It applies to leaf certs too. (Full disclosure - I work in the industry, so know this well).
After June 15th, 2026 - no leaf certs with serverAuth and clientAuth.
Mind you, client authentication with public certificates is a bad idea anyway, but I appreciate many people do and it's just been 'the way' for many years.
This is why I think it's going to hurt if folks don't realise soon and start to plan.