Security update

Winsage
July 21, 2026
Microsoft released an unscheduled update for Windows 11, designated as KB5121767, targeting users on versions 24H2 and 25H2 to address performance issues on certain Dell PCs and laptops with Intel Innovation Platform Framework drivers. The update aims to fix degraded battery life, increased power consumption, and unexpected system behavior caused by conflicts with these drivers. Affected devices primarily include newer Dell models such as the Precision, XPS, and Pro Max series. Users can obtain the update automatically if they have enabled the relevant option in Windows Update or manually through Settings or the Microsoft Update Catalog. The update modifies the Windows build number to 26200.8894 for 25H2 and 26100.8894 for 24H2 and includes previous security and quality enhancements. Microsoft recommends the update for users experiencing sluggish performance or erratic behavior after July updates, particularly those with recent Dell devices with Intel processors.
Winsage
July 21, 2026
Microsoft has released an emergency out-of-band security update (KB5121767) for Windows 11 versions 25H2 and 24H2 due to performance issues caused by the July Patch Tuesday update (KB5101650) affecting certain Dell devices. The issues include system shutdowns, stemming from a conflict between the Windows USB-C Connection Manager and the Intel Innovation Platform Framework Processor Participant driver. Confirmed affected Dell models include the Dell Pro Max 14 Premium MA14250, Dell Pro Max 16 Premium MA16250, Dell XPS 17 9720, and Dell XPS 17 9730. The update is specifically for users of these devices experiencing performance-related issues, and Microsoft stated that no action is required for unaffected devices.
Winsage
July 20, 2026
On July 14, 2026, Microsoft released cumulative update KB5101650 for Windows 11 versions 25H2 and 24H2, addressing OS Builds 26200.8875 and 26100.8875. This update includes essential security fixes, updates to Secure Boot certificates, and enhanced Remote Desktop Protocol (RDP) defenses against phishing attacks. It consolidates July 2026's security content, addressing known vulnerabilities and introducing functional improvements. The update is critical for minimizing exposure to identified threats and is prioritized for systems managing remote access or nearing certificate expiration. The update enhances Remote Desktop security by supporting SHA-2 certificate thumbprints while retaining SHA-1 for legacy compatibility. It includes new Group Policy options to mitigate phishing risks associated with malicious .rdp files. The curl upgrade to version 8.21.0 incorporates security patches for command-line tools in Windows environments. Secure Boot certificates are automatically updated through Windows updates, ensuring boot security across various hardware. KB5101650 installs primarily through the Windows Update interface, requiring a restart to activate changes. Enterprise environments can use the Microsoft Update Catalog for manual distribution. A temporary restriction affects certain Dell devices with Intel Innovation Platform Framework drivers, which Microsoft plans to address in a future update. The cumulative update resolves a total of 622 Microsoft CVEs, including 416 affecting Windows components. Users are advised to verify and install the update promptly to secure the full suite of improvements.
Winsage
July 18, 2026
Windows Server 2022 will end its mainstream support on October 13, 2026, transitioning to an extended support phase that will last until October 14, 2031, during which security updates will be provided at no additional cost. Windows Server 2022 was released in September 2021 and is part of the Long-Term Servicing Channel (LTSC) with a decade of support. Microsoft recommends upgrading to Windows Server 2025, which became generally available in November 2024 and will have mainstream support until November 13, 2029, and extended support until November 14, 2034. A 180-day trial for Windows Server 2025 is available through the Microsoft Evaluation Center. Additionally, hotpatching for Windows Server 2022 will be extended until October 2027 for Datacenter: Azure Edition systems, and the free Windows 10 Extended Security Updates program has been extended by one year. Windows 10 Enterprise LTSB 2016 and Windows 11 24H2 will stop receiving updates three months after their end of support.
Winsage
July 16, 2026
Microsoft released update KB5099539 for Windows 10, enhancing security and addressing vulnerabilities. This update is part of a broader initiative for Windows 10 22H2, Windows 10 Enterprise LTSC 2021, and Windows 10 IoT Enterprise LTSC 2021. It will be automatically installed on eligible systems, resulting in build number 19045.7548. The update resolves issues in File Explorer related to OneDrive shortcuts and erroneous error messages during file deletions, as well as fixes for keyboard shortcut malfunctions. Windows 10 PCs will receive updated Secure Boot certificates, which are essential for system integrity, with Microsoft actively rolling these out. Secure Boot certificates for most Windows devices are set to expire starting in June 2026. Users must be enrolled in the Extended Security Updates (ESU) program to benefit from the KB5099539 update, which provides continued support until October 12, 2027.
Winsage
July 16, 2026
Microsoft has released its July 2026 Patch Tuesday updates, addressing 570 new security vulnerabilities, bringing the total for the month to over 620. The cumulative count of vulnerabilities patched this year has reached 1,380, exceeding the total of 1,250 for the entire year of 2020. Over 400 vulnerabilities are related to various versions of Windows, and the Windows 10 Extended Security Update program has been extended until October 12, 2027. Notable vulnerabilities include CVE-2026-56155 in Active Directory Federation Services, which allows attackers to gain administrator rights, and several critical Remote Code Execution vulnerabilities, including CVE-2026-57092 in Hyper-V and CVE-2026-56190 in Remote Desktop Protocol. Microsoft has also patched 97 vulnerabilities in Office products, with 17 classified as critical RCE vulnerabilities, and four vulnerabilities in Exchange Server, including CVE-2026-55008. The latest Microsoft Edge update addresses 27 vulnerabilities related to Chromium, and a vulnerability in Minecraft Bedrock servers has been patched.
Search