Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
end-of-life-softwarewidely-deployed-product-advisory

Microsoft Windows lifecycle and update changes affecting Windows 10/Server 2016 and Windows 11

Updated 3mo agoFirst seen Feb 25, 20262 sources

Microsoft is warning organizations that Windows Server 2016, Windows 10 Enterprise LTSB 2016, and Windows 10 IoT Enterprise 2016 LTSB are approaching end of support, after which they will no longer receive security patches, bug fixes, or technical support. Reported lifecycle dates include October 13, 2026 for the Windows 10 2016 LTSB variants and January 12, 2027 for Windows Server 2016; Microsoft’s guidance is to prioritize upgrades (e.g., to Windows Server 2025 and Windows 10/11 LTSC options where hardware permits) and, if migration timelines slip, to use the Extended Security Updates (ESU) program as a short-term bridge for up to three years with only “critical” and “important” security updates.

Separately, Microsoft released the Windows 11 KB5077241 optional (non-security) preview cumulative update with 29 quality changes, including BitLocker reliability improvements (addressing freezes after entering a recovery key) and new built-in capabilities such as a taskbar network speed test and native Sysmon functionality (disabled by default). The update also enables Quick Machine Recovery (QMR) by default on certain unmanaged Windows Pro devices and is positioned for admin testing ahead of the next Patch Tuesday release, but it does not include security fixes.

Share:
Microsoft Windows lifecycle and update changes affecting Windows 10/Server 2016 and Windows 11
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 12, 2027just now

Windows Server 2016 reaches end of support

Windows Server 2016 is scheduled to reach end of support, after which it will no longer receive security updates, bug fixes, or technical support. Microsoft recommends upgrading to a newer server release or using ESU as a temporary measure.

Oct 13, 2026just now

Windows 10 Enterprise LTSB 2016 and IoT Enterprise 2016 LTSB reach end of support

Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB are scheduled to stop receiving security patches, bug fixes, non-security updates, and technical support. Microsoft says organizations should migrate or rely on ESU if eligible.

Feb 25, 20264mo ago

Microsoft reminds customers of 2026-2027 Windows end-of-support deadlines

Microsoft warned organizations that Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on 2026-10-13, and Windows Server 2016 will reach end of support on 2027-01-12. It advised customers to upgrade to newer releases or use the Extended Security Updates program as a temporary bridge.

Microsoft releases Windows 11 KB5077241 preview update

Microsoft released the optional non-security Windows 11 cumulative preview update KB5077241, adding 29 quality and feature changes for testing ahead of the next Patch Tuesday. The update improves BitLocker reliability, adds native System Monitor functionality disabled by default, and updates Windows 11 25H2 and 24H2 to builds 26200.7922 and 26100.7922.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
5 linked
Windows Server 2016Windows Server 2025Windows 11BitlockerActive Directory Certificate Services
Organizations
3 linked
Microsoft CorporationTinesGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.