Security update

Winsage
August 27, 2026
Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach their end of support on October 13, 2026, after which they will no longer receive security updates. These operating systems are designed for fixed-function devices like kiosks and point-of-sale terminals, which are often not actively managed, posing risks if the end-of-support date is overlooked. Microsoft offers an Extended Security Updates (ESU) program as a temporary solution, with escalating costs over three years, but it is not intended as a long-term fix. Customers must decide whether to continue paying for ESU, upgrade to newer hardware, or transition away from Windows.
Winsage
August 25, 2026
Microsoft has acknowledged issues with the August security update KB5121003 for Windows 11, affecting versions 24H2 and 25H2. Users reported problems such as game freezing, unexpected closures, and system restarts after installing the update. The issues are linked to drivers and software for specific RGB-enabled peripherals or components, particularly involving the inpoutx64.sys driver. Games mentioned include ARC Raiders, MARVEL Tōkon: Fighting Souls, and THE FINALS. Embark Studios has released a support guide suggesting users stop and remove the inpoutx64.sys service as a temporary workaround. Microsoft is investigating the issue but has not provided a definitive fix or patch timeline.
Winsage
August 21, 2026
Timely updates are crucial for home users to protect personal data and device integrity. Organizations should assess systems for vulnerabilities, especially those accessible via the internet. CVE-2026-33824 is a critical vulnerability in the Internet Key Exchange (IKE) service extensions within Windows, caused by a “double-free” error, allowing code execution. It affects various versions of Windows 10, Windows 11, and Windows Server, and is included in the CISA KEV catalog. Users are urged to install the April Windows updates immediately. CVE-2026-55040 is a critical vulnerability in Microsoft SharePoint that allows unauthenticated attackers to bypass a key security feature, with a CVSS score of 9.1. It affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and the Subscription Edition, with fixed builds already available.
Winsage
August 20, 2026
ShieldBreak, identified as CVE-2026-69414, is a zero-day vulnerability in the Microsoft Malware Protection Engine that allows low-privileged local attackers to escalate privileges to SYSTEM. The public proof of concept was released on August 12, 2026, and Microsoft recognized the CVE on August 14, 2026. No patch is currently available. ShieldBreak exploits an elevation-of-privilege vulnerability by manipulating file processing during the cloud-file hydration process in Microsoft Defender, allowing attackers to control processes with elevated privileges. The exploit is functional on Windows 11 25H2 and Windows Server 2025. Qualys VMDR can detect this vulnerability using a specific query, and organizations can use Qualys TruRisk™ Eliminate for mitigation until a patch is released.
Winsage
August 13, 2026
A recent update has been released, addressing security vulnerabilities and improving system functionality. Key improvements include a fix for the Backup feature, resolving an "invalid credentials" error that caused automatic backups to fail when using Server Message Block (SMB). The update also enhances the Secure Boot feature by introducing high-confidence device targeting data, allowing more devices to receive new Secure Boot certificates. This update addresses outdated Secure Boot certificates for Windows 11 and Windows 10 users. The update, identified as KB5120249, is under 1 GB and is available only to PCs enrolled in the Extended Security Updates (ESU) program, which ensures Windows 10 PCs receive security updates until at least October 2027. Non-enrolled PCs lost security update support in October 2025.
Winsage
August 12, 2026
Microsoft's August update, KB5121003, includes several enhancements: - The File Explorer now displays file sizes in kilobytes (KB), megabytes (MB), or gigabytes (GB) dynamically, simplifying file management. - The Low Latency Profile is expanded to more applications, improving launch speeds for Microsoft apps like Edge and Outlook by up to 40%, and other system components by up to 70%. - Windows Search has been improved to better handle typos and incomplete queries, prioritizing relevant results and indexing files across the operating system. - The Start Menu now more effectively respects user preferences, ensuring consistent settings.
Winsage
August 12, 2026
Microsoft released a patch for a zero-day vulnerability, CVE-2026-68820, which is being exploited by cybercriminals, specifically the North Korean hacking group Lazarus. This vulnerability allows unauthorized attackers to elevate their privileges locally, posing a significant risk to affected systems. The August 2026 Patch Tuesday update addressed 421 vulnerabilities, including three zero-days, with CVE-2026-68820 being the only one confirmed to be actively exploited. The vulnerability's impacts on confidentiality, integrity, and availability are rated as High. Users of Microsoft Windows 10, Windows 11, and various versions of Windows Server should prioritize deploying the patch for this vulnerability.
Winsage
August 12, 2026
Windows 11 introduced the Low Latency Profile feature with the August 2026 security update, enhancing app launch speeds. This feature allows the CPU to quickly reach near-maximum frequency when an application is launched, improving loading times and conserving energy by returning to low-power idle states more rapidly. Initially limited to core Windows shell elements, the August update (KB5121003) expanded this functionality to a wider range of applications. Testing showed significant improvements in app launch times, with no adverse effects on CPU performance or battery life. Users can manually enable the feature using the ViVeTool if it hasn't been rolled out to them yet. Microsoft is also working on optimizing Windows 11 for devices with 8GB of RAM and above by the end of 2026.
Search