Windows 11 cumulative updates notification on a modern laptop screen

Windows 11 Cumulative Updates August 2026: What’s Fixed

The August 2026 Windows 11 cumulative updates — KB5121003 and KB5120240 — are now rolling out to all supported devices, and they are not optional. Released on 12 August 2026 as part of Microsoft’s monthly Patch Tuesday cycle, these updates collectively address 400 security vulnerabilities, including three actively exploited zero-days, making them among the most critical releases of the year. If you haven’t installed them yet, read on to understand exactly what’s fixed, what’s improved, and how to get your PC protected.

What Are KB5121003 and KB5120240?

Windows 11 cumulative updates KB5121003 and KB5120240 package icons infographic

KB5121003 and KB5120240 are Windows 11 security patches targeting different release branches. KB5121003 applies to Windows 11 versions 24H2 and 25H2 (OS Builds 26100.9168 and 26200.9168), while KB5120240 covers earlier supported builds. Both updates are classified as mandatory cumulative updates — meaning Windows Update will push them automatically to devices that haven’t opted out of automatic updates. Together they represent the full August 2026 Patch Tuesday rollout for Windows 11.

Microsoft’s own support page for KB5121003 confirms the update provides broad security improvements and includes new Secure Boot certificate targeting, designed to harden systems against firmware-level attacks.

400 Vulnerabilities Fixed: The Security Breakdown

The August 2026 Patch Tuesday Windows 11 release is one of the largest in recent memory. According to reporting by BleepingComputer, the full patch batch addresses 400 flaws across the Windows ecosystem, with the most severe breakdown as follows:

  • 42 Critical vulnerabilities patched in total
  • 37 Remote Code Execution (RCE) flaws within those Critical CVEs
  • 5 Elevation of Privilege vulnerabilities rated Critical
  • 3 zero-day exploits confirmed as actively exploited in the wild

Remote code execution flaws are among the most dangerous classes of vulnerability — they can allow an attacker to run arbitrary code on your machine without any interaction from you beyond visiting a compromised page or opening a malicious file. The three zero-days mean threat actors were already using these gaps before Microsoft published the fix, which is precisely why this update should be treated as urgent.

Windows 11 Security Patch: Key Fixes in KB5121003

Windows 11 security patch August 2026 vulnerability breakdown chart with 400 fixes

Beyond raw vulnerability counts, the August Windows 11 security patch includes a range of targeted quality and stability fixes that real users will notice day-to-day. Here is a summary of the most significant changes confirmed across multiple sources:

  • Secure Boot certificate updates — Additional high-confidence device targeting to block unauthorised bootloaders, directly addressing firmware-level attack vectors.
  • Slow startup fix — A bug causing extremely slow boot times on certain hardware configurations has been resolved.
  • Memory leak resolved — A memory leak affecting background processes was causing gradual performance degradation; KB5121003 stops the leak.
  • App search improvements — The Start menu and Settings search now handle typos and partial app names more reliably, making it faster to find installed apps on low-end PCs.
  • Voice Isolation — The update activates Voice Isolation in supported audio settings, filtering background noise during calls and recordings.
  • File Explorer readable sizes — File sizes in Explorer are now displayed in a more human-readable format, removing ambiguity about whether a listed size is in KB, MB, or GB.
  • External fingerprint sign-in — Improved support for external fingerprint readers at the Windows Hello login screen, broadening biometric authentication without built-in hardware.
  • USB/xHCI regression fix — A regression introduced in a previous update that broke certain USB controller configurations has been corrected.

Patch Tuesday Windows 11: Which Versions Are Affected?

Not all Windows 11 installations receive the same update package. Here is how Microsoft has split the August rollout:

  • Windows 11 24H2 & 25H2 → KB5121003 (Builds 26100.9168 / 26200.9168)
  • Windows 11 26H1 → KB5121000 (Build 28000.2704)
  • Earlier supported builds → KB5120240

Devices running editions that have reached end-of-servicing will not receive these fixes. Microsoft’s support documentation explicitly states that such devices will no longer receive fixes for known issues or time zone updates — another strong reason to stay on a supported version. If you are still running Windows 10 or an out-of-support Windows 11 build, you are exposed to all 400 of these vulnerabilities with no official mitigation.

Should You Install the Windows 11 Updates Immediately?

Yes — particularly given the three active zero-days. Microsoft classifies these Windows 11 updates as mandatory, and independent security researchers echo that recommendation. The combination of three in-the-wild zero-days and 37 critical remote code execution flaws means the risk of delaying is measurably higher than the risk of installing. The known post-install issue is limited to a USB/xHCI regression for specific controller setups, which Microsoft has already confirmed is fixed within KB5121003 itself.

To install manually: open Settings → Windows Update → Check for updates. The update will appear automatically if it hasn’t already downloaded in the background. A restart is required to complete installation.

Windows 11 Updates and Your Licence: Are You Covered?

Windows 11 updates settings screen showing cumulative update installation steps

Cumulative updates like KB5121003 are free for all activated Windows 11 installations — Microsoft does not charge for security patches. However, they only apply to genuine, activated copies of Windows 11. If your PC is running an unactivated or counterfeit licence, Windows Update may still deliver the update file, but you remain at risk because system integrity protections are weakened on non-genuine installations.

If you’re on Windows 10 or an older version and these headlines are prompting an overdue upgrade, now is a sensible time to act. Buy Now Key offers genuine Microsoft Windows 11 Pro (Retail) licences from €17.90 — a one-time purchase that gives you lifetime activation, full Windows Update coverage, and every future security patch as it drops. There is also a more affordable Microsoft Windows 11 Home OEM option from €9.65 if you are activating on a single new device and don’t need the Pro feature set.

Not sure which edition suits you? Read our in-depth Windows 11 Pro vs Home comparison to pick the right version before you buy.

How These Windows 11 Security Patches Relate to Previous Updates

The August release builds on a year of increasingly substantial monthly updates. In May 2026, for example, Microsoft shipped KB5089549, which alone patched 120 vulnerabilities alongside Xbox mode integration and a critical BitLocker recovery fix. The August 2026 batch dwarfs that figure at 400 flaws, reflecting both the growing attack surface of a maturing OS and Microsoft’s shift toward consolidating previously deferred patches into single large rollouts.

The Secure Boot improvements in KB5121003 are particularly notable in the context of earlier 2026 vulnerabilities. A zero-day BitLocker bypass exploit (CVE-2026-45585) disclosed earlier this year demonstrated that firmware-level weaknesses can let attackers read encrypted drives with nothing more than a USB stick. The new Secure Boot certificate targeting in August’s update closes a related class of bootloader exploits before they reach that severity.

How to Check Your Current Windows 11 Build

Before or after installing the update, you can confirm exactly which build is running on your machine:

  1. Press Win + R, type winver, and press Enter.
  2. The About Windows dialog shows your exact OS build number.
  3. Compare it against the target build for your version (e.g. 26100.9168 for 24H2).
  4. If your build is lower, go to Settings → Windows Update and install pending updates.

After a successful install and restart, running winver again should reflect the updated build number, confirming KB5121003 or its equivalent is applied.

For the complete official changelog and issue history, refer to Microsoft’s own support article: August 11, 2026 — KB5121003 (OS Builds 26200.9168 and 26100.9168).

Frequently Asked Questions

Are KB5121003 and KB5120240 mandatory Windows 11 updates?

Yes. Both are classified as mandatory security updates by Microsoft. They form the August 2026 Patch Tuesday cumulative rollout and will be pushed automatically to devices running Windows Update. Because they address actively exploited zero-days, Microsoft and independent security researchers strongly advise installing them without delay.

What zero-days do the August 2026 Windows 11 updates fix?

The August 2026 Patch Tuesday fixes three zero-day vulnerabilities that were confirmed as being actively exploited in the wild at the time of release. Microsoft has not publicly disclosed the full technical details of all three at launch — this is standard practice to give users time to patch before full exploit code circulates widely.

Will these Windows 11 security patches slow down my PC?

No performance regressions have been widely reported with KB5121003. On the contrary, the update specifically fixes a memory leak and slow-startup bug, meaning many users may notice modest performance improvements after installation. The known USB/xHCI regression from an earlier update is also resolved in this release.

Do I need a new Windows licence to receive these updates?

No — cumulative security updates are free for all genuine, activated Windows 11 installations. If you are running an unactivated copy, obtaining a legitimate licence ensures you receive full update protection and system integrity features going forward.

What if I’m still on Windows 10 — am I protected by these patches?

Windows 10 receives separate Patch Tuesday updates and is not covered by KB5121003 or KB5120240. Windows 10 mainstream support ended in October 2025, meaning only paid Extended Security Updates (ESU) provide continued patches. Upgrading to Windows 11 on supported hardware is the most straightforward long-term solution for staying protected.

How do I manually download KB5121003 if Windows Update isn’t working?

You can download the update directly from the Microsoft Update Catalog by searching for the KB number at catalog.update.microsoft.com. Download the .msu file matching your build (24H2 or 25H2), double-click to run the Windows Update Standalone Installer, and restart when prompted. This method bypasses Windows Update delivery but installs the identical package.

Leave a Reply

Your email address will not be published. Required fields are marked *