Windows updates

Winsage
July 21, 2026
Microsoft released an unscheduled update for Windows 11, designated as KB5121767, targeting users on versions 24H2 and 25H2 to address performance issues on certain Dell PCs and laptops with Intel Innovation Platform Framework drivers. The update aims to fix degraded battery life, increased power consumption, and unexpected system behavior caused by conflicts with these drivers. Affected devices primarily include newer Dell models such as the Precision, XPS, and Pro Max series. Users can obtain the update automatically if they have enabled the relevant option in Windows Update or manually through Settings or the Microsoft Update Catalog. The update modifies the Windows build number to 26200.8894 for 25H2 and 26100.8894 for 24H2 and includes previous security and quality enhancements. Microsoft recommends the update for users experiencing sluggish performance or erratic behavior after July updates, particularly those with recent Dell devices with Intel processors.
Winsage
July 20, 2026
Users may experience double reboots when installing substantial Windows updates, such as the April and July 2026 Updates, due to factors like Secure Boot and .NET Framework updates. The July 2026 .NET Framework update specifically requires a separate reboot. Microsoft is still rolling out the Secure Boot 2023 certificate update, which may also lead to multiple reboots. Users are advised not to panic during these reboots and to allow the system time to complete the installation process. Additionally, Microsoft has warned against delaying updates for more than three days due to increasing update sizes related to security vulnerabilities. Some users may encounter SCEP certificate errors in the Event Viewer after the July 2026 Update, but these errors do not indicate a failure of the update process.
Winsage
July 20, 2026
On July 14, 2026, Microsoft released cumulative update KB5101650 for Windows 11 versions 25H2 and 24H2, addressing OS Builds 26200.8875 and 26100.8875. This update includes essential security fixes, updates to Secure Boot certificates, and enhanced Remote Desktop Protocol (RDP) defenses against phishing attacks. It consolidates July 2026's security content, addressing known vulnerabilities and introducing functional improvements. The update is critical for minimizing exposure to identified threats and is prioritized for systems managing remote access or nearing certificate expiration. The update enhances Remote Desktop security by supporting SHA-2 certificate thumbprints while retaining SHA-1 for legacy compatibility. It includes new Group Policy options to mitigate phishing risks associated with malicious .rdp files. The curl upgrade to version 8.21.0 incorporates security patches for command-line tools in Windows environments. Secure Boot certificates are automatically updated through Windows updates, ensuring boot security across various hardware. KB5101650 installs primarily through the Windows Update interface, requiring a restart to activate changes. Enterprise environments can use the Microsoft Update Catalog for manual distribution. A temporary restriction affects certain Dell devices with Intel Innovation Platform Framework drivers, which Microsoft plans to address in a future update. The cumulative update resolves a total of 622 Microsoft CVEs, including 416 affecting Windows components. Users are advised to verify and install the update promptly to secure the full suite of improvements.
Winsage
July 19, 2026
Microsoft has introduced point-in-time restore for Windows 11 users, enhancing the traditional System Restore. This new recovery tool allows users to recover their PCs from software issues, problematic drivers, or faulty updates, even when Windows won’t boot. It uses the Volume Shadow Copy Service (VSS) to automatically generate restore points every 24 hours, which include both system and user files, unlike System Restore. Point-in-time restore manages storage by deleting restore points after 72 hours and integrates seamlessly into Windows Settings, being activated by default for volumes over 200GB. Users with smaller volumes must activate it manually. It also incorporates Reserved Storage to ensure restore points do not consume regular disk space. The feature is available on Windows 11 Home and Pro editions with the installation of the optional Preview Update KB5095093. Users can access point-in-time restore through Windows Settings under System > Recovery, and initiate recovery via the Windows Recovery Environment (Windows RE).
Winsage
July 18, 2026
Microsoft held its OEM Secure Boot Office Hours event on July 15, where engineers collaborated with OEM representatives from companies like Acer, Asus, Cisco, Dell, and HP. IT administrators were able to ask live questions about the Secure Boot 2023 rollout. The discussion thread became a detailed technical record, especially following the expiration of the first certificates three weeks prior. Concerns raised by IT admins included BitLocker recovery loops, stuck confidence ratings, and unhelpful Intune error codes. Key facts include: - Devices offline for long periods will still receive the 2023 certificates upon reconnecting to Windows Update. - Devices with existing 2023 certificates in firmware will switch to the new boot manager after the latest Windows patches are installed. - A new script, Detect-SecureBootCertUpdateStatus.ps1, is available in Windows for checking certificate status. - BIOS updates may reset a device’s confidence rating to unrated, which is normal and does not indicate certificate failure. - Admins should edit the AvailableUpdates registry key, not the AvailableUpdatesPolicy, which is managed by Intune and Group Policy. - A licensing bug affecting AvailableUpdatesPolicy on devices upgraded from Pro to Enterprise was resolved by Microsoft in 2026. - BitLocker recovery is not typically linked to the certificate update process but may relate to firmware or PCR issues. - Dell and HP provided guidance on which BIOS versions include the 2023 certificates for their newer models. - Older HP EliteBook 840 G5 units require a manual update package for the new certificates. - Eligible devices can still receive the 2023 certificates in the future, and Surface devices released from 2024 onward come pre-equipped with them. - Microsoft confirmed that devices running 2011 certificates will not lose the ability to receive the 2023 chain. - The Microsoft Corporation KEK CA 2011 and Microsoft UEFI CA 2011 certificates have expired, with the Microsoft Windows Production PCA 2011 set to expire on October 19, 2026.
Winsage
July 17, 2026
Windows 11 has introduced several new features and security enhancements in July 2026, including: 1. A transformed Widgets Board that provides a more streamlined experience without expanding completely when hovered over. 2. A new calendar feature allowing users to postpone Windows Updates, though Microsoft advises against long delays. 3. The Point-in-Time Restore (PITR) feature, which automatically creates restore points for the system, applications, settings, and files, allowing users to revert to snapshots from the last 72 hours. 4. The Screen Tint feature, which applies a customizable color overlay to reduce eye strain, allowing personalization of color and intensity. 5. Improved Bluetooth connectivity, including a new Shared Audio feature that allows users to listen to audio from multiple Bluetooth devices simultaneously.
Winsage
July 16, 2026
Microsoft released update KB5099539 for Windows 10, enhancing security and addressing vulnerabilities. This update is part of a broader initiative for Windows 10 22H2, Windows 10 Enterprise LTSC 2021, and Windows 10 IoT Enterprise LTSC 2021. It will be automatically installed on eligible systems, resulting in build number 19045.7548. The update resolves issues in File Explorer related to OneDrive shortcuts and erroneous error messages during file deletions, as well as fixes for keyboard shortcut malfunctions. Windows 10 PCs will receive updated Secure Boot certificates, which are essential for system integrity, with Microsoft actively rolling these out. Secure Boot certificates for most Windows devices are set to expire starting in June 2026. Users must be enrolled in the Extended Security Updates (ESU) program to benefit from the KB5099539 update, which provides continued support until October 12, 2027.
Search