flaw counted many times."],"series":[{"month":"2025-11","monthLabel":"November 2025","publicationDates":["2025-11-11"],"n":32,"cumulative":32,"shareOfTotalPct":2.2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6575"],"outOfBand":[]},{"month":"2025-12","monthLabel":"December 2025","publicationDates":["2025-12-09"],"n":29,"cumulative":61,"shareOfTotalPct":2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6575","10.0.19045.6691"],"outOfBand":[]},{"month":"2026-01","monthLabel":"January 2026","publicationDates":["2026-01-13"],"n":70,"cumulative":131,"shareOfTotalPct":4.7,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6809"],"outOfBand":[]},{"month":"2026-02","monthLabel":"February 2026","publicationDates":["2026-02-10"],"n":24,"cumulative":155,"shareOfTotalPct":1.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6937"],"outOfBand":[]},{"month":"2026-03","monthLabel":"March 2026","publicationDates":["2026-03-10"],"n":43,"cumulative":198,"shareOfTotalPct":2.9,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7058"],"outOfBand":[]},{"month":"2026-04","monthLabel":"April 2026","publicationDates":["2026-04-14"],"n":105,"cumulative":303,"shareOfTotalPct":7.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7184","10.0.19045.7548"],"outOfBand":[]},{"month":"2026-05","monthLabel":"May 2026","publicationDates":["2026-05-12"],"n":53,"cumulative":356,"shareOfTotalPct":3.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7417"],"outOfBand":[]},{"month":"2026-06","monthLabel":"June 2026","publicationDates":["2026-06-09"],"n":91,"cumulative":447,"shareOfTotalPct":6.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7417"],"outOfBand":[]},{"month":"2026-07","monthLabel":"July 2026","publicationDates":["2026-07-14","2026-07-16"],"n":313,"cumulative":760,"shareOfTotalPct":21.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7548"],"outOfBand":["2026-07-16"]},{"month":"2026-08","monthLabel":"August 2026","publicationDates":["2026-08-11"],"n":158,"cumulative":918,"shareOfTotalPct":10.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7663"],"outOfBand":[]},{"month":"2026-09","monthLabel":"September 2026","publicationDates":["2026-09-08"],"n":568,"cumulative":1486,"shareOfTotalPct":38.2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7725"],"outOfBand":[]}],"volatility":{"months":11,"median":70,"min":24,"minMonth":"2026-02","max":568,"maxMonth":"2026-09","mean":135.1,"rateClaimWithheld":true,"rateClaimWithheldReason":"Monthly values run from 24 to 568, a factor of 23.7. A single 'growing by N a month' figure would misdescribe the series, so the median and the full range are published instead and no rate is claimed. The window is about eleven and a quarter months, but October 2025 contributes nothing - its Patch Tuesday fell on the 14th, the last day of free support - so the median, mean and range are computed over the eleven months that carry a Patch Tuesday inside the window."},"concentration":[{"month":"2025-11","n":32,"distinctComponents":23,"largestComponent":"DirectX Graphics Kernel","largestComponentN":3,"largestComponentPct":9.4,"topFiveN":13,"topFivePct":40.6},{"month":"2025-12","n":29,"distinctComponents":16,"largestComponent":"Windows Projected File System","largestComponentN":5,"largestComponentPct":17.2,"topFiveN":16,"topFivePct":55.2},{"month":"2026-01","n":70,"distinctComponents":41,"largestComponent":"Windows Management Services","largestComponentN":12,"largestComponentPct":17.1,"topFiveN":27,"topFivePct":38.6},{"month":"2026-02","n":24,"distinctComponents":16,"largestComponent":"Windows Hyper-V","largestComponentN":4,"largestComponentPct":16.7,"topFiveN":13,"topFivePct":54.2},{"month":"2026-03","n":43,"distinctComponents":30,"largestComponent":"Windows Graphics Component","largestComponentN":4,"largestComponentPct":9.3,"topFiveN":16,"topFivePct":37.2},{"month":"2026-04","n":105,"distinctComponents":58,"largestComponent":"Windows Ancillary Function Driver for WinSock","largestComponentN":8,"largestComponentPct":7.6,"topFiveN":31,"topFivePct":29.5},{"month":"2026-05","n":53,"distinctComponents":33,"largestComponent":"Windows TCP/IP","largestComponentN":8,"largestComponentPct":15.1,"topFiveN":21,"topFivePct":39.6},{"month":"2026-06","n":91,"distinctComponents":47,"largestComponent":"Remote Desktop Client","largestComponentN":9,"largestComponentPct":9.9,"topFiveN":31,"topFivePct":34.1},{"month":"2026-07","n":313,"distinctComponents":143,"largestComponent":"Windows Kernel","largestComponentN":25,"largestComponentPct":8,"topFiveN":73,"topFivePct":23.3},{"month":"2026-08","n":158,"distinctComponents":76,"largestComponent":"Windows Telephony Service","largestComponentN":12,"largestComponentPct":7.6,"topFiveN":45,"topFivePct":28.5},{"month":"2026-09","n":568,"distinctComponents":184,"largestComponent":"Windows Biometric Service","largestComponentN":64,"largestComponentPct":11.3,"topFiveN":140,"topFivePct":24.6}],"seriesBreaks":["The series opens in November 2025, not October 2025. The window opens on 15 October 2025 but Microsoft published no CVE naming Windows 10 22H2 between then and the November Patch Tuesday, so there is no October point. Microsoft's own October 2025 document lists 97 CVEs affecting 22H2, every one of them first published before 15 October and therefore fixed by the free update.","July 2026 has two publication dates: the Patch Tuesday of 14 July 2026 and an out-of-band record dated 16 July 2026.","September 2026 is a part month. It covers the 8 September Patch Tuesday but the month was not over at the snapshot date, and October 2026's Patch Tuesday is not in the series.","One CVE published on 14 April 2026 was first fixed at the July 2026 build, so April shows two first-fixed builds. It is still counted as missed, because no non-ESU machine received that build either."]},{"id":"what-kind-of-flaws","heading":"What kind of flaws","body":["By Microsoft's own CVSS v3.1 scoring inside the CVE records, 38 of the 1486 are Critical and 1102 are High.","By vulnerability class, elevation of privilege dominates: these are mostly flaws that let code already running on the machine gain more control, rather than flaws an attacker reaches across the internet unaided.","The largest component family is Networking and protocols, 286 of 1486 (19.2 per cent)."],"cvssSeverity":{"note":"CVSS v3.1 as scored by the Microsoft CNA inside each CVE record. This is not NVD's score and it is not Microsoft's own Critical/Important rating, which is a separate scale reported in the ESU section.","rows":[{"label":"Critical","n":38,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.6,"pctWithheld":false},{"label":"High","n":1102,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":74.2,"pctWithheld":false},{"label":"Medium","n":343,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":23.1,"pctWithheld":false},{"label":"Low","n":3,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 3, fewer than 10; no percentage is published on a count this small"}]},"vulnerabilityTypes":{"note":"Parsed from Microsoft's own CVE titles. Every record in the population parsed to a type.","rows":[{"label":"Elevation of Privilege","n":888,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":59.8,"pctWithheld":false},{"label":"Remote Code Execution","n":235,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":15.8,"pctWithheld":false},{"label":"Information Disclosure","n":225,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":15.1,"pctWithheld":false},{"label":"Denial of Service","n":61,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.1,"pctWithheld":false},{"label":"Security Feature Bypass","n":47,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":3.2,"pctWithheld":false},{"label":"Tampering","n":17,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Spoofing","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false}]},"componentFamilies":{"note":"Families are assigned by an ordered rule list published in stage2_filter.py so the classification can be disputed and re-run. Microsoft spells some components several ways across months - 'Windows Win32k' and 'Win32k', 'Windows GDI+' and 'GDI+' - and the family column merges them while the component column does not. Some assignments are arguable: Windows Network File System is filed under file systems rather than networking, and Windows Biometric Service under authentication and identity.","rows":[{"label":"Networking and protocols","n":286,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":19.2,"pctWithheld":false},{"label":"File systems and storage","n":251,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":16.9,"pctWithheld":false},{"label":"Authentication and identity","n":152,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":10.2,"pctWithheld":false},{"label":"Graphics, fonts and imaging","n":123,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8.3,"pctWithheld":false},{"label":"Kernel and Win32k","n":119,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8,"pctWithheld":false},{"label":"Management and servicing","n":119,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8,"pctWithheld":false},{"label":"Shell and user interface","n":107,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":7.2,"pctWithheld":false},{"label":"Audio, video and media","n":69,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.6,"pctWithheld":false},{"label":"Devices and drivers","n":64,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.3,"pctWithheld":false},{"label":"Remote Desktop and RDP","n":64,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.3,"pctWithheld":false},{"label":"COM, RPC and scripting","n":37,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.5,"pctWithheld":false},{"label":"Boot and platform security","n":36,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.4,"pctWithheld":false},{"label":"Hyper-V and virtualisation","n":27,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.8,"pctWithheld":false},{"label":"Printing and scanning","n":26,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.7,"pctWithheld":false},{"label":"Office file handling in Windows","n":3,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 3, fewer than 10; no percentage is published on a count this small"},{"label":"Third-party silicon mitigations","n":2,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 2, fewer than 10; no percentage is published on a count this small"},{"label":"Other Windows component","n":1,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 1, fewer than 10; no percentage is published on a count this small"}]},"largestComponents":{"note":"Top 25 raw component strings exactly as Microsoft writes them, without spelling merges.","rows":[{"label":"Windows Biometric Service","n":65,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.4,"pctWithheld":false},{"label":"Windows NTFS","n":60,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4,"pctWithheld":false},{"label":"Windows Kernel","n":54,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":3.6,"pctWithheld":false},{"label":"Windows Ancillary Function Driver for WinSock","n":40,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.7,"pctWithheld":false},{"label":"Windows Win32k","n":33,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.2,"pctWithheld":false},{"label":"Windows Routing and Remote Access Service (RRAS)","n":23,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.5,"pctWithheld":false},{"label":"Windows TCP/IP","n":21,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.4,"pctWithheld":false},{"label":"Win32k","n":20,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Windows Hyper-V","n":20,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Remote Desktop Client","n":19,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Microsoft Standard XPS","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Cloud Files Mini Filter Driver","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Spaceport.sys","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Telephony Service","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Installer","n":17,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Windows Projected File System","n":16,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Windows Device Association Service","n":15,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1,"pctWithheld":false},{"label":"DirectX Graphics Kernel","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows File Explorer","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Management Services","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Remote Desktop Services","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Graphics Component","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Push Notifications","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Microsoft Windows Media Foundation","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false},{"label":"Windows Hello","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false}]}},{"id":"known-exploitation","heading":"Flaws already being exploited","body":["12 of the 1486 fixes are for flaws CISA has since listed in its Known Exploited Vulnerabilities catalogue.","For 9 of those 12, CISA listed the flaw as actively exploited on the same calendar day the fix shipped. CISA adds an entry only on evidence of active exploitation, so same-day listing means exploitation was already known when the update went out. It does not establish that any particular machine was attacked, and the arithmetic is date-only - it cannot resolve hours.","None of these carries CISA's 'Known' ransomware-campaign flag. All are flagged 'Unknown', which means not established rather than not used."],"headline":{"kevCount":{"label":"in the CISA KEV catalogue","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false},"lagVector":[0,0,0,0,0,0,0,0,0,1,14,126],"zeroLag":{"n":9,"denominator":12,"denominatorLabel":"KEV entries in the population","pctWithheld":true,"pctWithheldReason":"denominator is 12, fewer than 10; no percentage is published"},"lagMedianDays":0,"lagMaxDays":126,"ransomwareKnown":0},"rows":[{"cveId":"CVE-2025-62221","title":"Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability","component":"Windows Cloud Files Mini Filter Driver","componentFamily":"File systems and storage","vulnType":"Elevation of Privilege","datePublic":"2025-12-09","kevDateAdded":"2025-12-09","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Use After Free Vulnerability","kevShortDescription":"Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-20805","title":"Desktop Window Manager Information Disclosure Vulnerability","component":"Desktop Window Manager","componentFamily":"Graphics, fonts and imaging","vulnType":"Information Disclosure","datePublic":"2026-01-13","kevDateAdded":"2026-01-13","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Information Disclosure Vulnerability","kevShortDescription":"Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":5.5,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-21510","title":"Windows Shell Security Feature Bypass Vulnerability","component":"Windows Shell","componentFamily":"Shell and user interface","vulnType":"Security Feature Bypass","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Shell Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":8.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21513","title":"MSHTML Framework Security Feature Bypass Vulnerability","component":"MSHTML Framework","componentFamily":"COM, RPC and scripting","vulnType":"Security Feature Bypass","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":8.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21519","title":"Desktop Window Manager Elevation of Privilege Vulnerability","component":"Desktop Window Manager","componentFamily":"Graphics, fonts and imaging","vulnType":"Elevation of Privilege","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Type Confusion Vulnerability","kevShortDescription":"Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21525","title":"Windows Remote Access Connection Manager Denial of Service Vulnerability","component":"Windows Remote Access Connection Manager","componentFamily":"Networking and protocols","vulnType":"Denial of Service","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows NULL Pointer Dereference Vulnerability","kevShortDescription":"Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":6.2,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-21533","title":"Windows Remote Desktop Services Elevation of Privilege Vulnerability","component":"Windows Remote Desktop Services","componentFamily":"Remote Desktop and RDP","vulnType":"Elevation of Privilege","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Improper Privilege Management Vulnerability","kevShortDescription":"Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-68820","title":"Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability","component":"Windows Ancillary Function Driver for WinSock","componentFamily":"Networking and protocols","vulnType":"Elevation of Privilege","datePublic":"2026-08-11","kevDateAdded":"2026-08-11","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","kevShortDescription":"Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-85880","title":"Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability","component":"Windows Advanced Local Procedure Call (ALPC)","componentFamily":"Kernel and Win32k","vulnType":"Elevation of Privilege","datePublic":"2026-09-08","kevDateAdded":"2026-09-08","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Heap-Based Buffer Overflow Vulnerability","kevShortDescription":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2025-62215","title":"Windows Kernel Elevation of Privilege Vulnerability","component":"Windows Kernel","componentFamily":"Kernel and Win32k","vulnType":"Elevation of Privilege","datePublic":"2025-11-11","kevDateAdded":"2025-11-12","daysPublicationToKevListing":1,"kevVulnerabilityName":"Microsoft Windows Race Condition Vulnerability","kevShortDescription":"Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-32202","title":"Windows Shell Spoofing Vulnerability","component":"Windows Shell","componentFamily":"Shell and user interface","vulnType":"Spoofing","datePublic":"2026-04-14","kevDateAdded":"2026-04-28","daysPublicationToKevListing":14,"kevVulnerabilityName":"Microsoft Windows Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":4.3,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-33824","title":"Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability","component":"Windows Internet Key Exchange (IKE) Service Extensions","componentFamily":"Networking and protocols","vulnType":"Remote Code Execution","datePublic":"2026-04-14","kevDateAdded":"2026-08-18","daysPublicationToKevListing":126,"kevVulnerabilityName":"Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability","kevShortDescription":"Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":9.8,"cvssBaseSeverity":"CRITICAL"}],"ssvcCrossCheck":{"note":"Two independent routes give the same set: the CISA-ADP SSVC Exploitation field carried inside the CVE records, and a direct join to the KEV catalogue. They are different signals by definition and agreeing here is a result, not a guarantee.","rows":[{"label":"none","n":1471,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":99,"pctWithheld":false},{"label":"active","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false},{"label":"poc","n":3,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 3, fewer than 10; no percentage is published on a count this small"}]},"caveats":["KEV is a floor, not a census. Absence from KEV is not evidence that a flaw was not exploited.","KEV listings are retroactive. One entry here, CVE-2026-33824, was added 126 days after publication, so the figure for recent months will rise after this snapshot.","Each KEV entry carries a dueDate. That is a United States federal compliance deadline under CISA Binding Operational Directive 22-01. It has no force for a UK household and is not presented here as one."]},{"id":"does-esu-deliver-all-of-them","heading":"Does paying for ESU deliver all of them?","body":["On the evidence available, yes - with one documented boundary that cannot be tested from public data. Every one of the 1500 CVEs in Microsoft's own Windows 10 22H2 list for these months carries a shipped 22H2 vendor-fix KB in Microsoft's Security Update Guide, with no exceptions in any of the eleven months. There is no set of fixes that simply never shipped.","That boundary is the stated severity scope. Microsoft states that ESU delivers Critical- and Important-rated security updates only, and the Microsoft Security Response Center rates on four levels. In this window Microsoft rates 2 of the 1500 as Moderate, outside that stated scope - too few to express as a share. Those two fixes ship in the same monthly cumulative update as the rest, so whether ESU withholds them is not observable from anything Microsoft publishes. No claim is made here that an ESU subscriber misses anything."],"microsoftSeverity":{"note":"Microsoft's own Critical/Important/Moderate/Low rating, from the Security Update Guide. Cited, not reproduced: this source carries no open licence and its rows are not in the published dataset. Denominator is Microsoft's own total, which is larger than this study's CVE Program population.","denominator":1500,"denominatorLabel":"CVEs Microsoft lists as affecting Windows 10 Version 22H2, Nov 2025 to Sep 2026","rows":[{"label":"Important","n":1399,"denominator":1500,"denominatorLabel":"Microsoft's own 22H2 list for these months","pct":93.3,"pctWithheld":false},{"label":"Critical","n":99,"denominator":1500,"denominatorLabel":"Microsoft's own 22H2 list for these months","pct":6.6,"pctWithheld":false},{"label":"Moderate","n":2,"denominator":1500,"denominatorLabel":"Microsoft's own 22H2 list for these months","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 2, fewer than 10; no percentage is published on a count this small"}],"inStatedEsuScope":{"label":"Critical or Important, i.e. inside ESU's stated scope","n":1498,"denominator":1500,"denominatorLabel":"Microsoft's own 22H2 list for these months","pct":99.9,"pctWithheld":false},"outsideStatedEsuScope":{"label":"Moderate, i.e. outside ESU's stated severity scope","n":2,"denominator":1500,"denominatorLabel":"Microsoft's own 22H2 list for these months","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 2, fewer than 10; no percentage is published on a count this small"}},"everyFixShipped":{"cvesWithoutA22h2FixKb":0,"denominator":1500,"denominatorLabel":"CVEs Microsoft lists as affecting Windows 10 Version 22H2 in the window","note":"This is why the word 'unpatched' does not appear in this study. Microsoft fixed all of them. The finding is about delivery, not about whether a fix exists."},"quotes":[{"id":"esu-scope-severity","claim":"Consumer and commercial ESU deliver only Critical- and Important-rated security fixes, as rated by the Microsoft Security Response Center. Moderate- and Low-rated fixes are outside the stated scope.","sourceUrl":"https://www.microsoft.com/en-us/windows/end-of-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"esu-scope-severity-consumer","claim":"The consumer ESU page repeats the severity scope and adds that ESU brings no other fixes, no feature work and no support.","sourceUrl":"https://www.microsoft.com/en-us/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"msrc-severity-levels","claim":"MSRC defines four severity levels - Critical, Important, Moderate and Low - so the 'critical and important only' scope is a genuine subset, not a synonym for 'all'.","sourceUrl":"https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"The source is a table row: the rating name and its description sit in separate cells. The colon in square brackets is editorial, added here to join them; it is not in Microsoft's text. Whether any Windows 10 22H2 CVE in the study window is actually rated Moderate or Low is an empirical question for the CVE stream. The documentation establishes only that the scope is bounded by severity.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"esu-prereq-22h2","claim":"ESU requires Windows 10 version 22H2. No other Windows 10 version can be enrolled.","sourceUrl":"https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"esu-prereq-editions","claim":"Consumer ESU covers Windows 10 22H2 Home, Professional, Pro Education and Pro for Workstations, and excludes domain-joined / MDM-managed / kiosk devices.","sourceUrl":"https://www.microsoft.com/en-us/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."}],"droppedAngle":{"angle":"Even ESU subscribers miss some of these fixes","status":"not supported","reason":"All 1500 CVEs in Microsoft's own list carry a shipped 22H2 fix. The only bounded thing is the stated severity scope, and the two Moderate-rated fixes in this window ship in the same cumulative update, so no measurable gap was found. Reported as a negative finding rather than replaced with something weaker."}},{"id":"uk-vs-eea","heading":"The UK and the EEA: what actually differs","body":["The study set out to test whether a UK household pays for updates an EEA household gets free. As published by Microsoft on 20 September 2026, that is not what the difference is. Both regions have a route into consumer ESU that costs no money. What differs is the condition attached to it.","In the United Kingdom there are three routes: no additional cost if you sync your PC settings to Microsoft's cloud; 1,000 Microsoft Rewards points; or a one-off payment Microsoft prices as 30 US dollars or the local currency equivalent plus tax.","In the EEA there are two: no additional cost if you sign in with a Microsoft account and stay signed in, with no settings sync and no Rewards requirement; or the same one-off payment if you would rather keep a local account. The EEA free route also lapses - stop signing in and updates stop within up to 60 days, and you have to enrol again.","So the defensible statement is about the price in data and conditions, not the price in money: a UK household reaches the free route by syncing its PC settings to Microsoft's cloud or by spending Rewards points, where an EEA household only has to stay signed in. Microsoft does not name the destination of that sync on the UK page, and none is asserted here. On the updates themselves Microsoft states that they are 'applied consistently across all supported areas' - a sentence it carries on its US page but not, in this snapshot, on its UK or Irish ones.","Microsoft publishes no sterling figure. The UK page gives only '$30 USD or local currency equivalent plus applicable tax', so no pound figure is published here. One consumer licence covers up to ten devices, which matters to any per-household cost framing."],"routes":{"unitedKingdom":{"n":3,"denominatorLabel":"enrolment routes Microsoft lists on the en-GB consumer ESU page","routes":["No additional cost, conditional on syncing PC settings to Microsoft's cloud","1,000 Microsoft Rewards points","One-off purchase, priced as 30 US dollars or local currency equivalent plus tax"]},"eea":{"n":2,"denominatorLabel":"enrolment routes Microsoft lists on the en-IE consumer ESU page","routes":["No additional cost, conditional on signing in and staying signed in with a Microsoft account","One-off purchase, for people who want to keep a local account"]}},"eeaCountryList":{"n":36,"note":"Microsoft's own list of countries subject to the EEA terms has 36 entries. It includes Switzerland, which is in EFTA but not the EEA, and five French overseas territories. The United Kingdom is not on it. That endnote is the cleanest sourced basis for saying the UK sits outside the EEA terms."},"quotes":[{"id":"uk-enrolment-routes","claim":"The UK consumer page offers three enrolment routes, one of which costs no money but requires syncing PC settings to Microsoft's cloud, and one of which spends Rewards points.","sourceUrl":"https://www.microsoft.com/en-gb/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Microsoft publishes no sterling price on the UK page. It gives only '$30 USD or local currency equivalent plus applicable tax'. A pound figure would have to come from the in-Windows purchase flow, which this study does not measure, so none is published here.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"eea-free-route","claim":"In the EEA the no-cost route requires only that the user signs in and stays signed in with a Microsoft account. There is no settings-sync and no Rewards requirement.","sourceUrl":"https://www.microsoft.com/en-ie/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Ireland is used as the English-language EEA variant of the page. The German (de-de) page was also captured.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"eea-60-day-signin","claim":"The EEA no-cost route carries a sign-in condition: stop signing in with that Microsoft account and updates stop within up to 60 days, after which you must re-enrol.","sourceUrl":"https://www.microsoft.com/en-ie/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"eea-paid-route-local-account","claim":"In the EEA the 30 USD purchase exists as the route for people who want to keep using a local account rather than stay signed in.","sourceUrl":"https://www.microsoft.com/en-ie/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"The source is a two-part list item: a heading and the route beneath it. The colon in square brackets is editorial, added here to join them; it is not in Microsoft's text.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"regional-variation-statement","claim":"Microsoft acknowledges the regional difference in enrolment options but states the updates themselves are identical everywhere.","sourceUrl":"https://www.microsoft.com/en-us/windows/end-of-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"This FAQ entry appears on Microsoft's en-US page. It is not on the en-GB page or the en-IE consumer ESU page in the 2026-09-20 snapshot, so it is quoted as a US-page statement rather than as a UK or Irish one.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"eea-country-list","claim":"Microsoft's own list of the countries subject to the EEA terms has 36 entries. It includes Switzerland, which is not an EEA member, and five French overseas territories. The United Kingdom is not on it.","sourceUrl":"https://blogs.windows.com/windowsexperience/2025/06/24/stay-secure-with-windows-11-copilot-pcs-and-windows-365-before-support-ends-for-windows-10/","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"This endnote is the cleanest sourced basis for 'the UK is outside the EEA terms'. Switzerland is in EFTA but not the EEA - Microsoft's inclusion of it is worth a footnote.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"uk-licence-10-devices","claim":"One consumer ESU licence covers up to 10 devices.","sourceUrl":"https://www.microsoft.com/en-gb/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"euroconsumers-concession","claim":"Euroconsumers, a European consumer-group alliance, states that Microsoft agreed to a no-cost EEA ESU option without the backup or Rewards conditions, and frames it as a Digital Markets Act Article 6(6) concern.","sourceUrl":"https://www.euroconsumers.org/wp-content/uploads/2025/09/Euroconsumers_vs_Microsoft_092025.pdf","licence":"Euroconsumers published position letter (PDF on their own site, robots.txt allows all). No open licence stated. Quoted here as a short attributed quotation; not redistributed.","note":"Letter dated Brussels, 22/09/2025, to Microsoft Ireland Operations Ltd, replying to Microsoft's response to a Euroconsumers letter of 29 July 2025. Addressee and signatories are named in the PDF; their names are deliberately omitted here. This is Euroconsumers' characterisation of what Microsoft agreed - it is not a Microsoft statement.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."}],"caveats":["The brief for this study assumed the UK route costs money and the EEA route does not. Microsoft's published pages do not support that, and the claim is not made.","The Euroconsumers letter cited here mis-cites the Digital Markets Act as Regulation (EU) 2022/2065, which is the Digital Services Act. The DMA is Regulation (EU) 2022/1925. The error is flagged so this study does not repeat it, and its companion citation, Directive (EU) 2019/770, is correct.","A device-count figure in the same letter is sourced to a commercial reseller's blog rather than to any measurement, and its sentence is garbled in the original. It is not used.","Individuals named in that letter are deliberately not carried into this study or its dataset."]},{"id":"what-a-non-esu-pc-still-gets","heading":"What a non-ESU PC still gets, and what it does not","body":["A Windows 10 22H2 machine without ESU is not cut off from everything. Microsoft Defender Antivirus security intelligence updates continue through October 2028. Microsoft Edge and the WebView2 Runtime keep updating on 22H2 until at least October 2028 and do not require ESU. Microsoft 365 Apps keep receiving security updates to 10 October 2028, though feature updates stop, and the OneDrive desktop app keeps updating on 22H2 to the same date.","Microsoft itself makes the point that antivirus definitions are not a substitute for operating system fixes. What stops without ESU is technical support, feature updates and quality updates including security and reliability fixes - which is exactly the 1486 fixes counted here."],"quotes":[{"id":"still-gets-defender","claim":"Microsoft Defender Antivirus security intelligence (definition) updates continue on Windows 10 through October 2028, with or without ESU.","sourceUrl":"https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/end-of-windows-10-support-what-defender-customers-need-to-know/4461349","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"The Tech Community article body is rendered in the browser and is absent from a direct fetch of the article URL. The wording quoted here was confirmed against the Internet Archive capture of 8 September 2026, which carries the full body, and again against Microsoft's own RSS feed for that blog board. 'Customers without Defender' means without Microsoft Defender for Endpoint, the paid product.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"defender-caveat","claim":"Microsoft states plainly that definition updates do not compensate for missing OS fixes.","sourceUrl":"https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/end-of-windows-10-support-what-defender-customers-need-to-know/4461349","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Confirmed against the Internet Archive capture of 8 September 2026 and against Microsoft's own RSS feed for that blog board; the article URL itself renders its body in the browser, so a direct fetch does not carry it. It is Microsoft, not this study, making the point that antivirus definitions are not a substitute for operating-system fixes.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"still-gets-edge","claim":"Microsoft Edge and the WebView2 Runtime keep updating on Windows 10 22H2 until at least October 2028, and ESU is not required for them.","sourceUrl":"https://learn.microsoft.com/en-us/deployedge/microsoft-edge-supported-operating-systems","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"'the end of the ESU program' here means the end of commercial Year 3, October 2028.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"still-gets-m365","claim":"Microsoft 365 Apps on Windows 10 keep receiving security updates until 10 October 2028, but feature updates stop at Version 2608.","sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365-apps/end-of-support/windows-10-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"still-gets-onedrive","claim":"The OneDrive desktop app keeps updating on Windows 10 22H2 through 10 October 2028, but not on older Windows 10 versions.","sourceUrl":"https://learn.microsoft.com/en-us/microsoft-365-apps/end-of-support/windows-10-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"does-not-get","claim":"Without ESU, Microsoft provides no technical support, no feature updates and no quality updates including security and reliability fixes.","sourceUrl":"https://www.microsoft.com/en-us/windows/end-of-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."}]},{"id":"dates","heading":"The dates, and what changes next","body":["Consumer ESU was extended by a year in June 2026 and now runs to 12 October 2027. The extension was announced as an editor's note appended to a blog post from June 2025 rather than as a standalone announcement, which is why older write-ups still give 13 October 2026.","Commercial ESU runs in three purchasable years: Year 1 ends 13 October 2026, Year 2 ends 12 October 2027, Year 3 ends 10 October 2028. It is cumulative - buying Year 2 means paying for Year 1 as well.","So nothing counted here expires in the weeks after publication. The next date that changes the picture for a household is 12 October 2027, when consumer ESU ends and these monthly fixes stop reaching consumer machines entirely. For a business the next date is 13 October 2026, the end of commercial Year 1.","One thing the count does not mean: that these fixes are gone for good. Microsoft's UK consumer page states that a device can be enrolled at any time up to 12 October 2027, and Microsoft states that Windows quality updates are cumulative, each one built on the updates before it. So the figure here is what a machine has not received to date, not a permanent hole in it. What this study does not test is whether any particular enrolment delivers any particular earlier fix - that would need the update itself, which is not measured here."],"quotes":[{"id":"w10-eos-date","claim":"Windows 10 Home and Pro, and version 22H2, retired on 14 October 2025 (lifecycle table records 10/15/2025 06:59:59, i.e. end of 14 October US Pacific).","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/products/windows-10-home-and-pro","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Microsoft's lifecycle tables are timestamped in a US time zone, so the retirement date reads as 10/15/2025 06:59:59. Everywhere else Microsoft writes 14 October 2025.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"consumer-esu-coverage-start","claim":"Consumer ESU coverage starts 15 October 2025 - the day after end of support - which is exactly the start of the study's CVE window.","sourceUrl":"https://blogs.windows.com/windowsexperience/2025/06/24/stay-secure-with-windows-11-copilot-pcs-and-windows-365-before-support-ends-for-windows-10/","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"consumer-esu-end-2027","claim":"AS AT 20 SEPTEMBER 2026 consumer ESU runs to 12 October 2027, NOT 13 October 2026. Microsoft extended it by a year in June 2026.","sourceUrl":"https://www.microsoft.com/en-us/windows/end-of-support","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Same statement on the en-GB end-of-support page with British date order ('12 October, 2027'). The consumer ESU page carries it as 'You can enroll in ESU any time until the program ends on October 12, 2027.' This contradicts the study brief, which assumed consumer ESU ends 13 October 2026.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"consumer-esu-extension-announcement","claim":"The extension was announced on 25 June 2026 as an editor's note appended to a June 2025 Windows Experience Blog post, not as a standalone announcement.","sourceUrl":"https://blogs.windows.com/windowsexperience/2025/06/24/stay-secure-with-windows-11-copilot-pcs-and-windows-365-before-support-ends-for-windows-10/","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Typographic apostrophe in the original normalised to ASCII here.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"commercial-esu-years","claim":"Commercial ESU has three years: Year 1 ends 13 October 2026, Year 2 ends 12 October 2027, Year 3 ends 10 October 2028.","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/faq/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Table columns: Products | End of Extended Support/ESU Start Date | ESU End Year 1 | Year 2 | Year 3 | Type of Security Update. The brief's 'commercial enrolment to 12 Oct 2027' is Year 2, not the end of the programme.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"commercial-esu-editions","claim":"Commercial ESU qualifying editions are Enterprise, Education and Pro in commercial use.","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/faq/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":null,"quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"commercial-price","claim":"Commercial ESU is 61 USD per device for Year One via Volume Licensing and doubles each consecutive year, to a maximum of three years.","sourceUrl":"https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"The [...] marks one intervening sentence removed - a cross-reference to another Microsoft page - so the two priced sentences read together. ESU is also cumulative: 'If you decide to purchase the program in Year Two, you have to pay for Year One too, as ESUs are cumulative.' Same page.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"consumer-esu-enrol-any-time-gb","claim":"Enrolment in consumer ESU is not closed. Microsoft's UK consumer page states that a device can be enrolled at any time up to 12 October 2027, so a machine that has not received these fixes to date is not permanently shut out of them.","sourceUrl":"https://www.microsoft.com/en-gb/windows/extended-security-updates","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"This is the UK-facing wording, with the British spelling of 'programme' and British date order. The en-US page carries the same statement as 'the program ends on October 12, 2027'.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"quality-updates-cumulative","claim":"Windows quality updates are cumulative, so a later update carries the fixes from the updates before it. This is why the count here is what a machine has not received to date rather than a set of fixes it can never get.","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/faq/windows","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Microsoft states the servicing property in general terms. This study does not test whether any particular enrolment delivers any particular earlier fix; that would need the update itself, which is not measured here.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."}],"keyDates":[{"date":"2025-10-14","what":"Windows 10 Home and Pro, and version 22H2, retired"},{"date":"2025-10-15","what":"consumer ESU coverage begins; this study's window opens"},{"date":"2026-10-13","what":"commercial ESU Year 1 ends"},{"date":"2027-10-12","what":"consumer ESU ends; commercial ESU Year 2 ends"},{"date":"2028-10-10","what":"commercial ESU Year 3 ends"}]},{"id":"other-windows-versions","heading":"Other Windows versions, and a footnote on Windows 11","body":["1478 of the 1486 fixes also apply to Windows 11, which is 99.5 per cent of them. Only 8 are Windows 10 only - too few to express as a share. A Windows 11 machine on a version still in support received these same fixes as part of its ordinary monthly update. Windows 11 versions that are themselves out of support did not, and this study does not test which version any machine was on.","The traffic runs the other way too. In the same window Microsoft published 263 CVEs affecting Windows 11 whose records do not name Windows 10 22H2 at all, out of 1,745 affecting Windows 11 in total. That is absence from Microsoft's affected list, not a statement that Windows 10 is unaffected. They are not counted as fixes a Windows 10 machine missed, because Microsoft does not name it as affected.","1485 of the 1486 also name Windows 10 Version 21H2 (build 19044, which is also Enterprise and IoT LTSC 2021). Those products are not in this study's population, and for good reason in both directions: Home and Pro 21H2 went out of support on 14 June 2023 and cannot enrol in ESU at all, because ESU requires 22H2; Enterprise LTSC 2021 is still supported into January 2027 and IoT Enterprise LTSC 2021 into January 2032, so those machines are getting the fixes free."],"findings":[{"label":"also affects Windows 11","n":1478,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":99.5,"pctWithheld":false},{"label":"Windows 10 only, not Windows 11","n":8,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 8, fewer than 10; no percentage is published on a count this small"},{"label":"also affects Windows 10 Version 21H2 or LTSC 2021","n":1485,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":99.9,"pctWithheld":false},{"label":"also affects a Windows Server product","n":1465,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":98.6,"pctWithheld":false}],"windows11Only":{"n":263,"denominator":1745,"denominatorLabel":"Microsoft-CNA CVEs in the window naming any Windows 11 product","pct":15.1},"quotes":[{"id":"population-21h2-correction","claim":"CORRECTION TO THE BRIEF: Windows 10 21H2 is NOT supported to 12 January 2027. Home and Pro 21H2 ended 14 June 2023; Enterprise and Education 21H2 ended 12 June 2024. 21H2 machines receive nothing at all and cannot enrol in ESU, which requires 22H2.","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/products/windows-10-home-and-pro","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"Enterprise and Education 21H2: 6/12/2024 6:59:59 AM, from learn-lifecycle-w10-enterprise.html. The 12 January 2027 date in the brief belongs to Enterprise LTSC 2021, not to 21H2.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."},{"id":"population-ltsc-2021","claim":"Windows 10 Enterprise LTSC 2021 is supported to 13 January 2027. Windows 10 IoT Enterprise LTSC 2021 runs to 14 January 2032. Both are correctly excluded from the study population.","sourceUrl":"https://learn.microsoft.com/en-us/lifecycle/products/windows-10-enterprise-ltsc-2021","licence":"Microsoft documentation / website terms. Quoted here as a short attributed quotation for identification and comment; the page text and the cached copy are not redistributed.","note":"IoT Enterprise LTSC 2021: mainstream 1/13/2027, extended 1/14/2032, from learn-lifecycle-w10-iot-ltsc-2021.html. The study brief says '12 Jan 2027'; the lifecycle table timestamp 1/13/2027 06:59:59 corresponds to 12 January 2027 US Pacific. Both readings trace to the same row - state the row, not a bare date.","quotedTextOmitted":"Quoted on the study page under the source’s own terms; not redistributed here. Follow sourceUrl for the original wording."}],"briefCorrection":"An earlier draft of this study's brief excluded 21H2 on the grounds that it is 'supported free to 12 January 2027'. That is wrong. 21H2 is excluded because it is out of support entirely and cannot enrol in ESU. The 12 January 2027 date belongs to Enterprise LTSC 2021, which is excluded for the opposite reason."}],"internalLinks":[{"href":"/windows-10-end-of-life-calculator","label":"Windows 10 end-of-life calculator","why":"work out what an estate of Windows 10 machines costs to carry or replace"},{"href":"/server-end-of-life","label":"Server end-of-life checker","why":"the same question for server hardware and operating systems"},{"href":"/windows-server-eol-cost-calculator","label":"Windows Server end-of-support cost calculator","why":"Windows Server 2016 reaches the same point on 12 January 2027"}],"novelty":{"claim":"The individual pieces are public. Microsoft's Security Update Guide has a product filter, so a determined person could approximate this count by hand month by month; the CISA KEV catalogue is a free download; and third-party services already list Windows 10 CVEs with a KEV overlay. What this study adds is the combination, dated and hashed: a single published filter over the CVE Program's own records rather than NVD's enrichment, scoped to the exact affected-array string 'Windows 10 Version 22H2', with the fixes the free 14 October 2025 update already delivered removed, the exploitation overlay joined on with days from publication to listing, and the whole dataset downloadable so the count can be disputed.","priorWork":[{"what":"Microsoft Security Update Guide","url":"https://msrc.microsoft.com/update-guide","differs":"Microsoft publishes the monthly documents and a product filter, but no cumulative count since end of support, no exploitation overlay, and no downloadable frozen series. Its rows also carry no open licence."},{"what":"CISA Known Exploited Vulnerabilities catalogue","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","differs":"CISA publishes exploitation status across all vendors, not scoped to a Windows version and not joined to publication dates, so it does not answer how many of one product's missed fixes were for flaws already under attack."},{"what":"CVE Program cvelistV5 bulk release","url":"https://github.com/CVEProject/cvelistV5","differs":"The bulk release is the raw material used here. It is not filtered to any product and carries no analysis."},{"what":"OpenCVE, Microsoft Windows 10 product listing","url":"https://app.opencve.io/cve/?product=windows_10&vendor=microsoft","differs":"Checked on 20 September 2026: OpenCVE lists 7,456 CVEs for Microsoft Windows 10, with a query builder that filters on KEV status, EPSS, CVSS and date, and a CSV export. It matches on the NVD/CPE product 'windows_10' rather than on Microsoft's own affected-array string 'Windows 10 Version 22H2', so it does not separate 22H2 from 21H2 and the LTSC editions; it is not scoped to the window that opens when support ended; it does not remove the fixes the free 14 October 2025 update already delivered; and it is a live index rather than a frozen, hashed series carrying days from publication to KEV listing."},{"what":"Senserva, Microsoft Patch Tracker","url":"https://senserva.com/microsoft-patch-tracker.html","differs":"Checked on 20 September 2026: Senserva tracks 1,088 Microsoft security updates fixing 3,880 CVEs, of which it says 319 close a vulnerability CISA lists as under active attack, refreshed twice a day with CSV and JSON export. It ranks Microsoft's updates across products rather than counting one Windows version, is not scoped to the post-end-of-support window, and does not exclude fixes a non-ESU machine did receive, so its counts answer a different question from this one."}],"notClaimed":"No claim is made that this is the first count of its kind, and none that the study is maintained: it is a single frozen snapshot, and no refresh cadence is committed to here. A search for a published series of this kind - a cumulative count of post-end-of-support Windows 10 22H2 fixes with an exploitation overlay - was run on 20 September 2026 and found none. That is the claim: none was found, not that none exists."}},"data":{"monthly":[{"month":"2025-11","monthLabel":"November 2025","publicationDates":["2025-11-11"],"n":32,"cumulative":32,"shareOfTotalPct":2.2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6575"],"outOfBand":[]},{"month":"2025-12","monthLabel":"December 2025","publicationDates":["2025-12-09"],"n":29,"cumulative":61,"shareOfTotalPct":2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6575","10.0.19045.6691"],"outOfBand":[]},{"month":"2026-01","monthLabel":"January 2026","publicationDates":["2026-01-13"],"n":70,"cumulative":131,"shareOfTotalPct":4.7,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6809"],"outOfBand":[]},{"month":"2026-02","monthLabel":"February 2026","publicationDates":["2026-02-10"],"n":24,"cumulative":155,"shareOfTotalPct":1.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.6937"],"outOfBand":[]},{"month":"2026-03","monthLabel":"March 2026","publicationDates":["2026-03-10"],"n":43,"cumulative":198,"shareOfTotalPct":2.9,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7058"],"outOfBand":[]},{"month":"2026-04","monthLabel":"April 2026","publicationDates":["2026-04-14"],"n":105,"cumulative":303,"shareOfTotalPct":7.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7184","10.0.19045.7548"],"outOfBand":[]},{"month":"2026-05","monthLabel":"May 2026","publicationDates":["2026-05-12"],"n":53,"cumulative":356,"shareOfTotalPct":3.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7417"],"outOfBand":[]},{"month":"2026-06","monthLabel":"June 2026","publicationDates":["2026-06-09"],"n":91,"cumulative":447,"shareOfTotalPct":6.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7417"],"outOfBand":[]},{"month":"2026-07","monthLabel":"July 2026","publicationDates":["2026-07-14","2026-07-16"],"n":313,"cumulative":760,"shareOfTotalPct":21.1,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7548"],"outOfBand":["2026-07-16"]},{"month":"2026-08","monthLabel":"August 2026","publicationDates":["2026-08-11"],"n":158,"cumulative":918,"shareOfTotalPct":10.6,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7663"],"outOfBand":[]},{"month":"2026-09","monthLabel":"September 2026","publicationDates":["2026-09-08"],"n":568,"cumulative":1486,"shareOfTotalPct":38.2,"denominator":1486,"denominatorLabel":"all fixes a non-ESU 22H2 PC did not receive in the window","firstFixedBuilds":["10.0.19045.7725"],"outOfBand":[]}],"volatility":{"months":11,"median":70,"min":24,"minMonth":"2026-02","max":568,"maxMonth":"2026-09","mean":135.1,"rateClaimWithheld":true,"rateClaimWithheldReason":"Monthly values run from 24 to 568, a factor of 23.7. A single 'growing by N a month' figure would misdescribe the series, so the median and the full range are published instead and no rate is claimed. The window is about eleven and a quarter months, but October 2025 contributes nothing - its Patch Tuesday fell on the 14th, the last day of free support - so the median, mean and range are computed over the eleven months that carry a Patch Tuesday inside the window."},"monthlyConcentration":[{"month":"2025-11","n":32,"distinctComponents":23,"largestComponent":"DirectX Graphics Kernel","largestComponentN":3,"largestComponentPct":9.4,"topFiveN":13,"topFivePct":40.6},{"month":"2025-12","n":29,"distinctComponents":16,"largestComponent":"Windows Projected File System","largestComponentN":5,"largestComponentPct":17.2,"topFiveN":16,"topFivePct":55.2},{"month":"2026-01","n":70,"distinctComponents":41,"largestComponent":"Windows Management Services","largestComponentN":12,"largestComponentPct":17.1,"topFiveN":27,"topFivePct":38.6},{"month":"2026-02","n":24,"distinctComponents":16,"largestComponent":"Windows Hyper-V","largestComponentN":4,"largestComponentPct":16.7,"topFiveN":13,"topFivePct":54.2},{"month":"2026-03","n":43,"distinctComponents":30,"largestComponent":"Windows Graphics Component","largestComponentN":4,"largestComponentPct":9.3,"topFiveN":16,"topFivePct":37.2},{"month":"2026-04","n":105,"distinctComponents":58,"largestComponent":"Windows Ancillary Function Driver for WinSock","largestComponentN":8,"largestComponentPct":7.6,"topFiveN":31,"topFivePct":29.5},{"month":"2026-05","n":53,"distinctComponents":33,"largestComponent":"Windows TCP/IP","largestComponentN":8,"largestComponentPct":15.1,"topFiveN":21,"topFivePct":39.6},{"month":"2026-06","n":91,"distinctComponents":47,"largestComponent":"Remote Desktop Client","largestComponentN":9,"largestComponentPct":9.9,"topFiveN":31,"topFivePct":34.1},{"month":"2026-07","n":313,"distinctComponents":143,"largestComponent":"Windows Kernel","largestComponentN":25,"largestComponentPct":8,"topFiveN":73,"topFivePct":23.3},{"month":"2026-08","n":158,"distinctComponents":76,"largestComponent":"Windows Telephony Service","largestComponentN":12,"largestComponentPct":7.6,"topFiveN":45,"topFivePct":28.5},{"month":"2026-09","n":568,"distinctComponents":184,"largestComponent":"Windows Biometric Service","largestComponentN":64,"largestComponentPct":11.3,"topFiveN":140,"topFivePct":24.6}],"cvssSeverity":[{"label":"Critical","n":38,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.6,"pctWithheld":false},{"label":"High","n":1102,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":74.2,"pctWithheld":false},{"label":"Medium","n":343,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":23.1,"pctWithheld":false},{"label":"Low","n":3,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 3, fewer than 10; no percentage is published on a count this small"}],"vulnerabilityTypes":[{"label":"Elevation of Privilege","n":888,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":59.8,"pctWithheld":false},{"label":"Remote Code Execution","n":235,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":15.8,"pctWithheld":false},{"label":"Information Disclosure","n":225,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":15.1,"pctWithheld":false},{"label":"Denial of Service","n":61,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.1,"pctWithheld":false},{"label":"Security Feature Bypass","n":47,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":3.2,"pctWithheld":false},{"label":"Tampering","n":17,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Spoofing","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false}],"componentFamilies":[{"label":"Networking and protocols","n":286,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":19.2,"pctWithheld":false},{"label":"File systems and storage","n":251,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":16.9,"pctWithheld":false},{"label":"Authentication and identity","n":152,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":10.2,"pctWithheld":false},{"label":"Graphics, fonts and imaging","n":123,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8.3,"pctWithheld":false},{"label":"Kernel and Win32k","n":119,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8,"pctWithheld":false},{"label":"Management and servicing","n":119,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":8,"pctWithheld":false},{"label":"Shell and user interface","n":107,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":7.2,"pctWithheld":false},{"label":"Audio, video and media","n":69,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.6,"pctWithheld":false},{"label":"Devices and drivers","n":64,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.3,"pctWithheld":false},{"label":"Remote Desktop and RDP","n":64,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.3,"pctWithheld":false},{"label":"COM, RPC and scripting","n":37,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.5,"pctWithheld":false},{"label":"Boot and platform security","n":36,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.4,"pctWithheld":false},{"label":"Hyper-V and virtualisation","n":27,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.8,"pctWithheld":false},{"label":"Printing and scanning","n":26,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.7,"pctWithheld":false},{"label":"Office file handling in Windows","n":3,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 3, fewer than 10; no percentage is published on a count this small"},{"label":"Third-party silicon mitigations","n":2,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 2, fewer than 10; no percentage is published on a count this small"},{"label":"Other Windows component","n":1,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":null,"pctWithheld":true,"pctWithheldReason":"n = 1, fewer than 10; no percentage is published on a count this small"}],"largestComponents":[{"label":"Windows Biometric Service","n":65,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4.4,"pctWithheld":false},{"label":"Windows NTFS","n":60,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":4,"pctWithheld":false},{"label":"Windows Kernel","n":54,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":3.6,"pctWithheld":false},{"label":"Windows Ancillary Function Driver for WinSock","n":40,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.7,"pctWithheld":false},{"label":"Windows Win32k","n":33,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":2.2,"pctWithheld":false},{"label":"Windows Routing and Remote Access Service (RRAS)","n":23,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.5,"pctWithheld":false},{"label":"Windows TCP/IP","n":21,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.4,"pctWithheld":false},{"label":"Win32k","n":20,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Windows Hyper-V","n":20,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Remote Desktop Client","n":19,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.3,"pctWithheld":false},{"label":"Microsoft Standard XPS","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Cloud Files Mini Filter Driver","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Spaceport.sys","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Telephony Service","n":18,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.2,"pctWithheld":false},{"label":"Windows Installer","n":17,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Windows Projected File System","n":16,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1.1,"pctWithheld":false},{"label":"Windows Device Association Service","n":15,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":1,"pctWithheld":false},{"label":"DirectX Graphics Kernel","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows File Explorer","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Management Services","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Remote Desktop Services","n":14,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Graphics Component","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Windows Push Notifications","n":13,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.9,"pctWithheld":false},{"label":"Microsoft Windows Media Foundation","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false},{"label":"Windows Hello","n":12,"denominator":1486,"denominatorLabel":"all fixes in the population","pct":0.8,"pctWithheld":false}],"kev":[{"cveId":"CVE-2025-62221","title":"Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability","component":"Windows Cloud Files Mini Filter Driver","componentFamily":"File systems and storage","vulnType":"Elevation of Privilege","datePublic":"2025-12-09","kevDateAdded":"2025-12-09","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Use After Free Vulnerability","kevShortDescription":"Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-20805","title":"Desktop Window Manager Information Disclosure Vulnerability","component":"Desktop Window Manager","componentFamily":"Graphics, fonts and imaging","vulnType":"Information Disclosure","datePublic":"2026-01-13","kevDateAdded":"2026-01-13","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Information Disclosure Vulnerability","kevShortDescription":"Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":5.5,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-21510","title":"Windows Shell Security Feature Bypass Vulnerability","component":"Windows Shell","componentFamily":"Shell and user interface","vulnType":"Security Feature Bypass","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Shell Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":8.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21513","title":"MSHTML Framework Security Feature Bypass Vulnerability","component":"MSHTML Framework","componentFamily":"COM, RPC and scripting","vulnType":"Security Feature Bypass","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":8.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21519","title":"Desktop Window Manager Elevation of Privilege Vulnerability","component":"Desktop Window Manager","componentFamily":"Graphics, fonts and imaging","vulnType":"Elevation of Privilege","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Type Confusion Vulnerability","kevShortDescription":"Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-21525","title":"Windows Remote Access Connection Manager Denial of Service Vulnerability","component":"Windows Remote Access Connection Manager","componentFamily":"Networking and protocols","vulnType":"Denial of Service","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows NULL Pointer Dereference Vulnerability","kevShortDescription":"Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":6.2,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-21533","title":"Windows Remote Desktop Services Elevation of Privilege Vulnerability","component":"Windows Remote Desktop Services","componentFamily":"Remote Desktop and RDP","vulnType":"Elevation of Privilege","datePublic":"2026-02-10","kevDateAdded":"2026-02-10","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Improper Privilege Management Vulnerability","kevShortDescription":"Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-68820","title":"Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability","component":"Windows Ancillary Function Driver for WinSock","componentFamily":"Networking and protocols","vulnType":"Elevation of Privilege","datePublic":"2026-08-11","kevDateAdded":"2026-08-11","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","kevShortDescription":"Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-85880","title":"Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability","component":"Windows Advanced Local Procedure Call (ALPC)","componentFamily":"Kernel and Win32k","vulnType":"Elevation of Privilege","datePublic":"2026-09-08","kevDateAdded":"2026-09-08","daysPublicationToKevListing":0,"kevVulnerabilityName":"Microsoft Windows Heap-Based Buffer Overflow Vulnerability","kevShortDescription":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7.8,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2025-62215","title":"Windows Kernel Elevation of Privilege Vulnerability","component":"Windows Kernel","componentFamily":"Kernel and Win32k","vulnType":"Elevation of Privilege","datePublic":"2025-11-11","kevDateAdded":"2025-11-12","daysPublicationToKevListing":1,"kevVulnerabilityName":"Microsoft Windows Race Condition Vulnerability","kevShortDescription":"Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":7,"cvssBaseSeverity":"HIGH"},{"cveId":"CVE-2026-32202","title":"Windows Shell Spoofing Vulnerability","component":"Windows Shell","componentFamily":"Shell and user interface","vulnType":"Spoofing","datePublic":"2026-04-14","kevDateAdded":"2026-04-28","daysPublicationToKevListing":14,"kevVulnerabilityName":"Microsoft Windows Protection Mechanism Failure Vulnerability","kevShortDescription":"Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":4.3,"cvssBaseSeverity":"MEDIUM"},{"cveId":"CVE-2026-33824","title":"Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability","component":"Windows Internet Key Exchange (IKE) Service Extensions","componentFamily":"Networking and protocols","vulnType":"Remote Code Execution","datePublic":"2026-04-14","kevDateAdded":"2026-08-18","daysPublicationToKevListing":126,"kevVulnerabilityName":"Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability","kevShortDescription":"Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.","knownRansomwareCampaignUse":"Unknown","cvssBaseScore":9.8,"cvssBaseSeverity":"CRITICAL"}],"exploitationSignals":{"cisaKev":12,"microsoftExploitedFlag":11,"overlap":11},"platformOverlap":{"alsoWindows11":1478,"windows10Only":8,"also21h2OrLtsc2021":1485,"alsoWindowsServer":1465,"denominator":1486},"microsoftOwnFigures":{"note":"Cited from Microsoft's Security Update Guide, not reproduced: aggregate counts only. No per-CVE row from that source appears in the published dataset or here.","total":1500,"monthly":{"2025-Nov":36,"2025-Dec":31,"2026-Jan":72,"2026-Feb":24,"2026-Mar":43,"2026-Apr":106,"2026-May":54,"2026-Jun":93,"2026-Jul":313,"2026-Aug":160,"2026-Sep":568},"severity":{"Important":1399,"Critical":99,"Moderate":2},"exploitedFlagCount":11,"cvesWithoutAShipped22h2Fix":0}},"caveats":["As at 20 September 2026. CVE records are revised continuously, so counts for past months rise over time. Everything here is computed from a frozen, hashed snapshot of the CVE Program's bulk release of 20 September 2026 and the CISA KEV catalogue v2026.09.18. Re-running the same filter on a later release will give a larger number, which is a property of the source, not a correction to this one.","Microsoft's own monthly documents are living documents too. All twelve carry a current release date in September 2026 while their version field still reads 1.0 - the October 2025 document was last revised on 19 September 2026.","1,486 is a floor. It counts Microsoft-CNA records only; Microsoft's own list for the same months is 1,500, and the difference is fully explained but not folded in.","12 is a floor. The CISA KEV catalogue lists only what CISA has confirmed and chosen to publish, it is US-centric, and listings are retroactive.","Absence of a product from a CVE record's affected array is absence, not a claim that the product is unaffected. This matters for any reasoning about what Windows 10 does not have.","Monthly counts swing from 24 to 568, so no monthly rate is published. The median and the full range are published instead, computed over the eleven months that carry a Patch Tuesday inside the window; October 2025 contributes nothing, because its Patch Tuesday fell on the 14th, the last day of free support.","September 2026 is a part month: it covers the 8 September Patch Tuesday, not the whole calendar month, and October's Patch Tuesday falls after the snapshot.","The severity figures come from two different scales. CVSS v3.1 in the dataset is the Microsoft CNA's own score inside the CVE record, not NVD's. Microsoft's Critical/Important rating is a separate scale and is cited from the Security Update Guide, not reproduced.","NVD was not used. The National Vulnerability Database's 'configurations' data lags and undercounts affected products - applying it to September 2026 would have halved that month. No NVD API key was registered and no NVD data is in this study.","Component families are assigned by a rule list parsed from Microsoft's own CVE titles. The rule list is published in the analysis scripts so the classification can be disputed. Some assignments are defensible but arguable.","Microsoft spells some component names several ways across months, and seven CVE titles in this set contain Microsoft's typo 'Vulernability'. Both are handled, and the raw component string is kept in the dataset alongside the merged family.","This study can say which build first carried each fix, because Microsoft states it in the CVE record. It does not map builds to KB numbers or release dates: that would need the Security Update Guide, which is cited here rather than reproduced.","Nothing here says Windows 10 was left without a patch. Microsoft shipped a fix for every CVE counted. The measurement is about which machines received it.","This is a count of what a machine has not received to date, not a permanent gap. Microsoft's UK consumer page states that a device can be enrolled in consumer ESU at any time until the programme ends on 12 October 2027, and Microsoft states that Windows quality updates are cumulative. Whether any particular enrolment delivers any particular earlier fix is not tested here.","This is a count of fixes, not a measure of risk to any individual machine. Most of these flaws require code already running on the device. No claim is made that any particular PC was attacked.","No personal data is present. The dataset contains CVE identifiers, Microsoft product and component strings, builds, dates and scores. Researcher acknowledgements in Microsoft's source documents were never read into any output, and individuals named in a cited consumer-group letter are not carried into the dataset or the page."],"disagreements":[{"id":"cve-program-vs-microsoft-total","question":"How many fixes were missed?","positions":[{"source":"CVE Program v5, Microsoft-CNA records only","value":1486,"basis":"Records the Microsoft CNA itself owns, whose affected array names Windows 10 Version 22H2, minus four already fixed by the free 14 October 2025 update."},{"source":"Microsoft Security Update Guide (CVRF v3.0), cited not reproduced","value":1500,"basis":"Every CVE Microsoft's own monthly documents list as affecting Windows 10 Version 22H2."}],"difference":14,"differencePctOfMicrosoftTotal":0.93,"resolved":false,"explanation":"All 14 of them are individually accounted for and none is a filter error. 10 are not Microsoft-CNA records at all: their CVE records are assigned by CERT/CC (3), MITRE (3), GitHub (2), AMD (1) and Arm (1), and Microsoft relays them because a Microsoft update carries the fix. The other four were already fixed by the free 14 October 2025 update. The CVE Program set is a strict subset of Microsoft's: nothing is in this study's population and absent from Microsoft's list. All fourteen are named below, in the dataset README and in this study's JSON.","nonMicrosoftCnaDivergences":[{"cve":"CVE-2023-31096","assignerShortName":"mitre"},{"cve":"CVE-2024-55414","assignerShortName":"mitre"},{"cve":"CVE-2025-10263","assignerShortName":"Arm"},{"cve":"CVE-2025-54518","assignerShortName":"AMD"},{"cve":"CVE-2025-64720","assignerShortName":"GitHub_M"},{"cve":"CVE-2025-65018","assignerShortName":"GitHub_M"},{"cve":"CVE-2026-25250","assignerShortName":"mitre"},{"cve":"CVE-2026-6726","assignerShortName":"certcc"},{"cve":"CVE-2026-6727","assignerShortName":"certcc"},{"cve":"CVE-2026-8863","assignerShortName":"certcc"}],"howReported":"Both numbers are published. 1486 is the verified floor from the redistributable source; 1500 is Microsoft's own figure and is cited, not reproduced.","divergentCveCount":{"non_microsoft_cna":10,"stage2_exclusion":4,"unexplained":0}},{"id":"monthly-two-per-cent-gate","question":"Does the study's own pre-publication divergence gate pass?","positions":[{"source":"Gate as written: any month diverging by more than 2 per cent against Microsoft blocks publication","value":"trips on 4 months: 2025-11, 2025-12, 2026-01, 2026-06"},{"source":"The same months in absolute counts","value":"4, 2, 2 and 2 CVEs"}],"resolved":false,"explanation":"This gate was set before the data was pulled, as a condition that would block publication. It tripped on four months. On months of 24 to 36 CVEs a single record is worth 3 to 4 per cent, so the percentage gate is tripped by arithmetic on small denominators, not by a defect: the absolute differences are 4, 2, 2 and 2 CVEs. Every divergent CVE is named in the table below, in the dataset README and in this study's JSON, and all fourteen are accounted for. Publication proceeded on that basis. The gate is reported as tripped and the reason published, rather than the gate being quietly restated.","monthly":[{"month":"2025-11","microsoft_security_update_guide":36,"cve_program_v5_floor":32,"difference":4,"divergence_pct_of_microsoft_month":11.11,"over_2pct_gate":true,"divergent_cves":["CVE-2025-62208","CVE-2025-62209","CVE-2025-64720","CVE-2025-65018"]},{"month":"2025-12","microsoft_security_update_guide":31,"cve_program_v5_floor":29,"difference":2,"divergence_pct_of_microsoft_month":6.45,"over_2pct_gate":true,"divergent_cves":["CVE-2025-64679","CVE-2025-64680"]},{"month":"2026-01","microsoft_security_update_guide":72,"cve_program_v5_floor":70,"difference":2,"divergence_pct_of_microsoft_month":2.78,"over_2pct_gate":true,"divergent_cves":["CVE-2023-31096","CVE-2024-55414"]},{"month":"2026-02","microsoft_security_update_guide":24,"cve_program_v5_floor":24,"difference":0,"divergence_pct_of_microsoft_month":0,"over_2pct_gate":false,"divergent_cves":[]},{"month":"2026-03","microsoft_security_update_guide":43,"cve_program_v5_floor":43,"difference":0,"divergence_pct_of_microsoft_month":0,"over_2pct_gate":false,"divergent_cves":[]},{"month":"2026-04","microsoft_security_update_guide":106,"cve_program_v5_floor":105,"difference":1,"divergence_pct_of_microsoft_month":0.94,"over_2pct_gate":false,"divergent_cves":["CVE-2026-25250"]},{"month":"2026-05","microsoft_security_update_guide":54,"cve_program_v5_floor":53,"difference":1,"divergence_pct_of_microsoft_month":1.85,"over_2pct_gate":false,"divergent_cves":["CVE-2025-54518"]},{"month":"2026-06","microsoft_security_update_guide":93,"cve_program_v5_floor":91,"difference":2,"divergence_pct_of_microsoft_month":2.15,"over_2pct_gate":true,"divergent_cves":["CVE-2025-10263","CVE-2026-8863"]},{"month":"2026-07","microsoft_security_update_guide":313,"cve_program_v5_floor":313,"difference":0,"divergence_pct_of_microsoft_month":0,"over_2pct_gate":false,"divergent_cves":[]},{"month":"2026-08","microsoft_security_update_guide":160,"cve_program_v5_floor":158,"difference":2,"divergence_pct_of_microsoft_month":1.25,"over_2pct_gate":false,"divergent_cves":["CVE-2026-6726","CVE-2026-6727"]},{"month":"2026-09","microsoft_security_update_guide":568,"cve_program_v5_floor":568,"difference":0,"divergence_pct_of_microsoft_month":0,"over_2pct_gate":false,"divergent_cves":[]}]},{"id":"exploitation-signals","question":"How many of these flaws were being exploited?","positions":[{"source":"CISA Known Exploited Vulnerabilities catalogue, v2026.09.18","value":12,"basis":"Added by CISA on evidence of exploitation, at any time after publication."},{"source":"Microsoft's own 'Exploited: Yes' flag in the Security Update Guide, cited not reproduced","value":11,"basis":"Set by Microsoft at publication and not reliably updated afterwards."}],"resolved":false,"explanation":"These are different measures and neither is a superset by definition. Here they overlap on 11 CVEs. CISA lists 1 that Microsoft did not flag at publication (CVE-2026-33824), which CISA added 126 days later; Microsoft flags 0 that CISA has not listed (none).","overlap":["CVE-2025-62215","CVE-2025-62221","CVE-2026-20805","CVE-2026-21510","CVE-2026-21513","CVE-2026-21519","CVE-2026-21525","CVE-2026-21533","CVE-2026-32202","CVE-2026-68820","CVE-2026-85880"],"kevOnly":["CVE-2026-33824"],"microsoftFlagOnly":[]},{"id":"brief-vs-data","question":"Does the study's own pre-registered headline survive the data?","positions":[{"source":"Study brief, pre-registered floor","value":1204},{"source":"Study brief, alternative estimate using Microsoft's own affected lists","value":"about 1,500"},{"source":"This analysis, CVE Program v5","value":1486},{"source":"This analysis, Microsoft's own count, cited","value":1500}],"resolved":true,"explanation":"The pre-registered floor of 1,204 does not survive. 8 of the 11 months match it within one CVE; November 2025 and December 2025 are two out; and September 2026 is 285 out, where the brief expected 283 and the CVE records give 568. The brief's own alternative estimate, about 1,500 from Microsoft's affected lists, is what the data supports. The published figure is 1,486. Every month is set out against the brief below. This is recorded rather than quietly corrected, because the brief was written before the data was pulled and the filter is published so anyone can recount.","monthlyAgainstBrief":[{"month":"2025-11","study_brief_pre_registered":34,"this_analysis":32,"difference":-2},{"month":"2025-12","study_brief_pre_registered":31,"this_analysis":29,"difference":-2},{"month":"2026-01","study_brief_pre_registered":70,"this_analysis":70,"difference":0},{"month":"2026-02","study_brief_pre_registered":24,"this_analysis":24,"difference":0},{"month":"2026-03","study_brief_pre_registered":42,"this_analysis":43,"difference":1},{"month":"2026-04","study_brief_pre_registered":104,"this_analysis":105,"difference":1},{"month":"2026-05","study_brief_pre_registered":53,"this_analysis":53,"difference":0},{"month":"2026-06","study_brief_pre_registered":91,"this_analysis":91,"difference":0},{"month":"2026-07","study_brief_pre_registered":313,"this_analysis":313,"difference":0},{"month":"2026-08","study_brief_pre_registered":159,"this_analysis":158,"difference":-1},{"month":"2026-09","study_brief_pre_registered":283,"this_analysis":568,"difference":285}]},{"id":"esu-severity-scope","question":"Does ESU deliver every one of these fixes?","positions":[{"source":"Microsoft's ESU documentation","value":"Critical and Important security updates only, of four MSRC severity levels"},{"source":"Microsoft's Security Update Guide for these months","value":"2 of 1500 are rated Moderate, and all 1500 carry a shipped 22H2 fix in the monthly cumulative update"}],"resolved":false,"explanation":"The documentation bounds ESU by severity; the update mechanics do not obviously allow a Moderate-rated fix to be stripped out of a cumulative update that also carries Critical and Important ones. Nothing Microsoft publishes settles it either way, so both are stated and no claim is made that ESU subscribers miss anything."}],"method":{"unitOfAnalysis":"One CVE.","population":"Every CVE published by the Microsoft CNA between 15 October 2025 and 20 September 2026 whose CVE Program v5 record names \"Windows 10 Version 22H2\" as a vulnerable component, excluding those the free update of 14 October 2025 had already fixed.","inclusionTest":"cveMetadata.assignerShortName == 'microsoft' AND cveMetadata.state == 'PUBLISHED' AND containers.cna.datePublic >= 2025-10-15 AND containers.cna.affected[] contains an entry with product == 'Windows 10 Version 22H2' (exact string, case-insensitive) carrying a versions[] item with status 'affected'.","exclusions":[{"rule":"E1 - named but not affected","test":"22H2 named in affected[] but no versions[] item with status 'affected'","removed":0},{"rule":"E2 - wrong build family","test":"22H2 first-fixed build outside the 10.0.19045.* family, i.e. a data artefact","removed":0},{"rule":"E3 - already fixed before support ended","test":"first fixed at or below build 10.0.19045.6456, the free 14 October 2025 update, so a non-ESU PC did receive the fix","removed":4,"cves":["CVE-2025-62208","CVE-2025-62209","CVE-2025-64679","CVE-2025-64680"],"note":"This rule was not in the study brief and is necessary. Any recount that skips it lands on 1,490 rather than 1,486."},{"rule":"E4 - serviced outside ESU","test":"component delivered outside the Windows monthly cumulative update AND first fixed at a build other than that Patch Tuesday's","removed":0,"note":"Yield zero, and the zero is the finding. Ten candidates exist - SQL Server ODBC driver, Windows WebView, Defender Firewall Service, some Office-named entries, WDAC OLE DB, Device Health Attestation. Every one carries the same Windows 10 22H2 first-fixed build as the rest of its Patch Tuesday, so all ten ship in the Windows monthly cumulative update, which is exactly what ESU delivers. Excluding them on component name alone would have silently dropped ten in-scope fixes. Microsoft Defender Antivirus proper, Edge and WebView2 never name Windows 10 Version 22H2 at all and so never entered the set."},{"rule":"E5 - running-on artefact","test":"every windows_10_22H2 cpeMatch marked vulnerable:false, i.e. 22H2 is only the host platform","removed":0,"note":"Yield zero. All 3,101 in-window records carry cpeApplicability and every 22H2 cpeMatch across the matched set is vulnerable:true. Running-on artefacts do exist elsewhere in the data, such as Internet Explorer 11 on Windows 10 Version 1903, which is why a substring match on '22H2' would be wrong: it would also pull in 'Windows 11 version 22H2'."}],"cveSchemaSemantics":"Across all 33,881 affected[] entries in the 3,101 in-window Microsoft records, the only version status Microsoft uses is 'affected' and defaultStatus is never set. Presence of the exact product string in containers.cna.affected is therefore itself the vulnerable-component claim. Every Windows 10 Version 22H2 entry - all 1,490 of them - uses versionType 'custom', with version = the first affected build and lessThan = the first fixed build. 231 of the 33,881 entries carry no versionType at all: they are cloud-service products such as Microsoft Entra and Azure Key Vault, written as version '-' with no lessThan. None of them is a Windows 10 entry, so a recount is unaffected, but a recounter who assumes versionType is always present will hit them.","lastFreeBuild":"The boundary build 10.0.19045.6456 is derived inside the CVE data, not taken from an outside claim: 91 Microsoft-CNA CVEs dated 14 October 2025 give that value as the Windows 10 22H2 lessThan. September 2025 gives 6332 and July 2025 gives 6093, confirming the progression.","kevJoin":"Exact match on CVE identifier between the published dataset and the cveID field of the CISA KEV catalogue. Lag is KEV dateAdded minus CVE datePublic in whole days; it is date-only arithmetic and cannot resolve hours. The join was cross-checked against the CISA-ADP SSVC Exploitation field carried inside the CVE records, and against a hand check of every entry against the raw catalogue.","classification":"Component family and vulnerability type are parsed from Microsoft's own CVE titles by an ordered rule list published in stage2_filter.py.","crossCheck":"Monthly totals were recounted against Microsoft's own Security Update Guide, by three independent routes within that source: matching on product id, matching on product name string, and counting CVEs carrying a 22H2 vendor-fix KB. All three agree for every month.","percentages":"Every percentage states its denominator. No percentage is published on a count below 10; those cuts say so. Percentages are rounded to one decimal place and may not sum to 100.","revisions":"Both primary sources are revised continuously. This study freezes and hashes them at 2026-09-20 and carries that date on every figure.","noNetwork":"The analysis script performs no network access. It reads the frozen local snapshot only, so it produces identical output on every run."},"sources":[{"id":"cve-program-v5","name":"CVE Program, CVE List V5 daily bulk release","role":"primary - the affected-product claim comes from Microsoft's own CNA record, with no enrichment lag","url":"https://github.com/CVEProject/cvelistV5","release":"cve_2026-09-20_0300Z, published 2026-09-20T03:28:48Z","retrieved":"2026-09-20T04:18Z","sha256":"3f226d290571eee431b48efd26cf5e7efbd5a1dc11c224e835e8c087edaadbc0","records":"395,554 CVE records scanned; 15,414 Microsoft-CNA at all dates; 3,101 PUBLISHED in the window","licence":"CVE Program Terms of Use (SPDX: cve-tou)","licenceUrl":"https://www.cve.org/Legal/TermsOfUse","redistributable":true,"condition":"Perpetual, worldwide, royalty-free, irrevocable licence to reproduce, prepare derivative works of, display and distribute, including commercial use, conditional on reproducing MITRE's copyright designation AND this licence in any copy. Both ship with the download: the designation on the CSV's first line, the licence text in the README and in windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt beside the CSV.","licenceText":"CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge,\nroyalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly\ndisplay, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE(R)).\nAny copy you make for such purposes is authorized provided that you reproduce MITRE's copyright\ndesignation and this license in any such copy.\n\nDISCLAIMERS\n\nALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN PROVIDED BY MITRE ARE PROVIDED ON AN \"AS IS\"\nBASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE\nCORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS\nOR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL\nNOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR\nPURPOSE.","licenceFile":"/research/windows-10-missed-security-fixes-2026-LICENCE-CVE-PROGRAM.txt"},{"id":"cisa-kev","name":"CISA Known Exploited Vulnerabilities catalog","role":"exploitation overlay","url":"https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json","release":"catalogVersion 2026.09.18, released 2026-09-18T19:00:05Z, 1,716 entries","retrieved":"2026-09-20T04:18:41Z","sha256":"7b770a6f5eb1d47a7176ef2f1428594551399912c8f3b5d2bf0f562b7e745e06","licence":"CC0 1.0 Universal","licenceUrl":"https://www.cisa.gov/sites/default/files/licenses/kev/license.txt","redistributable":true,"condition":"Fully redistributable. Does not authorise use of the CISA logo or DHS seal and is not an endorsement."},{"id":"msrc-cvrf","name":"Microsoft Security Update Guide, CVRF v3.0 monthly documents","role":"cross-check only - monthly totals, Microsoft's own severity rating, and confirmation that every fix shipped","url":"https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Sep","release":"twelve monthly documents, October 2025 to September 2026","retrieved":"2026-09-20, requests spaced 35 seconds apart with an identifying user agent","licence":"No open licence. Microsoft site terms.","redistributable":false,"condition":"Quoted and attributed, not redistributed: aggregate counts only. No per-CVE row from this source is reproduced. The per-month lists of divergent CVE identifiers are derived by diffing Microsoft's list against this study's, and are identifiers, not Microsoft's rows."},{"id":"microsoft-esu-docs","name":"Microsoft Learn and microsoft.com - Extended Security Updates, lifecycle and end-of-support pages","role":"ESU scope, eligibility, dates, enrolment routes and the UK/EEA difference","url":"https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates","retrieved":"2026-09-20","licence":"Microsoft documentation and website terms","redistributable":false,"condition":"Short attributed quotation only. Cached pages are kept as evidence and are not published."},{"id":"euroconsumers","name":"Euroconsumers, letter to Microsoft Ireland Operations Ltd, 22 September 2025","role":"one consumer-group characterisation of the EEA concession, used for context only","url":"https://www.euroconsumers.org/wp-content/uploads/2025/09/Euroconsumers_vs_Microsoft_092025.pdf","retrieved":"2026-09-20","licence":"No open licence stated","redistributable":false,"condition":"Cite only. Individuals named in the letter are not carried into this study. One legal citation in the letter is wrong and one figure in it is unusable; both are flagged on the page rather than repeated."},{"id":"nvd","name":"NVD CVE API 2.0","role":"not used","url":"https://services.nvd.nist.gov/rest/json/cves/2.0","licence":"n/a","redistributable":false,"condition":"Deliberately not used. NVD's configurations data lags and would have undercounted the most recent month by roughly half. No NVD API key was registered."}],"verification":{"howToCheckThisStudy":"Everything below can be recomputed from the published CSV alone, except the items marked as needing the original sources. The filter is published so a journalist can recount from the CVE Program's own bulk release.","recompute":[{"what":"the headline count","expected":1486,"from":"the published CSV","how":"count data rows, excluding the three leading '#' comment lines and the header"},{"what":"no duplicate CVE identifiers","expected":1486,"from":"the published CSV","how":"count distinct cve_id"},{"what":"monthly counts","expected":{"2025-11":32,"2025-12":29,"2026-01":70,"2026-02":24,"2026-03":43,"2026-04":105,"2026-05":53,"2026-06":91,"2026-07":313,"2026-08":158,"2026-09":568},"from":"the published CSV","how":"group by patch_month and count"},{"what":"monthly median, minimum and maximum","expected":[70,24,568],"from":"the published CSV","how":"median, min and max of the monthly counts"},{"what":"CVEs in the CISA KEV catalogue","expected":12,"from":"the published CSV","how":"count rows where in_cisa_kev is true"},{"what":"days from publication to KEV listing","expected":[0,0,0,0,0,0,0,0,0,1,14,126],"from":"the published CSV","how":"sorted values of kev_days_publication_to_listing where in_cisa_kev is true"},{"what":"KEV entries listed on the day the fix shipped","expected":9,"from":"the published CSV","how":"count rows where kev_days_publication_to_listing = 0"},{"what":"no KEV entry carries CISA's 'Known' ransomware flag","expected":0,"from":"the published CSV","how":"count rows where kev_known_ransomware_campaign_use = 'Known'"},{"what":"CVSS severity split","expected":{"CRITICAL":38,"HIGH":1102,"LOW":3,"MEDIUM":343},"from":"the published CSV","how":"group by cvss_v3_1_base_severity and count; buckets must sum to the headline"},{"what":"component family league table","expected":{"Networking and protocols":286,"File systems and storage":251,"Authentication and identity":152,"Graphics, fonts and imaging":123,"Kernel and Win32k":119,"Management and servicing":119,"Shell and user interface":107,"Audio, video and media":69,"Devices and drivers":64,"Remote Desktop and RDP":64,"COM, RPC and scripting":37,"Boot and platform security":36,"Hyper-V and virtualisation":27,"Printing and scanning":26,"Office file handling in Windows":3,"Third-party silicon mitigations":2,"Other Windows component":1},"from":"the published CSV","how":"group by component_family and count; must sum to the headline"},{"what":"no row was already fixed by the last free build","expected":0,"from":"the published CSV","how":"count rows where w10_22h2_first_fixed_build <= 10.0.19045.6456"},{"what":"Windows 11 overlap","expected":1478,"from":"the published CSV","how":"count rows where also_affects_windows_11 is true"},{"what":"the KEV catalogue join itself","expected":12,"from":"the original CISA KEV catalogue, CC0, free to download","how":"download the catalogue, match its cveID values against the CSV's cve_id, count matches. Note that KEV listings are added over time, so a later catalogue will match more."},{"what":"the population filter from source","expected":1486,"from":"the CVE Program cvelistV5 bulk release","how":"apply method.inclusionTest and the five exclusion rules. A recount that omits rule E3 will land on 1,490, which is the expected divergence, not a defect."},{"what":"each row's source record","expected":"byte-identical","from":"the CVE Program record for any cve_id","how":"the CSV carries cve_record_sha256 for every row, the SHA-256 of the CVE v5 JSON record as it stood in the frozen bulk release. Later revisions of a record will hash differently; that is revision drift, not an error."}],"knownDivergences":[{"what":"a recount that omits exclusion rule E3","willGive":1490,"reason":"four CVEs published in November and December 2025 were already fixed by the free 14 October 2025 update, so a non-ESU PC did receive them"},{"what":"a recount against Microsoft's Security Update Guide","willGive":1500,"reason":"Microsoft also relays fixes whose CVE records belong to other CNAs. The CVE Program set is a strict subset; all fourteen differences are named on the page."},{"what":"a recount using NVD 'configurations' rather than the CVE v5 CNA affected array","willGive":"materially lower, roughly half for the most recent month","reason":"NVD enrichment lags behind publication. This study does not use NVD."},{"what":"a recount against a later CVE Program release","willGive":"higher","reason":"CVE records are revised continuously and past-month counts rise."}],"assertionsRun":[{"check":"population size matches the Stage 2 filter report","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"no duplicate CVE ids in the population","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"every record is dated on or after the free-support cut-off","expected":true,"observed":true,"passed":true,"note":"datePublic strictly after 14 October 2025, i.e. inside the window that opens 15 October 2025"},{"check":"no record was already fixed by the last free build","expected":0,"observed":0,"passed":true,"note":"exclusion rule E3"},{"check":"monthly counts sum to the population","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"monthly counts match the Stage 2 filter report","expected":{"2025-11":32,"2025-12":29,"2026-01":70,"2026-02":24,"2026-03":43,"2026-04":105,"2026-05":53,"2026-06":91,"2026-07":313,"2026-08":158,"2026-09":568},"observed":{"2025-11":32,"2025-12":29,"2026-01":70,"2026-02":24,"2026-03":43,"2026-04":105,"2026-05":53,"2026-06":91,"2026-07":313,"2026-08":158,"2026-09":568},"passed":true,"note":""},{"check":"CVSS severity buckets sum to the population","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"every record carries a Microsoft CNA CVSS v3.1 base score","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"vulnerability types sum to the population","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"component families sum to the population","expected":1486,"observed":1486,"passed":true,"note":""},{"check":"no single component accounts for more than a fifth of any month","expected":[],"observed":[],"passed":true,"note":"the evidence against a 'big months are one component in a batch' claim"},{"check":"KEV catalogue count field matches its own array length","expected":1716,"observed":1716,"passed":true,"note":""},{"check":"KEV join and the CISA-ADP SSVC 'active' flag agree on the same CVE set","expected":["CVE-2025-62215","CVE-2025-62221","CVE-2026-20805","CVE-2026-21510","CVE-2026-21513","CVE-2026-21519","CVE-2026-21525","CVE-2026-21533","CVE-2026-32202","CVE-2026-33824","CVE-2026-68820","CVE-2026-85880"],"observed":["CVE-2025-62215","CVE-2025-62221","CVE-2026-20805","CVE-2026-21510","CVE-2026-21513","CVE-2026-21519","CVE-2026-21525","CVE-2026-21533","CVE-2026-32202","CVE-2026-33824","CVE-2026-68820","CVE-2026-85880"],"passed":true,"note":"two independent routes to K"},{"check":"KEV lag vector reproduces the pre-registered value","expected":[0,0,0,0,0,0,0,0,0,1,14,126],"observed":[0,0,0,0,0,0,0,0,0,1,14,126],"passed":true,"note":""},{"check":"no KEV entry in the population carries CISA's 'Known' ransomware flag","expected":[],"observed":[],"passed":true,"note":"blocks any ransomware framing"},{"check":"Windows 11 overlap matches the Stage 2 filter report","expected":1478,"observed":1478,"passed":true,"note":""},{"check":"Microsoft's own severity buckets sum to Microsoft's own total","expected":1500,"observed":1500,"passed":true,"note":""},{"check":"every CVE in Microsoft's own 22H2 list carries a shipped 22H2 fix","expected":0,"observed":0,"passed":true,"note":"the evidence that Microsoft fixed all of them - so 'unpatched' is the wrong word"},{"check":"the EEA country count is the length of Microsoft's own list","expected":36,"observed":36,"passed":true,"note":"no duplicate entries in the endnote"},{"check":"every pre-registered month is accounted for against the data","expected":11,"observed":11,"passed":true,"note":""},{"check":"every non-Microsoft-CNA divergence has a recorded assigner","expected":["CVE-2023-31096","CVE-2024-55414","CVE-2025-10263","CVE-2025-54518","CVE-2025-64720","CVE-2025-65018","CVE-2026-25250","CVE-2026-6726","CVE-2026-6727","CVE-2026-8863"],"observed":["CVE-2023-31096","CVE-2024-55414","CVE-2025-10263","CVE-2025-54518","CVE-2025-64720","CVE-2025-65018","CVE-2026-25250","CVE-2026-6726","CVE-2026-6727","CVE-2026-8863"],"passed":true,"note":"so the divergence list can be checked record by record"}],"assertionsPassed":21,"assertionsFailed":0},"compliance":{"outboundContact":"none. No emails, requests, surveys or notices were sent to anyone.","scraping":"no vendor or retailer store was accessed; no prices or stock were collected. Public endpoints only, with an identifying user agent, requests spaced and raw responses cached so nothing was fetched twice. robots.txt was read for every host and honoured, including blogs.windows.com's Crawl-delay of 10 seconds. One fetch is worth stating: a single request to Microsoft Tech Community's board RSS feed at /t5/s/gxcuf89792/rss/board. That host's robots.txt disallows /gxcuf89792/rss, which does not match the path fetched under RFC 9309 prefix matching, but the rule is plainly aimed at that feed. The two quotations it was fetched for are confirmed against the Internet Archive capture of 8 September 2026 instead, and that capture is what the study cites.","personalData":"none in any output. Researcher acknowledgements in Microsoft's documents were never parsed; individuals named in the cited Euroconsumers letter are not carried into the dataset or the page.","namedOrganisations":"no organisation is identified as insecure. The unit is a Microsoft product version, not a customer."}}