Microsoft: Outdated Windows devices will stop receiving security updates

Microsoft has announced that devices running outdated versions of Windows will no longer receive critical security updates after next year’s Windows Update certificate rotation. This means that any device still using an unsupported version of Windows will be left vulnerable to cyber threats, without access to essential security patches and updates.

The affected systems are those running on older versions of Windows, including Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016. These devices will stop receiving updates after the certificate rotation in May and June 2027, leaving them exposed to potential attacks. The issue is not limited to consumer devices; businesses and organizations using outdated versions of Windows are also at risk.

The reason behind this change lies in the way Microsoft handles security certificates for its Windows Update service. These certificates have an expiration date, just like any other digital certificate. As a standard security practice, they need to be rotated periodically to maintain their validity and effectiveness. In this case, two sets of certificates will expire next year: one on May 17, 2027, and the other on June 19, 2027.

If devices are not running on supported versions of Windows, they will lose access to Windows Update services and won’t receive any updates as a result. Microsoft has provided detailed guidance on the required actions for different versions of Windows, including upgrading to a supported version or installing specific security updates before the certificate rotation.

For users with devices still running on unsupported versions of Windows, there are several options available. If they have already upgraded to a supported version of Windows 11, such as version 25H2 or later, no action is required. However, for those using older versions like Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016, upgrading to a supported version of Windows before the May 2027 certificate expiration date is necessary.

In addition to individual users, IT administrators are also advised to take action. They should identify all devices running older or unsupported versions of Windows and deploy monthly Windows updates on all supported devices to keep them up to date. Creating an upgrade plan for unsupported devices before next year’s certificate rotation will help minimize the impact of this change.

This development serves as a reminder that maintaining up-to-date software is crucial in today’s digital landscape, where threats are constantly evolving. With new versions of Windows being released regularly, it’s essential to stay informed and take proactive steps to ensure the security of your devices. Don’t wait until next year’s certificate rotation – review your system’s compatibility and upgrade as needed to avoid potential vulnerabilities.


Source: Bleeping Computer — 2026-10-09