Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Expiring Windows Update certificates will cut unsupported devices off from updates in 2027

Microsoft says Windows devices on unsupported versions will lose all Windows Update access when update certificates expire on May 17 and June 19, 2027. Every supported release below Windows 11 25H2, servers included, needs a specific monthly update installed first to stay connected.

The Watch · Security desk

How we use AISend a correction

What happened

  • Server 2016, Server 2019 and Windows 10 Enterprise 2019 LTSC must have the July 2026 security update or later installed before May 17, 2027.
  • Windows 10, Server 2022 and other supported Windows 11 versions have until June 19, 2027 to install the July 2026 security update or later.
  • For Windows 11 24H2 and Server 2025, the September 2025 security update or any later one, installed before June 19, 2027, is enough.
  • BleepingComputer reports the change does not apply to devices that receive their updates through Windows Server Update Services.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A machine that misses its date stays open to every Windows flaw fixed after that point, because Windows Update can no longer deliver the fix to it.
  • constraint Patch deferral on Server 2016, Server 2019 and LTSC 2019 now has a ceiling: holding back the July 2026 update past May 17, 2027 costs the machine its update channel.
  • decision For Windows versions outside the list, the choice before the 2027 dates is upgrade or run without updates, since Microsoft's only guidance is a move to a supported client or server release.

"As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates). A set of these certificates will expire on May 17, 2027 and June 19, 2027," Microsoft said on Thursday [1]. The notice describes a certificate rotation. No flaw is involved, and nothing changes for an attacker before May 17, 2027 [1].

For Windows 11 25H2 and later, this does not matter. Microsoft lists no action [2]. Every other release on the list comes with a required action [12]. Running a supported version does not clear a machine by itself. The build has to carry the named update by the named date [4][5].

The two dates are 33 days apart: the 14 days left in May after the 17th, plus 19 days of June [13]. That month comes off the window for the oldest servers on the list [5]. Counting from July 2026, those servers have roughly ten months to take the prerequisite update [14].

Windows 11 26H2 shipped last month as a small enablement package for eligible 24H2 and 25H2 systems, in a phased rollout that expands over the next few months [10]. A 24H2 machine that takes it moves into the 25H2-and-later group, where Microsoft lists no action [15].

BleepingComputer states the WSUS exception in its own words and does not say how WSUS-fed devices handle the rotated certificates [9].

Microsoft's advice to administrators is to find every device on an older or unsupported version, keep monthly updates flowing to supported ones, and draw up an upgrade plan before the 2027 dates [8]. "And if you do need to act on older device populations, there's still time! Review, update, and plan upgrades for unsupported versions before the May 2027 or June 2027 certificate expiration dates," Microsoft added [11].

What to watch

  • Microsoft guidance on how WSUS-managed fleets handle the rotated Windows Update certificates.
  • Any move of the May 17 or June 19, 2027 expiry dates; every deadline in the per-version list depends on them.
  • Release notes for the July 2026 security update that let admins confirm, machine by machine, that the prerequisite is in place.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence70
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence66
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    "As a standard security practice, these certificates have an expiration date. This means that they eventually need to be rotated (that is, replaced by new certificates). A set of these certificates will expire on May 17, 2027 and June 19, 2027," Microsoft said on Thursday.

    ReportedSupportedSource: Microsoft, quoted by BleepingComputerView cited source
  2. [2]

    Windows 11, version 25H2 and later: no action is required.

    ReportedSupportedSource: Microsoft guidance, via BleepingComputerView cited source
  3. [3]

    Windows 11, version 24H2 and Windows Server 2025 must install the September 2025 security update or later before June 19, 2027.

    ReportedSupportedSource: Microsoft guidance, via BleepingComputerView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 9, 2026

    Microsoft: Outdated Windows devices will stop receiving security updates

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories