security vulnerabilities

Winsage
July 22, 2026
A study by Lansweeper found that Windows 10 PCs have an average of 1,903 active security vulnerabilities, while Windows 11 systems have only 652 vulnerabilities. As of June 2026, nearly 20% of Windows PCs in the U.S. are still using Windows 10, despite Microsoft ceasing regular updates for it. Users can enroll in the Extended Security Updates (ESU) program for continued security updates until October 12, 2027. Security experts have urged users to upgrade to Windows 11 due to increasing vulnerabilities in Windows 10, while some data privacy experts recommend staying with Windows 10 for as long as possible.
Winsage
July 22, 2026
Approximately 17% of all Windows client devices are still running Windows 10, equating to about one in six machines. Windows 11 accounts for 78% of Windows devices, with third-party trackers indicating it surpassed 70% of desktop share as of February 2026. Official support for Windows 10 ended in October 2025, but Microsoft’s Extended Security Updates (ESU) program will provide patches until October 2027 for eligible devices. A typical Windows 10 device has an average of 1,903 active security vulnerabilities, nearly three times the 652 CVE-tracked flaws found on a Windows 11 machine. 66% of Windows 10 vulnerabilities are classified as "high" or "critical." Small and medium enterprises have 21.4% of their Windows devices still on Windows 10, while larger enterprises have 16.6%. The healthcare and pharmaceuticals sectors have 23% of devices on Windows 10, followed by consumer and retail at 22%, and manufacturing at 18%. Lansweeper is urging organizations to enroll in the ESU program and address reasons for remaining on Windows 10 as 2026 approaches.
Winsage
July 20, 2026
Users may experience double reboots when installing substantial Windows updates, such as the April and July 2026 Updates, due to factors like Secure Boot and .NET Framework updates. The July 2026 .NET Framework update specifically requires a separate reboot. Microsoft is still rolling out the Secure Boot 2023 certificate update, which may also lead to multiple reboots. Users are advised not to panic during these reboots and to allow the system time to complete the installation process. Additionally, Microsoft has warned against delaying updates for more than three days due to increasing update sizes related to security vulnerabilities. Some users may encounter SCEP certificate errors in the Event Viewer after the July 2026 Update, but these errors do not indicate a failure of the update process.
Winsage
July 20, 2026
The latest Windows Insider update, KB5101650, is the first to use artificial intelligence to identify and address security vulnerabilities, featuring 570 patches aimed at enhancing system security. Users have reported various display and graphics problems, including performance dips and graphical glitches, following the update. Microsoft has temporarily halted the update for certain Dell PCs due to compatibility issues affecting performance and power consumption. Users are experiencing difficulties reverting the update, and there are concerns about a drop in refresh rates from 400 Hz to 240 Hz.
Winsage
July 18, 2026
Approximately 16.9% of Windows client devices are still using Windows 10, which has three times more active Common Vulnerabilities and Exposures (CVEs) than Windows 11, totaling 1,903 compared to 652. Two-thirds of the vulnerabilities in Windows 10 are classified as high or critical, with an exploitable rate 1.7 times greater than in Windows 11. Migration to Windows 11 is not primarily hindered by technical limitations, as only a small fraction of Windows 10 devices do not meet the hardware requirements. Additionally, nearly 20% of monitored Windows devices are running end-of-life operating systems, including Windows 7, 8.1, and XP.
Winsage
July 17, 2026
Microsoft's July update, KB5101650, is temporarily withheld for certain Dell PCs using Intel Innovation Platform Framework (IPF) drivers due to compatibility issues. Affected devices are experiencing performance problems such as crashes, reduced efficiency, overheating, and battery drain. Microsoft has acknowledged the incompatibility and is working on a fix, expecting to release the update for affected devices soon. The issues may be linked to the optional June update, KB5095093, which was not widely adopted. Specific Dell models impacted by these issues have not been disclosed.
Winsage
July 16, 2026
Approximately 16.9 percent of monitored Windows devices are still running Windows 10, a decline from about half a year ago. Windows 10 will receive updates until October 12, 2027, for consumer devices and until October 10, 2028, for commercial customers. Small and medium-sized businesses (SMBs) have 21.4 percent of their machines on Windows 10, with 23 percent in healthcare and pharmaceutical sectors and 22.7 percent in consumer and retail. A Windows 10 device has an average of 1,903 active Common Vulnerabilities and Exposures (CVEs), compared to 652 on Windows 11. Only 14 percent of Windows 10 assets have Extended Security Updates (ESU) patches applied. Many devices are tied to vendor certifications that complicate upgrades, and the rising cost of new PC hardware is a concern. The stagnation of Windows 11 adoption continues, with minimal change in market share distribution.
Winsage
July 16, 2026
Support for Windows 10 version 22H1 will end on August 15, 2026. Users on this version may face challenges with OneDrive synchronization and will not receive new features, security updates, or bug fixes after the cutoff date. Users are encouraged to upgrade to Windows 10 22H2 to maintain functionality and security, with continued access to OneDrive and updates until October 10, 2028.
Winsage
July 16, 2026
Microsoft has released its July 2026 Patch Tuesday updates, addressing 570 new security vulnerabilities, bringing the total for the month to over 620. The cumulative count of vulnerabilities patched this year has reached 1,380, exceeding the total of 1,250 for the entire year of 2020. Over 400 vulnerabilities are related to various versions of Windows, and the Windows 10 Extended Security Update program has been extended until October 12, 2027. Notable vulnerabilities include CVE-2026-56155 in Active Directory Federation Services, which allows attackers to gain administrator rights, and several critical Remote Code Execution vulnerabilities, including CVE-2026-57092 in Hyper-V and CVE-2026-56190 in Remote Desktop Protocol. Microsoft has also patched 97 vulnerabilities in Office products, with 17 classified as critical RCE vulnerabilities, and four vulnerabilities in Exchange Server, including CVE-2026-55008. The latest Microsoft Edge update addresses 27 vulnerabilities related to Chromium, and a vulnerability in Minecraft Bedrock servers has been patched.
Winsage
July 16, 2026
Microsoft will introduce a new registry policy in Windows 11 in July 2026 that allows IT administrators to enable automatic acceptance of single sign-on (SSO) prompts on managed devices. This policy will streamline user authentication by using Windows sign-in credentials automatically for Microsoft apps or services, reducing the need for manual authentication. The registry path for this policy is HKLMSOFTWAREPoliciesMicrosoftWindowsAAD, with the value AutoAcceptSsoPermission (DWORD) set to 1. It can be deployed using Group Policy Objects (GPO), Intune, Microsoft Configuration Manager, or mobile device management (MDM) tools. This setting is applicable only to Windows 11 versions 25H2 and 24H2 that have received the July 2026 Patch Tuesday updates (KB5101650 and KB5094126) and is designed for managed devices using Entra ID accounts, not personal Microsoft accounts or unmanaged devices.
Search