Windows 10 End of Support Raises Risk
Windows 10 support ended October 14, 2025, leaving unpatched systems increasingly exposed to exploited vulnerabilities including ransomware-linked flaws.
IPA (Japan's Information-technology Promotion Agency) issued an advisory warning that Windows 10 (GAC editions: Enterprise, Education, Home, Pro, and IoT Enterprise) reached end of support on October 14, 2025. Microsoft will no longer provide security updates for the affected editions, and users are urged to migrate to supported successor OS versions or enroll in the paid Extended Security Updates (ESU) program, which Microsoft has extended for consumers through October 12, 2027.
The advisory highlights that CISA's Known Exploited Vulnerabilities (KEV) catalog listed 41 actively exploited Windows OS vulnerabilities disclosed since 2024 (as of end-September 2025), a 26-vulnerability increase since October 2024, underscoring the ongoing threat to unsupported systems. One specifically named flaw, CVE-2024-26169, has reportedly been exploited to deploy ransomware. IPA warns that once support ends, newly discovered vulnerabilities will go unpatched, increasing the risk of data breaches and service disruption, and that this risk extends to third-party software (browsers, email clients) running on the unsupported OS as their own vendor support lapses in parallel.
This is a policy/advisory notice rather than a report of active exploitation targeting a specific campaign; the core recommendation is timely migration to supported OS versions or third-party software updates, with LTSC editions of Windows 10 unaffected by this particular end-of-support milestone.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/win10_eos.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free