Microsoft Extends Windows 10 ESU Support to October 2027
Article Content
- •Microsoft extended Windows 10 ESU support until October 12, 2027.
- •Enrollment is open until the new deadline, requiring a Microsoft account.
- •Devices not signed in with a Microsoft account may lose update access after 60 days.
Microsoft has extended the Windows 10 Extended Security Updates (ESU) program for consumers by one year, allowing enrolled devices to receive critical security updates until October 12, 2027. This extension was quietly announced through updates to Microsoft's documentation and a blog post. The ESU program is designed for users transitioning to Windows 11 and provides critical security updates for Windows 10, version 22H2. Enrollment remains open until October 12, 2027, and users must sign in with a Microsoft account to maintain coverage. Devices that do not remain signed in may lose access to updates after 60 days. The program does not include technical support or feature enhancements. Microsoft emphasizes the importance of enrolling to reduce vulnerabilities during the transition period.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How do I enroll in the ESU program?
What happens if I don't enroll by October 12, 2027?
Are there any costs associated with ESU enrollment?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…