Windows Latest’s central point—that the remaining Windows 10 population is unusually resistant to migration—is supported by Lansweeper’s report and by comments from HP. But its reading of the Extended Security Updates data reverses a critical denominator. The difference changes the immediate security assessment for administrators.
Windows 11 became generally available on October 5, 2021, meaning Tuesday, August 11, 2026 is four years and 10 months after launch—not quite five years. That is a minor calendar error. The more consequential correction is that the holdouts are increasingly concentrated in machines that are expensive, certified, embedded, or otherwise difficult to replace, rather than ordinary PCs that Microsoft can shift with another full-screen upgrade prompt.
The migration worked—until it reached the hard cases
Lansweeper’s July report is based on a subset of millions of assets across tens of thousands of active customer sites. Its numbers are not a worldwide Windows market-share census, and should not be presented as one. They are nevertheless valuable because they are based on discovered IT assets rather than browser traffic, a meaningful distinction when the question is what enterprises actually still have connected to their networks.
The pattern in that dataset is stark. Windows 10 dropped from around 50% in mid-2025 to the low-to-mid 40% range when support ended, then down to 18.6% by June 2026 and 16.9% in the latest snapshot. Windows 11 now represents 78.8%.
That is a rapid migration by any enterprise desktop standard. It is also why the remaining 16.9% needs to be understood differently. The easy devices—eligible PCs with standard applications, normal replacement cycles, and no regulatory dependency—have largely moved. What remains is more likely to be tied to point-of-sale deployments, medical equipment, industrial systems, retail kiosks, rugged handhelds, or a line-of-business application whose supplier has not certified Windows 11.
The Register independently reported the same Lansweeper findings and quoted the company’s principal technical evangelist, Esben Dochy, describing vendor dependency, certification gaps, cost, and accepted risk as reasons these systems remain in place. Those are not obstacles a Windows Update banner can solve.
Lansweeper’s sector data bears that out. Healthcare and pharmaceuticals have the highest share of Windows 10 devices at 23.0%, followed by consumer and retail at 22.7%. Manufacturing sits at 18.0%, while small and midsize businesses trail the overall migration rate with 21.4% of their Windows machines still on Windows 10.
HP’s own investor call offers a separate, though broader and vendor-specific, indication that the refresh is unfinished. During HP’s fiscal 2026 second-quarter call in May, CFO Karen Parkhill said roughly 30% of HP’s installed base was still on Windows 10. That figure cannot be directly compared with Lansweeper’s 16.9% because HP is measuring its own installed base rather than a cross-vendor set of discovered enterprise devices. Still, both point to the same commercial reality: a substantial replacement opportunity remains, especially in regions and segments that delayed their refresh.
Microsoft has also acknowledged that the Windows 10 end-of-support deadline created a temporary sales tailwind. In its fiscal 2026 third-quarter call, Microsoft said Windows OEM revenue was expected to decline in the high teens in the following quarter, citing roughly six percentage points of impact from comparison against the prior year’s Windows 10 end-of-support benefit. Microsoft also cited falling channel inventory and higher memory-driven PC prices. The company is not publishing a Windows 10-versus-Windows 11 installed-base breakdown, but it plainly sees the deadline-driven surge as a finite event.
The ESU math in Windows Latest is backwards
Windows Latest says that, out of the roughly 17% of devices still on Windows 10, “about 14% are receiving ESU patches,” leaving “roughly 2%” unprotected. That interpretation is unsupported by the corroborating reporting.
The Register reports that 14% of Windows 10 assets in Lansweeper’s figures have Extended Security Updates patches applied. That is 14% of the remaining Windows 10 estate, not 14 percentage points of the entire Windows estate.
If Lansweeper’s 16.9% Windows 10 share and The Register’s 14% ESU figure are read together, the arithmetic points in the opposite direction:
- Roughly 2.4% of all Windows assets in the Lansweeper sample would be Windows 10 devices with ESU patches applied.
- Roughly 14.5% of all Windows assets would be Windows 10 devices without a recorded ESU patch, before accounting for systems on still-supported LTSC servicing tracks or devices that are isolated from normal patching.
That does not prove every remaining machine is exposed to the internet or immediately vulnerable. Some may be segmented, air-gapped, covered by another servicing arrangement, or run a supported Windows 10 LTSC edition. But it means no administrator should take the “only 2% are unpatched” conclusion from Windows Latest as a reassuring estimate.
The practical task is to verify each device’s exact edition, version, servicing channel, patch level, ESU entitlement, and network exposure. “Windows 10” is no longer a sufficient inventory category.
Microsoft’s current consumer ESU page says eligible Windows 10 version 22H2 Home, Pro, Pro Education, and Pro for Workstations PCs can receive critical and important security updates through October 12, 2027. Enrollment is free for users who sync PC settings, available for 1,000 Microsoft Rewards points, or costs $30; one consumer license can cover up to 10 devices.
Commercial coverage is different. Microsoft’s lifecycle documentation provides three annual ESU periods for Windows 10 through October 10, 2028, with later ESU years requiring purchase of earlier coverage. Consumer ESU is also explicitly unavailable for devices in kiosk mode, Active Directory-joined devices, Microsoft Entra-joined devices, and MDM-managed devices, although Entra-registered devices may qualify. Those exclusions matter because many of the most stubborn Windows 10 deployments are precisely the centrally managed or special-purpose machines for which consumer ESU is not an option.
The vulnerability comparison is a warning, not an OS scorecard
Lansweeper says a Windows 10 device in its dataset carries an average of 1,903 active CVEs, compared with 652 for Windows 11—a 2.9-times gap. It also says 66.6% of those Windows 10 CVEs are rated high or critical, while 2.4% are known to have been exploited in the wild.
Those numbers should be read as asset-risk measurements, not as a claim that Windows 10 itself contains 1,903 separate operating-system flaws. Lansweeper’s platform inventories the software and vulnerability exposure associated with a device. A Windows 10 endpoint can also be older hardware with older applications, drivers, browsers, runtimes, and management agents; Windows 11 devices tend to be newer and more recently refreshed. The comparison is still operationally useful, but it does not isolate the operating system as the sole cause.
The security implication is more concrete. Standard Windows 10 servicing ended in October 2025, while Windows 11 continues to receive monthly fixes. Where a vulnerability affects both platforms but only Windows 11 receives a patch, the supported build can reveal valuable information to attackers studying what remains unfixed on Windows 10. Lansweeper calls this patch diffing.
ESU changes that picture for enrolled devices by delivering critical and important Windows security updates, but it does not deliver feature improvements, ordinary bug fixes, or technical support. It is time purchased for a migration plan, not proof that a legacy deployment is sustainably maintained.
Hardware eligibility is only part of the problem
The Windows 11 hardware baseline—particularly TPM 2.0, Secure Boot capability, and supported processor requirements—remains a genuine barrier for some PCs. Lansweeper estimates that 2.8% of Windows 10 devices in its observed estate cannot move to Windows 11 because of hardware constraints. The percentage rises to 7.8% in consumer and retail and 6.1% in transport and logistics.
Yet the data also shows why “buy new PCs” is an incomplete answer. Healthcare has a 23.0% Windows 10 share but only 1.1% of its Windows 10 fleet is classified by Lansweeper as unable to migrate on hardware grounds. In that sector, the obstacle is more often application validation, clinical-device certification, operational scheduling, or the cost of taking a system out of service.
For IT teams, the correct prioritization is therefore not simply “replace every noncompliant CPU.” The first devices to address are Windows 10 endpoints without ESU or another valid servicing path that are reachable from ordinary user networks, handle sensitive data, expose remote access, or sit in a privileged administrative workflow. The second group is hardware-ineligible devices that need budget approval and a replacement lead time. The third is vendor-locked equipment that requires an explicit exception, compensating controls, and a supplier-backed retirement date.
Microsoft has moved the mass market. Its Windows 10 end-of-support deadline helped shift a large share of PCs, and the OEM refresh cycle did the rest. The stubborn residue is now a security and asset-management problem with a long tail—and the corrected ESU arithmetic suggests that tail is far less protected than the Windows Latest article implies.