How to Stop the Win 11 KB5094126 Installation Loop and Safely Upgrade From March Baseline Risk-Free


GreenBowl3344

New member
Member
Local time
2:59 AM
Posts
1
OS
Windows 11

Hello, I need some advice regarding a persistent Windows Update installation loop affecting my machine. My system is currently on a March baseline and is out of date. My primary goal is to completely stop this endless installation loop so I can successfully upgrade Windows to the latest version in a risk-free manner that doesn’t mess around with system files .

  1. What is the most effective, safe and risk-free way to temporarily stop this automatic background update installation loop without it coming back in a few days or causing a lot of background strain, as I feel like when it’s in the background and disabled it is still hammering my hardware and causing high thermal strain, because it flucationing between abled/disabled a lot, this can’t go on, it’s already been a month.
  2. Is it 100% safe to use the Microsoft WUShowHide utility (wushowhide.diagcab) as a block to stop the hardware strain, and will it prevent future brightness fluctuations? Will be permanently disable or come back?
  3. How can I fix this loop, with absolutely zero risk to my custom graphics profiles, legacy driver stability, or screen brightness thresholds?
  4. Does the newly released July Cumulative Update (KB5101650) wrapper contain the renewed firmware validation keys necessary to clear out this March-to-June servicing stack blockage cleanly? Or could it cause system crash or corruption if installed.
  5. Are there known risks or side effects with attempting a repair upgrade or an in-place reinstall for this specific loop? I want to completely avoid anything that resets custom device properties, alters display configurations, or reverts stable graphics card driver profiles or potentially gets stuck, as both take up 20-30 on every attempt and harsh to the system.
6.Since my system is currently out of date on a March baseline, what is the safest path to install a newer, stable update without risking my custom display configurations?

7.Has anyone successfully applied a manual UEFI certificate renewal or a Secure Boot key variable override to bypass the expired Microsoft June 2026 validation timeline on general retail hardware? Any risks?



My System Specs:

-OS Edition: Windows 11 Home Single Language (Retail Channel)

-Version / Build: 25H2 (OS Build 26200.8117 - March 2026 Baseline)

-Hardware: ASUS Laptop (Model M413A)

-Processor: AMD Ryzen 7 4700U with Radeon Graphics (2.00 GHz, 8 Cores)

-Memory: 8.00 GB RAM (7.42 GB usable)

-Storage: Local C: Drive has 226 GB used out of 477 GB total capacity (251 GB free)



Symptoms I Am Experiencing:

The 2026-06 Security Update (KB5094126) and the June Preview Update (KB5095093) download completely to 100%. During initialization, the engine throws error 0x80074101 and restarts the download pipeline.

This creates a heavy background loop that pins the CPU to high utilization, causing noticeable thermal strain. When my AC power charger is connected, the cooling fans run at a very high audible RPM. I also experience temporary screen brightness flaring strictly when the charger is active, likely due to voltage shifts on the shared motherboard power tracks between the integrated AMD graphics and the system RAM channels when the update engine collides with my stop scripts.

Other non- quality updates and daily Windows Defender definitions continue to download and install flawlessly when updates are enable. The issue is strictly isolated to this specific update package and sometimes previews.

Tried So Far:

Over the past few days, I have tried several methods to safely pause or stop this loop to protect my hardware from constant heat stress:

Cache Resets: Cleared the contents of C:\Windows\SoftwareDistribution multiple times. The loop returns as soon as the folder is regenerated.

System Scans: Executed SFC /scannow and DISM /Online /Cleanup-Image /RestoreHealth. Both reports show a completely clean component store with no local system file corruption.

Service Management: Used temporary command-line scripts to stop 'wuauserv', 'usosvc', and 'bits', and adjusted service recovery actions to prevent them from instantly restarting in the background. These tend to come and go, but most are usually settled at stopped for 2-3 days, and then installation of this lopping security update will force a reattempt on the 2 or 3 day and I have reenter the commands.

Built-in Safeguards: Used the "Pause updates for 5 weeks" toggle in Settings just yesterday, where it greyed out for weeks prior, not sure if it will force the reinstall at random again. However, the Windows 11 Home kernel continues to still run background queries every few hours, triggering the hardware strain and it produces loud sounds when charging or resisting disabled setting even if disabling quiets the fan a lot of the time.

Cleaned the software distribution folder.



Cross-Forum Context & Certificate Discovery:

While researching this, I noticed some initial confusion regarding whether the 26200 build numbering indicated an Insider build, but it appears to be a general retail baseline constraint. Some common suggestions include performing a full clean reinstall or a repair upgrade via USB, but I am hesitant due to the risk of overwriting fine-tuned hardware configurations and custom driver properties.

Through cross-referencing documentation uploaded by other users facing identical loops on Build 26200, we uncovered a likely root cause. Logs from 'Get-SecureBootUEFI' show that the motherboard's underlying security certificates (Microsoft KEK CA 2011 and Microsoft Corporation UEFI CA 2011) officially expired in late June 2026.

Because the current date has passed the certificate validity timeline, the Secure Boot subsystem appears to reject the cryptographic handshake of the June update files, causing the 0x80074101 database error and the subsequent retry loop.

As a temporary fix, I am looking into using the official Microsoft WUShowHide diagnostic utility ('wushowhide.diagcab') from my desktop to hide KB5094126 and stabilize my processor and fan noise while waiting for a working patch wrapper that lets me upgrade safely.

I would deeply appreciate any verified engineering insight or workarounds the community has found to help me safely bring this system up to date without side effects. Thank you so much for your time!
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Hello @GreenBowl3344 and welcome to ElevenForum. :-)


Here's how to get up-to-date w/o losing anything... Use Option Two, the ISO file method.



Here's how to deal with the Certificates jungle...





Here's ten points for listing your computer specs. I assume you'll enter them in the proper place in your profile.







And... here's some other things that you may find useful...



 

My Computers My Computers

  • At a glance

    Win 11 Home ♦♦♦26200.8875 ♦♦♦♦♦♦♦25H2AMD Ryzen 7 3700XG.Skill (F4-3200C14D-16GTZKW)EVGA RTX 2070 (08G-P4-2171-KR)
    OS
    Win 11 Home ♦♦♦26200.8875 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • At a glance

    Windows XP Pro 32bit w/SP3AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
Through cross-referencing documentation uploaded by other users facing identical loops on Build 26200, we uncovered a likely root cause. Logs from 'Get-SecureBootUEFI' show that the motherboard's underlying security certificates (Microsoft KEK CA 2011 and Microsoft Corporation UEFI CA 2011) officially expired in late June 2026.

Because the current date has passed the certificate validity timeline, the Secure Boot subsystem appears to reject the cryptographic handshake of the June update files, causing the 0x80074101 database error and the subsequent retry loop.
The CA 2023 migration is unlikely to be the real cause for your Windows Update problems, but you will get Event Log errors if you have an unsupported PC that did not get a previous BIOS update or a vendor-submitted KEK file as part of a recent Windows Update.

Two things can be happening at the same time, and be unrelated to each other.

In the CA 2023 migration, new Secure Boot certificates are written to your UEFI's NVRAM and a matching set of newer boot files are copied to the EFI volume on completion. Secure Boot certs have no impact on Windows certs, and vice versa. For Windows to reject a signed (non-boot) file, it would imply there's a problem with your machine's Certificate Store.

The UEFI's Secure Boot certs are only checked at boot-time when the boot manager is started. After that, they are never consulted again. Just because the CA 2011 cert expired, it does not imply Windows stops working. All it means is MS cannot re-use the same CA 2011 to securely sign a new boot file using that cert, it does not invalidate any previously signed boot files using the same cert.

Expired certs are valid as long as they're enrolled in your Certificate Store and have not be revoked by being added to a revocation list (CTL). That's how the system is designed to work.

A simple test to rule out Secure Boot as a culprit is to temporarily disable Secure Boot mode.

You should consider a repair install as a fix, as it's probably the most reliable solution to a broken update that cannot be solved by running a DISM /RestoreHealth.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Back
Top Bottom