You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
2026 expiration
About this tag
The 2026 expiration tag covers Microsoft's upcoming Secure Boot certificate rollover, where the cryptographic roots for UEFI Secure Boot on Windows devices begin expiring in June 2026. Discussions include planning for the global certificate update to avoid boot-level security issues and loss of updateability. Related threads detail out-of-band updates like KB5066189 that fix reset and cloud recovery regressions while reiterating the expiration advisory, and cumulative updates such as KB5063878 that include preparatory guidance for the rollover. IT teams and end users are advised to act now to safeguard boot integrity and ensure continued Windows update delivery.
Microsoft has warned that the cryptographic roots underpinning UEFI Secure Boot on Windows devices will begin to expire in June 2026, forcing a global certificate update that every IT team and many end users must plan for now to avoid boot-level insecurities and loss of updateability.
Background...
2026expiration
bitlocker
boot security
bootkit
certificate rollover
db
dbx
group policy
intune
kek
linux shim
mdm
oem firmware
recovery media
secure boot
uefi
vms
windows 11
windows server
windows update
Microsoft released an out‑of‑band update on August 19, 2025 — KB5066189 for Windows 11 (OS Builds 22621.5771 and 22631.5771) — to fix a high‑impact regression introduced earlier in the August security rollup that broke Reset and cloud recovery flows, while reiterating a separate, platform‑level...
Microsoft released the August 12, 2025 cumulative security update for Windows 11, version 24H2 — KB5063878 (OS Build 26100.4946) — a routine but important monthly package that bundles the latest cumulative fixes, updates to several AI components (targeted at Copilot+ devices), and an updated...
2026expiration
24h2
ai components
air-gapped deployment
august 2025
certificate expiration
configmgr
copilot
enterprise rollout
firmware
kb5063875
kb5063878
kek ca 2011
kek ca 2023
kek db updates
lcu
oem firmware
oem partnerships
os build 22621.5768
os build 26100.4946
patch
rollout testing
secure boot
secure boot certificates
servicing stack update
ssu
uefi
windows 11
windows update
windows update for business
wsus