SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Expiring Windows Update certificates will cut unsupported devices off from updates in 2027
Microsoft says Windows devices on unsupported versions will lose all Windows Update access when update certificates expire on May 17 and June 19, 2027. Every supported release below Windows 11 25H2, servers included, needs a specific monthly update installed first to stay connected.
The Watch · Security desk
What happened
- Server 2016, Server 2019 and Windows 10 Enterprise 2019 LTSC must have the July 2026 security update or later installed before May 17, 2027.
- Windows 10, Server 2022 and other supported Windows 11 versions have until June 19, 2027 to install the July 2026 security update or later.
- For Windows 11 24H2 and Server 2025, the September 2025 security update or any later one, installed before June 19, 2027, is enough.
- BleepingComputer reports the change does not apply to devices that receive their updates through Windows Server Update Services.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A machine that misses its date stays open to every Windows flaw fixed after that point, because Windows Update can no longer deliver the fix to it.
- constraint Patch deferral on Server 2016, Server 2019 and LTSC 2019 now has a ceiling: holding back the July 2026 update past May 17, 2027 costs the machine its update channel.
- decision For Windows versions outside the list, the choice before the 2027 dates is upgrade or run without updates, since Microsoft's only guidance is a move to a supported client or server release.
"As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates). A set of these certificates will expire on May 17, 2027 and June 19, 2027," Microsoft said on Thursday [1]. The notice describes a certificate rotation. No flaw is involved, and nothing changes for an attacker before May 17, 2027 [1].
For Windows 11 25H2 and later, this does not matter. Microsoft lists no action [2]. Every other release on the list comes with a required action [12]. Running a supported version does not clear a machine by itself. The build has to carry the named update by the named date [4][5].
The two dates are 33 days apart: the 14 days left in May after the 17th, plus 19 days of June [13]. That month comes off the window for the oldest servers on the list [5]. Counting from July 2026, those servers have roughly ten months to take the prerequisite update [14].
Windows 11 26H2 shipped last month as a small enablement package for eligible 24H2 and 25H2 systems, in a phased rollout that expands over the next few months [10]. A 24H2 machine that takes it moves into the 25H2-and-later group, where Microsoft lists no action [15].
BleepingComputer states the WSUS exception in its own words and does not say how WSUS-fed devices handle the rotated certificates [9].
Microsoft's advice to administrators is to find every device on an older or unsupported version, keep monthly updates flowing to supported ones, and draw up an upgrade plan before the 2027 dates [8]. "And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft added [11].
What to watch
- Microsoft guidance on how WSUS-managed fleets handle the rotated Windows Update certificates.
- Any move of the May 17 or June 19, 2027 expiry dates; every deadline in the per-version list depends on them.
- Release notes for the July 2026 security update that let admins confirm, machine by machine, that the prerequisite is in place.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence66
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
"As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates). A set of these certificates will expire on May 17, 2027 and June 19, 2027," Microsoft said on Thursday.
- [2]
Windows 11, version 25H2 and later: no action is required.
- [3]
Windows 11, version 24H2 and Windows Server 2025 must install the September 2025 security update or later before June 19, 2027.
- [4]
Other supported versions of Windows 11, Windows Server 2022, and Windows 10 must install the July 2026 security update or later before June 19, 2027.
- [5]
Windows 10 Enterprise 2019 LTSC, Windows Server 2019, and Windows Server 2016 must install the July 2026 security update or later before May 17, 2027.
- [6]
Devices on unsupported versions of Windows "will lose access to Windows Update services and won't receive any updates as a result."
- [7]
For other Windows versions, Microsoft's guidance is to upgrade to a supported version of Windows client or Windows Server.
- [8]
Microsoft advised IT administrators to identify all devices running older or unsupported Windows versions, deploy monthly Windows updates on all supported devices, and create an upgrade plan for unsupported devices before May and June 2027.
- [9]
The change does not apply to devices that receive updates from Windows Server Update Services (WSUS), which downloads updates and distributes them across enterprise networks.
- [10]
Last month Microsoft released Windows 11, version 26H2, generally available for eligible Windows 11 24H2 and 25H2 systems as a small enablement package in a phased rollout that will expand over the next few months.
- [11]
"And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft added.
- [12]
Microsoft shared detailed guidance on the required actions by Windows version.
- [13]
The May 17, 2027 and June 19, 2027 expiry dates are 33 days apart.
- [14]
From July 2026 to the May 17, 2027 deadline is roughly ten months.
- [15]
A Windows 11 24H2 device that installs the 26H2 enablement package falls in the 25H2-and-later group, for which Microsoft lists no action.
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comMicrosoft: Outdated Windows devices will stop receiving security updates
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Certificate rotationFollow
- Software end of supportFollow
- Patch And Redeploy LatencyFollow
Entities
- MicrosoftFollow
- Windows UpdateFollow
- Windows Server Update ServicesFollow
- Windows 11Follow
- Windows 10Follow
- Windows ServerFollow
- BleepingComputerFollow