Windows Update

Winsage
May 6, 2026
Beginning in May 2026, Microsoft will introduce Hotpatching as a default feature for compatible systems, allowing security updates to be applied without requiring a restart. Hotpatching updates code directly in the memory of running processes, enabling selective updates without interrupting the entire system. It does not replace monthly security updates but alters their activation process on eligible systems, categorized as security updates within the monthly B releases. Eligible systems must be running Windows 11 version 24H2 or newer and possess suitable licenses such as Enterprise, Education, Microsoft 365, or Windows 365. Management of these updates will be facilitated through Windows Autopatch or Microsoft Intune. Microsoft will continue to utilize baseline updates that require a restart, which will alternate with Hotpatch months. Hotpatching aims to reduce the frequency of restarts tied to security updates, particularly benefiting environments where uptime is critical. However, planned restarts will still be necessary, and robust telemetry and maintenance practices will be needed to ensure smooth operation.
Winsage
May 6, 2026
Microsoft is transforming its Windows Update system to reduce user frustration and enhance the experience. The company aims to minimize disruption from updates, promoting a more predictable update rhythm and greater user autonomy. Key changes include a unified monthly restart cycle to avoid multiple restarts, simplified management of updates allowing users to start, stop, or pause updates easily, and the ability to restart or shut down devices without immediate installation of updates. New PCs will allow users to pause updates during the initial setup. However, updates can only be paused for a maximum of 35 days to ensure security and system stability. Additionally, users will receive alerts regarding critical updates, including warnings about the retirement of older Secure Boot certificates.
Winsage
May 5, 2026
Upon installing the April 2026 Patch Tuesday update, some users experienced two or three reboots, which Microsoft confirmed is intentional due to the installation of Secure Boot 2023 certificates. This behavior is expected for a limited number of devices and is part of the Secure Boot update process. The Secure Boot certificates are replacing older ones issued in 2011, set to expire in June 2026. Users can check their Secure Boot status in the Windows Security app, which indicates the status with green, yellow, or red badges. A green badge means the system is up to date, while yellow and red badges indicate issues with certificate updates. Microsoft is managing Secure Boot certificates on modern PCs, but older machines without OEM support may struggle to receive updates due to firmware limitations.
Winsage
May 5, 2026
Microsoft will include the psmounterex.sys driver in its Vulnerable Driver Blocklist in the April 2026 security update, affecting third-party backup applications that use this driver for image mounting and Volume Shadow Copy Service (VSS) snapshots. This decision addresses CVE-2023-43896, a critical buffer overflow vulnerability. Affected software includes Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server, and NinjaOne Backup on Windows 11, Windows 10, and Windows Server platforms. Users may face issues during image-mount operations, receiving error messages related to VSS timeouts and Code Integrity errors in the Event Viewer. To check if a system is affected, users can look for Event ID 3077 in the Code Integrity Operational log. Microsoft recommends upgrading to newer versions of backup applications that do not use blocked drivers and advises against uninstalling or delaying the April update. Additionally, the update may cause certain Windows Server 2025 devices to boot into BitLocker recovery mode and has led to out-of-band updates for Windows Server update failures and restart loops on domain controllers.
Winsage
May 3, 2026
Microsoft CEO Satya Nadella reaffirmed the company's commitment to enhancing Windows 11 during a recent earnings call, emphasizing a focus on quality and serving core users better. He also expressed a commitment to Xbox and changes to Game Pass in response to customer feedback. Nadella mentioned that Windows now has over 1.6 billion active devices globally, highlighting its dominance in the desktop market. However, he faced criticism for including Bing and Edge in the consumer-focused dialogue, as their relevance to average consumers is questionable. Concerns were raised about upselling tactics within Windows 11, which some users find intrusive.
Winsage
May 3, 2026
Experts advise against postponing Windows updates, as Microsoft has introduced features allowing users to control when updates occur. Users can pause updates for up to 35 days indefinitely, but delaying updates can lead to security vulnerabilities. Microsoft releases several types of updates: security updates, feature updates, quality updates, driver updates, optional updates, out-of-band updates, and zero-day updates. Zero-day updates are critical and should be installed immediately to avoid exploitation. Recent reports indicate that critical OS patching for Windows 10 and 11 is lagging by an average of 256 days, increasing the risk of cyber incidents.
Winsage
May 2, 2026
Microsoft is scaling back its Copilot initiative, removing unnecessary buttons and rebranding tools in Notepad. The focus has shifted to refining the Windows operating system with quieter updates, a more efficient File Explorer, and simplified Insider program participation. AI features will remain but will be more selectively integrated to enhance user productivity. Recent updates to Windows 11's Insider branch include the removal of the "Ask Copilot" button from tools like Snipping Tool and Photos, and a new "Writing Tools" label in Notepad. Microsoft has introduced a new Windows Update feature for greater control over update timing, and improvements to File Explorer have enhanced speed and stability.
Search