Known issues in Microsoft Patches:
Microsoft often releases patches to address security and reliability issues. Sometimes, patches itself will introduce unprecedented issues after installing them. Here's the updated list of all the known issues in Microsoft patches and possible workaround for them.

Oops! No results for your search.

workaround
Sep 9, 2026
KB5120249
2026-08 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5120249) (CVE-2026-62832) (CVE-2026-68820)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible". The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager. In this scenario, the BitLocker recovery key only needs to be entered once -- subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.)"
Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. A permanent resolution for this issue is planned in a future Windows update. More information will be provided when it is available.
workaround
Sept 9, 2026
KB5120998
2026-08 Cumulative Update Preview for Windows 11, version 24H2 for arm64-based Systems (KB5120998) (26100.9278)
"Desktop background settings are lost or reset on some devices Following installation of Windows updates released August 27, 2026 KB5120998 and later, some Windows Desktop settings fail to load, resulting in desktop backgrounds displaying as a solid black color. It is possible other desktop settings may be affected, such as slideshow settings or contrast themes. On affected devices, attempting to manually restore customized settings does not work. This is because the issue prevents the correct loading of settings, regardless of their value. In this case, a default black background is used instead"
This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124008. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Sept 9, 2026
KB5121003
2026-08 Cumulative Update for Windows 11, version 24H2 for arm64-based Systems (KB5121003) (26100.9168) (CVE-2026-62832) (CVE-2026-68820)
"Microsoft Teams and Outlook might fail to launch on ARM-based devices After installing Windows security updates released on or after August 11, 2026, (KB5121003), Microsoft Teams and the new Outlook for Windows might fail to launch or might close unexpectedly on ARM-based devices, such as Surface Pro 11 and Surface Laptop 7. Classic Outlook, Word, Excel, and other applications are not known to be affected. This issue is most likely to occur on new or freshly imaged PCs that have not yet installed any Microsoft Store updates"
To work around this issue: Open Microsoft Store. Select Downloads > Check for updates. Install the latest update for the Auto Super Resolution Package (version 1.0.19.0 or later). This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124008. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Sept 9, 2026
KB5121000
2026-08 Cumulative Update for Windows 11, version 26H1 for arm64-based Systems (KB5121000) (28000.2704) (CVE-2026-62832) (CVE-2026-72971) (CVE-2026-68820)
"Microsoft Teams and Outlook might fail to launch on ARM-based devices After installing Windows security updates released on or after August 11, 2026, (KB5121000), Microsoft Teams and the new Outlook for Windows might fail to launch or might close unexpectedly on ARM-based devices, such as Surface Pro 11 and Surface Laptop 7. Classic Outlook, Word, Excel, and other applications are not known to be affected. This issue is most likely to occur on new or freshly imaged PCs that have not yet installed any Microsoft Store updates"
To work around this issue: Open Microsoft Store. Select Downloads > Check for updates. Install the latest update for the Auto Super Resolution Package (version 1.0.19.0 or later). This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124012. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Sept 9, 2026
KB5120998
2026-08 Cumulative Update Preview for Windows 11, version 24H2 for arm64-based Systems (KB5120998) (26100.9278)
"Microsoft Teams and Outlook might fail to launch on ARM-based devices After installing Windows security updates released on or after August 11, 2026, (KB5121003), Microsoft Teams and the new Outlook for Windows might fail to launch or might close unexpectedly on ARM-based devices, such as Surface Pro 11 and Surface Laptop 7. Classic Outlook, Word, Excel, and other applications are not known to be affected. This issue is most likely to occur on new or freshly imaged PCs that have not yet installed any Microsoft Store updates"
To work around this issue: Open Microsoft Store. Select Downloads > Check for updates. Install the latest update for the Auto Super Resolution Package (version 1.0.19.0 or later). This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124008. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Sept 4, 2026
KB5120996
2026-08 Cumulative Update Preview for Windows 11, version 26H1 for arm64-based Systems (KB5120996) (28000.2804)
"Microsoft Teams and Outlook might fail to launch on ARM-based devices After installing Windows security updates released on or after August 11, 2026, (KB5121000), Microsoft Teams and the new Outlook for Windows might fail to launch or might close unexpectedly on ARM-based devices, such as Surface Pro 11 and Surface Laptop 7. Classic Outlook, Word, Excel, and other applications are not known to be affected. This issue is most likely to occur on new or freshly imaged PCs that have not yet installed any Microsoft Store updates"
To work around this issue: Open Microsoft Store. Select Downloads > Check for updates. Install the latest update for the Auto Super Resolution Package (version 1.0.19.0 or later). This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124012. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Sept 9, 2026
KB5120998
2026-08 Cumulative Update Preview for Windows 11, version 24H2 for arm64-based Systems (KB5120998) (26100.9278)
"Mouse customization is reset on non-English Windows devices Following installation of Windows updates released August 27 2026 (KB5120998) and later, mouse personalization settings are being reverted to certain standard settings. This includes cursor and cursor animations that are selected in the Mouse Properties options under Windows. Our investigation indicates that this issue is caused by code components used in non-English Windows installations. In impacted locales, these settings will fail to load, causing a default to be used instead. Attempting to manually restore the settings values is not successful, as the issue prevents loading these settings regardless of their value"
This issue is resolved in Windows updates released on and after September 8, 2026 such as KB5124008. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Aug 28, 2026
KB5121003
2026-08 Cumulative Update for Windows 11, version 24H2 for arm64-based Systems (KB5121003) (26100.9168) (CVE-2026-62832) (CVE-2026-68820)
"Reports of certain games becoming unresponsive Microsoft received reports of issues involving inability to run certain games as expected after installing this update. Ongoing investigation indicates that this issue is associated with certain peripherals or internal device components that support RGB lighting features. These devices might install drivers or software components with file names similar to inpoutx64. On systems where these drivers are found, launching certain games can trigger this issue. Games identified in reports of this issue include ARC Raiders, MARVEL Tkon: Fighting Souls, and THE FINALS. Reported symptoms include: the game application becomes unresponsive the game application closes without notice the error "EXCEPTION_ACCESS_VIOLATION" is displayed the device restarts without warning If you are experiencing this issue or a similar issue, please use Feedback Hub to submit a report. You can open Feedback Hub by pressing the Windows logo key + F. For additional information, see Send feedback to Microsoft with the Feedback Hub app. Your reports are helpful to our investigation"
This issue is resolved by a block that prevents the inpoutx64 driver from loading on affected devices. When the block is applied, a message is displayed that states the driver has been disabled, after which the game will launch normally. This resolution is available automatically to consumer and business devices that are not managed by IT departments. For enterprise-managed devices, the mitigation will not propagate automatically. IT administrators can follow the steps in the workaround section on the Windows release health site.
workaround
Aug 12, 2026
KB5120233
2026-08 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5120233) (26100.33296) (CVE-2026-62832) (CVE-2026-68820)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
Aug 12, 2026
KB5120242
2026-08 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5120242) (CVE-2026-62832) (CVE-2026-68820)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070884 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
Jul 15, 2026
KB5099444
2026-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5099445)
"Microsoft has received reports of an issue in which certain third-party applications might be unable to launch Microsoft Office applications or open documents after installing the Windows updates released on or after June 9, 2026. This issue affects certain third-party applications that use OLE automation to interact with Microsoft Office applications. In some cases, the Office application or document might fail to open without displaying an error message."
This issue is resolved in Windows updates released on and after July 14, 2026 such as KB5099444. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Jul 15, 2026
KB5099444
2026-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5099445)
"After installing this update, the OneDrive shortcut in File Explorer might not work when File Explorer is running with administrative privileges. Symptoms include an unresponsive shortcut, blank OneDrive properties, and missing sync status icons. No error message is displayed. This issue affects only the built-in Administrator account or applications run using Run as administrator."
Create a desktop shortcut to the OneDrive folder and use that shortcut to access files when using elevated applications or the built-in Administrator account.
workaround
Jul 15, 2026
KB5099445
2026-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5099445)
"After installing this update, the OneDrive shortcut in File Explorer might not work when File Explorer is running with administrative privileges. Symptoms include an unresponsive shortcut, blank OneDrive properties, and missing sync status icons. No error message is displayed. This issue affects only the built-in Administrator account or applications run using Run as administrator."
Create a desktop shortcut to the OneDrive folder and use that shortcut to access files when using elevated applications or the built-in Administrator account.
workaround
Jul 15, 2026
KB5099445
2026-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5099445)
"Microsoft has received reports of an issue in which certain third-party applications might be unable to launch Microsoft Office applications or open documents after installing the Windows updates released on or after June 9, 2026. This issue affects certain third-party applications that use OLE automation to interact with Microsoft Office applications. In some cases, the Office application or document might fail to open without displaying an error message."
This issue is resolved in Windows updates released on and after July 14, 2026 such as KB5099445. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
workaround
Jul 15, 2026
KB5099536
2026-07 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5099536) (26100.33158)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
Jul 15, 2026
KB5099540
2026-07 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5099540)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070884 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
Jul 15, 2026
KB5099540
2026-07 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5099540)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments."
Remove the Group Policy configuration before installing the update (Recommended)
workaround
Jul 15, 2026
KB5094128
2026-06 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5094128) (CVE-2026-49160) (CVE-2026-50507) (CVE-2026-45586)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible". The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager. In this scenario, the BitLocker recovery key only needs to be entered once -- subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.)"
Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. A permanent resolution for this issue is planned in a future Windows update. More information will be provided when it is available.
workaround
Jul 15, 2026
KB5099539
2026-07 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5099539) (CVE-2026-50661)
"Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy Configure TPM platform validation profile for native UEFI firmware configurations is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as Not Possible. The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager"
This issue is addressed in update KB5122878. After installing update KB5122878, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: "The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration." If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protection. Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set Configure TPM platform validation profile for native UEFI firmware configurations to Not Configured. Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command: Start-ScheduledTask -TaskName \\Microsoft\\Windows\\PI\\Secure-Boot-Update Restart the device. Once the new Windows Boot Manager is successfully installed, enable BitLocker by running the command: manage-bde -protectors -enable C:
workaround
June 10, 2026
KB5094127
2026-06 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5094127) (CVE-2026-49160) (CVE-2026-50507) (CVE-2026-45586)
"Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy Configure TPM platform validation profile for native UEFI firmware configurations is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as Not Possible. The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager"
This issue is addressed in update KB5122878. After installing update KB5122878, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: "The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration." If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protection. Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set Configure TPM platform validation profile for native UEFI firmware configurations to Not Configured. Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command: Start-ScheduledTask -TaskName \\Microsoft\\Windows\\PI\\Secure-Boot-Update Restart the device. Once the new Windows Boot Manager is successfully installed, enable BitLocker by running the command: manage-bde -protectors -enable C:
workaround
May 30, 2026
KB5089573
2026-05 Cumulative Update Preview for Windows 11, version 24H2 for arm64-based Systems (KB5089573) (26100.8524)
"After you install this update (KB5089549), some devices might fail to complete installation with error code 0x800f0922. This issue occurs on devices that have limited free space on the EFI System Partition (ESP), especially if it has 10 MB or less available. What you might experience on affected devices: The update installs successfully during the initial phases. The installation fails during the restart phase at approximately 35-36% completion. Windows then rolls back the update. You may see the message: "Something didn't go as planned. Undoing changes." The installation fails with error code 0x800f0922. As a result of this issue, you might see log entries similar to the following in C:\Windows\Logs\CBS\CBS.log, indicating insufficient free space on the EFI System Partition: SpaceCheck: Insufficient free space ServicingBootFiles failed. Error = 0x70 SpaceCheck: used by third-party/OEM files outside of Microsoft boot directories"
Affected customers can use one of the following workarounds to mitigate this issue. Option 1: Allow the update to install by modifying an ESP registry setting Important: Editing the registry incorrectly can cause serious system problems. Always back up the registry before making any changes. Open Command Prompt as an administrator. Run the following command: reg add "HKLM\SYSTEM\CurrentControlSet\Control\Bfsvc /v EspPaddingPercent /t REG_DWORD /d 0 /f" Restart the affected device. Retry installing the update. Option 2: Mitigate the issue by using Known Issue Rollback (KIR) This issue is mitigated using Known Issue Rollback (KIR). The resolution has already propagated automatically to consumer devices and non-managed business devices. Restarting your Windows device might help the resolution apply more quickly. Enterprise-managed devices For devices where Windows updates are managed by IT departments, administrators can apply the mitigation by installing and configuring a special Group Policy. You can find the policy at Computer Configuration > Administrative Templates >. Group Policy download Windows 11, version 25H2 and Windows 11, version 24H2: KB5089549 260514_06221 Known Issue Rollback Important: You must install and configure the Group Policy that matches your version of Windows to resolve this issue. You must also restart affected devices to apply the policy. This Group Policy temporarily disables the change that causes the issue. For more information, seeHow to use Group Policy to deploy a Known Issue Rollback. A resolution is in progress and will be included in a future Windows update. This documentation will be updated once the resolution is available.
workaround
May 18, 2026
KB5089549
2026-05 Cumulative Update for Windows 11, version 24H2 for x64-based Systems (KB5089549) (26100.8457)
"After you install this update (KB5089549), some devices might fail to complete installation with error code 0x800f0922. This issue occurs on devices that have limited free space on the EFI System Partition (ESP), especially if it has 10 MB or less available. What you might experience on affected devices: The update installs successfully during the initial phases. The installation fails during the restart phase at approximately 35-36% completion. Windows then rolls back the update. You may see the message: \"Something didn\'t go as planned. Undoing changes.\" The installation fails with error code 0x800f0922. As a result of this issue, you might see log entries similar to the following in C:\\Windows\\Logs\\CBS\\CBS.log, indicating insufficient free space on the EFI System Partition: SpaceCheck: Insufficient free space ServicingBootFiles failed. Error = 0x70 SpaceCheck: used by third-party/OEM files outside of Microsoft boot directories"
This issue is addressed in KB5089573.
workaround
May 13, 2026
KB5087545
2026-05 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5087545)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070892 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
May 13, 2026
KB5087544
2026-05 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5087544)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive."
We are working on a resolution and will provide more information when it is available. To temporarily work around this issue, remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: ​​​​​​​This updates the BitLocker bindings to use the Windows-selected default PCR profile.
workaround
May 13, 2026
KB5087545
2026-05 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5087545)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070884 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
May 13, 2026
KB5087539
2026-05 Cumulative Update for Microsoft server operating system version 24H2 for arm64-based Systems (KB5087539) (26100.32860)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
May 13, 2026
KB5087541
2026-05 Cumulative Update for Microsoft server operating system version 23H2 for x64-based Systems (KB5087541)
"Windows Server Update Services (WSUS) does not display error details"
After installing KB5070879 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.
workaround
May 13, 2026
KB5087545
2026-05 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5087545)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible". The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager. In this scenario, the BitLocker recovery key only needs to be entered once -- subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.)"
Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. A permanent resolution for this issue is planned in a future Windows update. More information will be provided when it is available.
workaround
May 13, 2026
KB5087539
2026-05 Cumulative Update for Microsoft server operating system version 24H2 for arm64-based Systems (KB5087539) (26100.32860)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible". The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager. In this scenario, the BitLocker recovery key only needs to be entered once -- subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.)"
This issue is addressed in KB5094125. After installing KB5094125, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: \"The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration.\" If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protections. Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set \"Configure TPM platform validation profile for native UEFI firmware configurations\" to \"Not Configured\". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. If you do not wish to remove this Group Policy configuration, you can install the new Windows Boot Manager by temporarily suspending BitLocker and installing the Secure Boot update. To do this: Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command: Start-ScheduledTask -TaskName \"\\Microsoft\\Windows\\PI\\Secure-Boot-Update\" Restart the device. Once the new Windows Boot Manager is successfully installed, enable BitLocker by running the command: manage-bde -protectors -enable C:
workaround
May 13, 2026
KB5087420
2026-05 Cumulative Update for Windows 11, version 23H2 for arm64-based Systems (KB5087420)
"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible". The Windows UEFI CA 2023 certificate is present in the device's Secure Boot Signature Database (DB), making the device eligible for the 2023-signed Windows Boot Manager to be made the default. The device is not already running the 2023-signed Windows Boot Manager. In this scenario, the BitLocker recovery key only needs to be entered once -- subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.)"
This issue is addressed in KB5093998. After installing KB5093998, devices with this incompatible group policy configuration are prevented from installing the 2023-signed Windows Boot Manager. If your device was impacted, Event ID 1032 will appear in the System event log when installing Windows updates: \"The Secure Boot update Boot Manager (2023) was not applied due to a known incompatibility with the current BitLocker configuration.\" If you receive Event ID 1032, Microsoft strongly recommends removing the Group Policy configuration before installing updates so that you can install the 2023-signed Windows Boot Manager and continue to receive the latest Secure Boot protections. Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set \"Configure TPM platform validation profile for native UEFI firmware configurations\" to \"Not Configured\". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -enable C: This updates the BitLocker bindings to use the Windows-selected default PCR profile. If you do not wish to remove this Group Policy configuration, you can install the new Windows Boot Manager by temporarily suspending BitLocker and installing the Secure Boot update. To do this: Run the following command to suspend BitLocker (if BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command: Start-ScheduledTask -TaskName \"\\Microsoft\\Windows\\PI\\Secure-Boot-Update\" Restart the device. Once the new Windows Boot Manager is successfully installed, enable BitLocker by running the command: manage-bde -protectors -enable C:

Disclaimer:This webpage is intended to provide you information about patch announcement for certain specific software products. The information is provided "As Is" without warranty of any kind. The links provided point to pages on the vendors websites. You can get more information by clicking the links to visit the relevant pages on the vendors website.