cumulative updates

Winsage
March 17, 2026
The March 2026 Windows 11 update (KB5079473) has caused significant issues for users, including inaccessible C: drives, system crashes, and freezing. Reports indicate that Samsung Galaxy Book device owners are particularly affected, with complete blockage of access to the C: drive. Microsoft acknowledges the "C: is not accessible - Access denied" issue, linking it to the Samsung Galaxy Connect application, and is working on a resolution. The affected devices include various models of the Samsung Galaxy Book 4 and certain Samsung Desktop models running Windows 11 versions 24H2 and 25H2. While Microsoft claims only Samsung users are impacted, it is unclear if other manufacturers are experiencing similar problems. The update has raised concerns about the quality assurance processes prior to releases.
Winsage
March 15, 2026
Microsoft has released an out-of-band hotpatch update, KB5084597, to address three critical remote code execution vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) in the Windows Routing and Remote Access Service (RRAS) management tool. This update is specifically for Windows 11 Enterprise devices in the hotpatch program that did not receive fixes during the March 2026 Patch Tuesday. The vulnerabilities can be exploited by an authenticated attacker within the domain, potentially leading to remote code execution. Hotpatch updates apply fixes through in-memory patching without requiring a device reboot, making them suitable for mission-critical devices. The update is applicable to Windows 11 versions 24H2, 25H2, and Windows 11 Enterprise LTSC 2024, and will be automatically installed on enrolled devices without a restart. Non-enrolled devices received the fix via the standard March 10 Patch Tuesday update.
Winsage
February 26, 2026
Security researchers have developed a working Proof of Concept (PoC) exploit for a vulnerability in the Windows kernel, identified as CVE-2026-2636, which allows low-privileged users to induce a Blue Screen of Death (BSoD), resulting in a Denial of Service. This vulnerability is linked to the Windows Common Log File System (CLFS) driver, specifically the CLFS.sys component, and arises from improper handling of invalid or special elements within CLFS (CWE-159). The PoC demonstrates that a non-administrative user can trigger the bug by executing a crafted ReadFile operation on a handle linked to an opened .blf log file without the expected I/O Request Packet (IRP) flags set. This leads to a critical inconsistency in the driver, causing Windows to invoke the kernel routine KeBugCheckEx, which results in a BSoD. The CVE-2026-2636 has a CVSS score of 5.5 (Medium) and poses a high impact on availability, allowing any authenticated user to crash the host reliably. Microsoft addressed this vulnerability in the September 2025 cumulative update, protecting systems running Windows 11 2024 LTSC and Windows Server 2025 by default. However, older or unpatched builds remain vulnerable. Organizations are advised to verify the deployment of the September 2025 updates, prioritize patching multi-user systems, and monitor for unusual spikes in BSoD events.
Winsage
February 22, 2026
Windows 11 has faced challenges, including a comprehensive list of top issues identified in 2025, but it is not uniquely unstable compared to earlier versions like Windows 95, 98, XP, 7, and 10. Recent headlines have highlighted various problems such as printer malfunctions and performance issues, but these are often exaggerated due to increased visibility. Historically, Windows has experienced similar cycles of instability, and the perception of widespread failure today is amplified by rapid documentation of minor issues. User trust in Windows has eroded, with skepticism about performance stemming from cumulative updates and the personal impact of issues on over a billion users. The focus should shift to improving predictability and transparency regarding updates rather than solely counting bugs. Windows 11's frequency of out-of-band updates is comparable to that of Windows 7 and 10, with improved mechanisms for addressing problems quickly. Gamers continue to adopt Windows 11 due to enhanced CPU scheduling, improved GPU performance, and features like Auto HDR and DirectStorage. Microsoft is committed to further improving the gaming experience. The scale of Windows operations, with over a billion users and multiple concurrent releases, contributes to occasional anomalies. Despite criticisms, most Windows 11 systems operate without significant issues, performing adequately for daily tasks and gaming. Microsoft has announced plans for enhancements, including bug fixes, performance improvements, and security upgrades, indicating that Windows 11 remains a solid choice for users.
Winsage
February 14, 2026
Microsoft has released a patch for a significant vulnerability in Notepad on Windows 11 that could allow attackers to execute code by opening a Markdown file and clicking on a malicious link. This vulnerability was due to how Notepad processed links within Markdown files, which could trigger unverified protocols to load remote content. The patch now includes a security warning before such links can be activated. Users are advised to check for updates via Windows Update and the Microsoft Store to ensure Notepad and related components are up to date. Security tips include inspecting URLs before clicking and keeping Microsoft Defender features enabled.
Winsage
January 9, 2026
Windows 11 has integrated AI features, including Copilot, which is pinned to the taskbar and embedded in applications like Notepad and Paint. Users cannot universally disable these features, although individual toggles exist. A community script called RemoveWindowsAI has been created to disable Windows AI features at the system level and modify Windows Update settings to prevent reinstallation. The script targets Copilot, Recall, and their integrations, allowing users to disable all features or select specific components. It operates by making registry changes and aims to eliminate visible AI entry points while maintaining their disabled status across updates. When executed, RemoveWindowsAI removes Copilot from the taskbar, uninstalls the app, and disables AI functionalities in applications. Users run the script through Windows PowerShell 5.1, and it can be rerun to re-enable features. The tool provides a consistent experience but has limitations, as it may not address new AI features or changes from major Windows updates.
Search