# Windows 10 Is Dead. It's Also Getting the Biggest Patch Drop of the Year.


Eleven months after Microsoft officially killed Windows 10 support, the company just shipped what it's calling a record-breaking September 2026 Patch Tuesday update for the platform — a KB5122878 bundle that covers the same critical fixes landing on Windows 11 this month, plus a handful of OS-specific bug patches.


That sentence contains a contradiction that should bother every security-conscious reader. The OS is end-of-life. The patches are record-breaking. One of these things implies the other shouldn't still be necessary.


## The ESU Treadmill


Microsoft ended mainstream support for Windows 10 on October 14, 2025. What followed is the same playbook the company ran with Windows 7, and before that, Windows XP: a paid Extended Security Update program that keeps the patches flowing for organizations willing to pay for more time. Year one of Windows 10 ESU runs around $61 per device for businesses; the price escalates annually.


It's a reasonable program in theory — enterprises have real migration complexity, and a cliff-edge EOL creates dangerous incentives to just keep running unpatched systems. But what ESU doesn't solve is the fundamental exposure problem: a system running Windows 10 in September 2026 was almost certainly not upgraded for a reason, and that reason rarely has anything to do with waiting for a convenient moment to act.


The organizations on ESU right now skew heavily toward manufacturing shop floors, healthcare kiosks, point-of-sale terminals, embedded industrial systems, and under-resourced SMBs. These are not environments where "we'll get to the upgrade next quarter" is a temporary state — it's a permanent condition with a different label each year.


## What Makes This Patch Tuesday "Record-Breaking"


The source doesn't detail the exact CVE count, but September 2026 Patch Tuesday lands during what has been a particularly active quarter for Windows kernel and privilege escalation vulnerabilities. A "record-breaking" designation from Microsoft — a company that patches 60-100+ CVEs per month on a normal cycle — is worth pausing on. It suggests the underlying attack surface in Windows hasn't shrunk post-EOL; it's kept pace with the threat landscape.


This is important for ESU holders to understand: you're not getting a frozen, stable snapshot of Windows 10. You're getting a system that keeps accumulating new vulnerability classes as researchers and attackers alike continue to probe it. Every month that passes adds entries to the CVE database that ESU subscribers need to chase.


For Windows 10 systems outside ESU — running completely unpatched since October 2025 — this month's bulletin is a roadmap for attackers. The full disclosure that comes with Patch Tuesday tells anyone paying attention exactly which classes of bugs are present in the unpatched population.


## The Windows 7 Comparison Isn't Flattering


We've been here before. Windows 7 hit EOL in January 2020, with a nearly identical ESU lifeline. Three years later, Windows 7 still accounted for a statistically significant share of enterprise endpoints worldwide, particularly in healthcare and government verticals. EternalBlue, the exploit behind WannaCry, was already known by 2017 — and organizations still hadn't patched it by the time it became a global incident.


The Windows 10 situation is structurally similar but operating at larger scale. Windows 10 still runs on a massive share of global endpoints — estimates going into EOL put it north of 60% of the Windows installed base. Even aggressive migration assumptions leave tens of millions of machines on an OS that will stop receiving ESU patches entirely by October 2028. After that, nothing.


## What Defenders Need to Do Now


If you're an IT or security practitioner with Windows 10 in your environment, KB5122878 is table stakes — patch it if you're on ESU, and treat the delay between Patch Tuesday release and deployment as your exposure window. But the more durable question is whether ESU is actually your strategy or just a way to defer a harder conversation.


Some practical pressure points:


Inventory your Windows 10 population with real specificity. Not all Windows 10 machines are equal risk. A domain-joined workstation with EDR coverage and network segmentation is a very different animal than an isolated kiosk running an outdated browser. Treat them accordingly.


Know which systems can't be upgraded. Legacy application dependencies, hardware constraints, and vendor-locked configurations are legitimate reasons — but "we haven't checked" is not. Force the audit.


Model the post-ESU cliff. October 2028 isn't far. Organizations that waited until the last moment in the Windows 7 cycle paid steep premiums for emergency migrations. Building a Windows 10 exit plan now, when migration tooling is mature and Windows 11 hardware requirements are well understood, is meaningfully less painful than doing it under deadline pressure.


Watch your exposure window. The gap between Patch Tuesday release and full enterprise deployment has historically been four to six weeks in organizations without mature patch management. For record-breaking months — where the CVE list is long and testing burden is high — that window stretches further. Prioritize.


## HackWire Analysis


The quiet story inside KB5122878 is that Microsoft is still doing serious engineering work to maintain a platform it officially sunset almost a year ago. That's not a criticism — it's a reflection of how embedded Windows 10 remains across global infrastructure. But it also exposes a structural problem that neither Microsoft's pricing model nor the ESU program architecture actually solves.


Extended security updates are priced as a penalty for organizational inertia, not as a genuine long-term strategy. The escalating annual cost is meant to create migration urgency. What it actually creates, in many environments, is an annual budget line that gets approved because the alternative — a full Windows 11 migration project — requires capital expenditure, project management bandwidth, and application compatibility testing that security teams can't force through alone.


The record-breaking September 2026 Patch Tuesday is also arriving in a threat environment where ransomware operators have explicitly targeted organizations running EOL software. The intelligence from multiple incident response firms over the past 18 months shows consistent pattern: initial access via known-but-unpatched vulnerabilities in legacy endpoints, lateral movement enabled by flat network architecture, and deployment in environments where endpoint detection was absent or misconfigured on legacy machines specifically.


The organizations most exposed here are not the ones you'd expect to find on HackWire's front page — they're the mid-market manufacturers, regional healthcare systems, and municipal government agencies that made IT decisions in 2019 that felt reasonable at the time. For them, KB5122878 is available. The real question is whether the broader migration clock is actually running.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)