Skip to content

Windows August 2026 Security Update Is Here: What You Need to Know Before You Restart

Microsoft has released its August 2026 Windows security update, bringing a fresh round of security protections, reliability improvements, and servicing enhancements to supported versions of Windows. For users and IT administrators, the message is straightforward: check for the update and install it promptly.

While monthly Windows updates can sometimes feel routine, this month’s release deserves particular attention because Microsoft is continuing its phased rollout of new Secure Boot certificates. The August update expands the number of devices that can be confidently targeted for those certificate updates, while also making improvements to the Windows servicing stack—the underlying component responsible for installing updates.

For Windows 11 version 25H2 users in particular, the August release also incorporates improvements from the July 28 preview update, KB5101684. Microsoft says the release includes quality improvements and additional changes designed to make the update process more reliable.

The August Windows update is now rolling out

The August 2026 security release covers a wide range of supported Windows products, including Windows 11, Windows 10, and several Windows Server editions.

Microsoft recommends installing the updates as soon as practical. The company publishes detailed release notes and operating-system-specific KB articles for administrators and users who want to understand exactly which package applies to their device.

The release is part of Microsoft’s regular monthly quality-update cycle, meaning most users can receive the appropriate update through Windows Update. Enterprise and server environments may use additional management and deployment tools depending on their configuration.

The biggest story this month, however, goes beyond the usual security fixes.

Secure Boot remains a major focus

One of the most important elements of the August 2026 release is the continued rollout of new Secure Boot certificates.

Secure Boot is a security feature designed to help protect a computer’s startup process by allowing the system to verify trusted software before Windows loads. Microsoft has been preparing Windows devices for changes involving Secure Boot certificates because certificates currently used by many devices are approaching expiration.

Microsoft has been using a controlled rollout strategy rather than updating every eligible device at once. The August update expands what Microsoft describes as high-confidence device targeting data, increasing coverage of devices that are eligible to automatically receive the new certificates.

The important part for users is that this isn’t simply a case of pushing a certificate update to every machine simultaneously. Devices receive the new certificates after demonstrating enough successful update signals, helping Microsoft maintain a phased and controlled deployment.

Microsoft previously explained that newer Secure Boot certificates would continue to be delivered through Windows Update over the coming months.

For everyday Windows users, this should largely happen in the background. Nevertheless, keeping Windows fully updated is important because the certificate transition is being handled through Microsoft’s ongoing update process.

Windows 11 25H2 gets improvements from July’s preview update

For Windows 11 version 25H2, the August security update also includes improvements that were previously introduced through the July 28, 2026 preview release, KB5101684.

That preview update included a broad collection of quality and reliability improvements. Among them were improvements to File Explorer, the taskbar, Windows sign-in, power settings, Windows Update, networking, printing, clipboard reliability, and other areas of the operating system.

Microsoft also used the July preview release to improve the Windows Update experience itself, including changes related to update-progress calculations and update cleanup.

Some of these changes may not be immediately noticeable to users. That’s normal with cumulative Windows updates. Many improvements are designed to reduce bugs and improve reliability rather than introduce a dramatic new feature that changes how Windows looks.

Servicing stack improvements are another important change

The August release also includes quality improvements to the Windows servicing stack.

That may sound like a technical detail, but the servicing stack plays a critical role in the Windows update process. It is responsible for installing and managing updates, so improvements to it can make future update installations more dependable.

Microsoft has increasingly integrated servicing stack improvements with cumulative Windows updates. Recent Windows releases have included changes designed to improve the reliability of the update installation process.

In other words, some of the most valuable changes in a monthly update may be the ones users never directly notice.

A smoother update installation process can mean fewer failures, fewer confusing errors, and a more reliable path for future security patches.

Some PCs may restart one additional time

There is one detail Windows users should be aware of before starting the August update.

Microsoft says that, with recent and upcoming Windows updates, a limited number of consumer and business devices may experience one additional restart during installation.

This extra restart is associated with the Secure Boot certificate update process. It is described as a one-time restart that can occur after the Secure Boot certificate update has been applied.

For most users, that means the installation may take a little longer than a typical monthly update.

If you’re updating a work computer, it is worth saving open documents and closing applications before starting the installation. Businesses should also consider the potential restart when scheduling maintenance windows.

The additional restart should not be interpreted as a sign that something has gone wrong. It is part of the certificate update process Microsoft has outlined.

Which Windows versions are covered?

Microsoft has published separate KB articles for the supported Windows and Windows Server releases covered by the August 2026 update.

For Windows 11, the relevant packages include:

  • Windows 11 version 26H1: KB5121000
  • Windows 11 versions 25H2 and 24H2: KB5121003
  • Windows 11 version 23H2: KB5120240
  • Windows 11 Enterprise LTSC 2024: Hotpatch KB5120994

Windows 10 also receives updates for supported editions, including:

  • Windows 10 versions 22H2 and 21H2: KB5120249
  • Windows 10 Enterprise LTSC 2019 and Windows Server 2019: KB5120238
  • Windows 10 LTSB 2016 and Windows Server 2016: KB5120418

On the server side, Microsoft lists updates for Windows Server 2025, Windows Server 2022, Windows Server 2012 R2, Windows Server 2012, and related Azure Edition and Hotpatch configurations.

Because the correct KB number depends on the operating system and edition, users should avoid downloading a random package simply because they see it mentioned online. The safest approach is to use Windows Update or the official Microsoft support page for the version installed on the device.

What about Hotpatch-enabled devices?

Enterprise environments using Microsoft’s Hotpatch technology have an additional detail to consider.

Microsoft says that a limited number of devices enrolled in hotpatch updates will receive separate standalone security updates as part of the August 2026 release.

For affected devices, the August hotpatch update will be installed first, followed automatically by the applicable standalone update. Microsoft says that installing the standalone update does not remove the device from the Hotpatch program.

That means IT administrators do not need to manually re-enroll affected devices or change their policies simply because the standalone package appears.

Microsoft has identified specific packages for Windows 11 Enterprise and Windows Server environments, including KB5123607, KB5123273, and KB5123303 for particular configurations.

Some of these packages require a restart.

The key takeaway for businesses is that Microsoft’s update process is designed to handle the sequence automatically on hotpatch-enabled systems, reducing the need for administrators to intervene manually.

Should you install the August 2026 update?

For most supported Windows devices, yes.

Security updates exist to protect systems against known security problems, and delaying them unnecessarily increases the amount of time a device remains exposed to issues addressed by Microsoft’s monthly security releases.

There is also a broader reason to stay current this month: the Secure Boot certificate transition is ongoing. Microsoft is gradually expanding the number of devices eligible for automatic certificate delivery, so maintaining a healthy Windows Update history can help ensure that eligible devices participate successfully in the rollout.

Before installing, users should make sure important files are saved and that they have enough time for Windows to complete the installation and any required restarts.

Businesses should test updates according to their normal change-management procedures, particularly for critical systems and specialized applications. Administrators should also review Microsoft’s release notes for known issues that may apply to their particular environment.

How to install the August 2026 Windows update

For most users, installation is simple.

Open Settings, go to Windows Update, and select Check for updates. If the August 2026 update is available for your device, follow the prompts to download and install it.

The exact process may vary depending on the Windows version, organizational policies, or whether the computer is managed by an enterprise update system.

Microsoft also provides individual KB articles and update packages through its support and update channels for administrators who need more control over deployment.

The bigger picture

The August 2026 Windows security update is more than another monthly patch.

It continues Microsoft’s long-running effort to strengthen Windows security while preparing devices for the next stage of the Secure Boot certificate transition. At the same time, Microsoft is improving the servicing infrastructure that keeps Windows updated and incorporating the quality improvements introduced in July.

For consumers, the advice is simple: don’t ignore the update. Save your work, check Windows Update, install the appropriate security release, and allow the system to restart if required.

For IT departments, August is another reminder that Windows updates are increasingly connected to broader security infrastructure—not just individual vulnerability fixes. Secure Boot certificates, servicing reliability, Hotpatch deployment, and monthly cumulative updates are all part of keeping a modern Windows environment secure.

As Microsoft continues the phased Secure Boot certificate rollout over the coming months, keeping supported devices patched and maintaining a reliable update process will be one of the easiest ways organizations and individuals can stay prepared.

The August 2026 update may not dramatically change the Windows desktop, but that’s not necessarily the point. The most important Windows updates are often the ones quietly working in the background to keep your computer safer, more reliable, and ready for the next update.

Leave a Reply