Microsoft has warned that the cryptographic roots underpinning UEFI Secure Boot on Windows devices will begin to expire in June 2026, forcing a global certificate update that every IT team and many end users must plan for now to avoid boot-level insecurities and loss of updateability.
Background...
2026expiration
bitlocker
boot security
bootkit
certificate rollover
db
dbx
group policy
intune
kek
linux shim
mdm
oem firmware
recovery media
secure boot
uefi
vms
windows 11
windows server
windows update
Microsoft released an out‑of‑band update on August 19, 2025 — KB5066189 for Windows 11 (OS Builds 22621.5771 and 22631.5771) — to fix a high‑impact regression introduced earlier in the August security rollup that broke Reset and cloud recovery flows, while reiterating a separate, platform‑level...
Microsoft released the August 12, 2025 cumulative security update for Windows 11, version 24H2 — KB5063878 (OS Build 26100.4946) — a routine but important monthly package that bundles the latest cumulative fixes, updates to several AI components (targeted at Copilot+ devices), and an updated...
2026expiration
24h2
ai components
air-gapped deployment
august 2025
certificate expiration
configmgr
copilot
enterprise rollout
firmware
kb5063875
kb5063878
kek ca 2011
kek ca 2023
kek db updates
lcu
oem firmware
oem partnerships
os build 22621.5768
os build 26100.4946
patch
rollout testing
secure boot
secure boot certificates
servicing stack update
ssu
uefi
windows 11
windows update
windows update for business
wsus