UPDATE 4/30:
www.elevenforum.com
To view the latest updates about this release, visit the Windows release health dashboard or the update history page for Windows 11, version 25H2 and 24H2.
www.elevenforum.com
For more information about security vulnerabilities, see the Security Update Guide and the April 2026 Security Updates.
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
If you want to remove this update
Caution: Before you decide to remove this update, see Understanding the risks: Why you should not uninstall security updates.
To remove the LCU after installing the combined SSU and LCU package, use the DISM/Remove-Package command line option with the LCU package name as the argument. You can find the package name by using this command: DISM /online /get-packages.
Running Windows Update Standalone Installer (wusa.exe) with the /uninstall switch on the combined package will not work because the combined package contains the SSU. You cannot remove the SSU from the system after installation.
File information
For a list of the files provided in this update, download the file information for cumulative update 5083769.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5088467) - version 26100.8247.
support.microsoft.com
Check Windows Updates
ISO from Microsoft Media Creation Tool (MCT):
www.elevenforum.com
UUP Dump:
64-bit ISO download:
ARM64 ISO download:
www.elevenforum.com
KB5083631 Windows 11 Cumulative Update Preview build 26100.8328 (24H2) and 26200.8328 (25H2) - April 30
UPDATE 5/12: https://www.elevenforum.com/t/kb5089549-windows-11-cumulative-update-build-26100-8457-24h2-and-26200-8457-25h2-may-12.46765/ Microsoft Support: April 30, 2026 - KB5083631 (OS Builds 26200.8328 and 26100.8328) Preview This non-security update for Windows 11, version 25H2 and 24H2...
www.elevenforum.com
Microsoft Support:
April 14, 2026 - KB5083769 (OS Builds 26200.8246 and 26100.8246)
This cumulative update for Windows 11, version 25H2 and 24H2 (KB5083769), includes the latest security fixes and improvements, along with non-security updates from last month’s optional preview release. To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained. For information on Windows update terminology, see the different types of Windows software updates.To view the latest updates about this release, visit the Windows release health dashboard or the update history page for Windows 11, version 25H2 and 24H2.
Announcements and messages
This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.Windows Secure Boot certificate expiration
Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates.
Updating Microsoft Secure Boot keys before expiration in June 2026
https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524 UPDATE 4/02: https://support.microsoft.com/en-us/topic/secure-boot-certificate-update-status-in-the-windows-security-app-5ce39986-7dd2-4852-8c21-ef30dd04f046 UPDATE 2/10...
www.elevenforum.com
Change log
Change date | Change description |
|---|---|
| May 12, 20226 | Known issue revision: Updated workaround for "Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key" |
| May 1, 2026 | Improvement added: [Vulnerable driver blocklist] |
| April 30, 2026 | Known issue revision: Updated workaround for "Warnings related to Remote Desktop might not display correctly" |
| April 27, 2026 | Corrected the known issue "Warnings related to Remote Desktop might not display correctly" |
| April 23, 2026 | |
| April 21, 2026 | Known issue updated: "Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key" |
| April 14, 2026 | Known issue added: "Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key" |
Improvements
This security update contains fixes and quality improvements from KB5079473 (released March 10, 2026), KB5085516 (released March 21, 2026), KB5079391 (released March 26, 2026 - no longer offered), and KB5086672 (released March 31, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change.- [Secure Boot]
- New! The status of Secure Boot certificate updates on your device may be displayed in the Windows Security app (Settings > Privacy & security > Windows Security). Learn more about the status alerts via badges and notifications. These enhancements are disabled by default on commercial devices.
- With this update, Windows quality updates include additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Devices receive the new certificates only after demonstrating sufficient successful update signals, maintaining a controlled and phased rollout.
- This update addresses an issue where the device might enter BitLocker Recovery after the Secure Boot updates.
- [Networking] This update improves reliability when Windows uses SMB compression over QUIC. After you install this update, SMB compression requests over QUIC complete more consistently, reducing the likelihood of timeouts and supporting smoother, more dependable performance.
- [Remote Desktop] This update improves protection against phishing attacks that use Remote Desktop (.rdp) files. When you open an .rdp file, Remote Desktop shows all requested connection settings before it connects, with each setting turned off by default. A one-time security warning also appears the first time you open an .rdp file on a device. For more information, see Understanding security warnings when opening Remote Desktop (RDP) files.
- [Reset this PC (known issue)] Fixed: This update addresses an issue that might cause device reset to fail when using the “Keep my files” or “Remove everything” options. This might occur after installing the March 2026 (KB5079420) Hotpatch security update.
- [Vulnerable driver blocklist] This update introduces a security hardening change that adds known vulnerable kernel drivers to the Microsoft vulnerable driver blocklist. Backup applications that rely on blocked drivers might experience failures when attempting to mount or manage disk images.
These apps relying on blocked drivers might display error messages, including "The backup has failed because Microsoft VSS has timed out during the snapshot creation" or VSS_E_BAD_STATE. Affected users should update to a newer version of their application that uses newer drivers that include the required protections. For more information, see April 2026 Windows security updates introduce protections to known vulnerable kernel drivers.
For more information about security vulnerabilities, see the Security Update Guide and the April 2026 Security Updates.
AI Components
This release updates the following AI components:AI Component | Version |
|---|---|
| Image Search | 1.2603.377.0 |
| Content Extraction | 1.2603.377.0 |
| Semantic Analysis | 1.2603.377.0 |
| Settings Model | 1.2603.377.0 |
Windows 11 servicing stack update (KB5088467)- 26100.8247
This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.Known issues in this update
Symptom
Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update.
This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments.
Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See Option 1 below.)
Workaround
This issue is addressed in KB5089549. After installing KB5089549, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: "The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration."
If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protections.
Remove the Group Policy configuration before installing the update (Recommended)
Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update.
This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments.
- BitLocker is enabled on the OS drive.
- The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually).
- System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible".
- The Windows UEFI CA 2023 certificate is present in the device’s Secure Boot Signature Database (DB), making the device eligible for the 2023‑signed Windows Boot Manager to be made the default.
- The device is not already running the 2023-signed Windows Boot Manager.
Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See Option 1 below.)
Workaround
This issue is addressed in KB5089549. After installing KB5089549, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: "The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration."
If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protections.
Remove the Group Policy configuration before installing the update (Recommended)
- Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console.
- Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.
- Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured".
- Run the following command on affected devices to propagate the policy change: gpupdate /force
- Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C:
- Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C:
- This updates the BitLocker bindings to use the Windows-selected default PCR profile.
- Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C:
- Run the following command: Start-ScheduledTask -TaskName "\Microsoft\Windows\PI\Secure-Boot-Update"
- Restart the device.
- Once the new Windows Boot Manager is successfully installed, enable BitLocker by running the command: manage-bde -protectors -enable C:
Symptoms
After installing this update, the security warning that appears when opening Remote Desktop (RDP) files might not display correctly in some cases.
This issue can occur when you use more than one monitor with different display scaling settings (for example, one display set to 100% and another set to 125%). When this happens, the warning window might show overlapping text or partially hidden buttons, which can make the message difficult to read or interact with.
Workaround
This issue is addressed in KB5083631.
After installing this update, the security warning that appears when opening Remote Desktop (RDP) files might not display correctly in some cases.
This issue can occur when you use more than one monitor with different display scaling settings (for example, one display set to 100% and another set to 125%). When this happens, the warning window might show overlapping text or partially hidden buttons, which can make the message difficult to read or interact with.
Workaround
This issue is addressed in KB5083631.
How to get this update
Before you install this updateMicrosoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Install this update
To install this update, use one of the following Windows and Microsoft release channels.
Available | Next Step |
|---|---|
|
| This update downloads and installs automatically from Windows Update and Microsoft Update. |
| To install this release from the Microsoft Update Catalog, select the option that matches your device architecture (arm64 or x64), and then follow the instructions. |
If you want to remove this update
Caution: Before you decide to remove this update, see Understanding the risks: Why you should not uninstall security updates.
To remove the LCU after installing the combined SSU and LCU package, use the DISM/Remove-Package command line option with the LCU package name as the argument. You can find the package name by using this command: DISM /online /get-packages.
Running Windows Update Standalone Installer (wusa.exe) with the /uninstall switch on the combined package will not work because the combined package contains the SSU. You cannot remove the SSU from the system after installation.
File information
For a list of the files provided in this update, download the file information for cumulative update 5083769.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5088467) - version 26100.8247.
Source:
April 14, 2026—KB5083769 (OS Builds 26200.8246 and 26100.8246) - Microsoft Support
Check Windows Updates
ISO from Microsoft Media Creation Tool (MCT):
Download Official Windows 11 ISO file from Microsoft
This tutorial will show you how to download an official Windows Server or Windows 11 64-bit or ARM64 ISO file from Microsoft. Microsoft provides ISO files for Windows Server and Windows 11 to download. You can use these ISO files to clean install or in-place upgrade Windows 11. The Flight Hub...
www.elevenforum.com
UUP Dump:
64-bit ISO download:
Select language for Windows 11, version 24H2 (26100.8246) amd64
Select language for Windows 11, version 24H2 (26100.8246) amd64 on UUP dump. UUP dump lets you download Unified Update Platform files, like Windows Insider updates, directly from Windows Update.
uupdump.net
Select language for Windows 11, version 25H2 (26200.8246) amd64
Select language for Windows 11, version 25H2 (26200.8246) amd64 on UUP dump. UUP dump lets you download Unified Update Platform files, like Windows Insider updates, directly from Windows Update.
uupdump.net
ARM64 ISO download:
Select language for Windows 11, version 24H2 (26100.8246) arm64
Select language for Windows 11, version 24H2 (26100.8246) arm64 on UUP dump. UUP dump lets you download Unified Update Platform files, like Windows Insider updates, directly from Windows Update.
uupdump.net
Select language for Windows 11, version 25H2 (26200.8246) arm64
Select language for Windows 11, version 25H2 (26200.8246) arm64 on UUP dump. UUP dump lets you download Unified Update Platform files, like Windows Insider updates, directly from Windows Update.
uupdump.net
UUP Dump - Download Windows Insider ISO
UUP Dump is the most practical and easy way to get ISO images of any Insider Windows 10 or Windows 11 version, as soon as Microsoft has released a new build. UUP Dump creates a download configuration file according to your choices, downloads necessary files directly from Microsoft servers, and...
www.elevenforum.com
Last edited:
















