Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
end-of-life-softwarepatch-regressionwidely-deployed-product-advisory

Windows 10 Extended Security Updates Program and Support Messaging Bug

Updated 3mo agoFirst seen Nov 4, 20252 sources

Microsoft has introduced the Windows 10 Extended Security Updates (ESU) program, allowing eligible consumer users to receive an additional year of security updates after official support for Windows 10 ended. The ESU can be accessed for free by using Windows Backup, redeeming Microsoft Rewards points, or through a one-time purchase, with special provisions for users in the European Economic Area. The program is limited to up to 10 devices per user and is not available for corporate or commercial licenses, requiring devices to run at least version 22H2 and be linked to an administrator Microsoft account.

Following the October 2025 updates, a bug has caused some Windows 10 systems—including those enrolled in the ESU program and those running supported LTSC editions—to display incorrect end-of-support warnings. Microsoft clarified that this is a cosmetic issue and does not affect the delivery of security updates. A cloud configuration update has been deployed to address the erroneous messages, but some devices may require manual intervention using Group Policy and Known Issue Rollback. A permanent fix is planned for a future Windows update.

Share:
Windows 10 Extended Security Updates Program and Support Messaging Bug
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Nov 4, 20258mo ago

Windows 10 update bug shows incorrect end-of-support alerts

A Windows 10 update issue triggered erroneous notifications telling some users that support had ended or was ending incorrectly, creating confusion around the product's support status and ESU availability.

Microsoft introduces free Windows 10 ESU enrollment option

Microsoft made available a way for eligible users to enroll in Windows 10 Extended Security Updates and receive one additional year of security updates at no cost after the operating system's normal support period.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
Microsoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Windows 10 Extended Security Updates Program and Support Messaging Bug | Mallory