KB5120249: a mandatory update as part of the August 2026 Patch Tuesday
Microsoft released the cumulative update KB5120249 for Windows 10 versions 22H2 and 21H2 on August 11, 2026, as part of the Extended Security Updates (ESU) program. This update is mandatory as it contains all security patches from the August 2026 Patch Tuesday.
After installation, Windows 10 is updated to builds 19045.7663 (22H2) and 19044.7663 (21H2). The update is available via Windows Update (Settings > Update & Security > Windows Update > Check for updates) or through the Microsoft Update Catalog, which offers several variants based on architecture (x64, x86, ARM64) with sizes ranging from 545 MB to 895 MB.
What is fixed in KB5120249
Two notable improvements accompany this update, beyond the generic security patches:
1. Fix for the File History bug
An issue affected the automatic backups of File History to network shares using the SMB protocol. Users encountered an “invalid credentials” error even when the credentials were correct. As a result, scheduled backups did not copy any files. KB5120249 resolves this issue, which is good news for individuals and small businesses relying on this built-in Windows 10 backup feature.
2. Expansion of Secure Boot certificate deployment
The update includes additional high-trust device targeting data, expanding the coverage of devices eligible to automatically receive the new Secure Boot certificates. Microsoft specifies that the deployment of these certificates via Windows Update will continue on supported PCs and unmanaged professional devices in the coming months.
This renewal of Secure Boot certificates is a critical operation: the original certificates are nearing expiration, and without an update, devices might lose the ability to validate the integrity of the boot process. Microsoft is proceeding with a phased deployment to minimize the risks of boot failures.
Background: a massive August 2026 Patch Tuesday
KB5120249 is part of a particularly busy Patch Tuesday. According to BleepingComputer, Microsoft fixed 400 vulnerabilities this month, including:
| Category | Number |
|---|---|
| Privilege escalation | 176 |
| Information disclosure | 86 |
| Remote code execution | 110 |
| Security feature bypass | 11 |
| Denial of service | 12 |
| Spoofing | 21 |
Among these 400 flaws, 42 are classified as “Critical” (37 remote code executions and 5 privilege escalations). This volume, although lower than the record set the previous month — July 2026 with 570 fixed flaws — remains exceptionally high. Microsoft had warned in June that this volume would increase due to the use of an AI-driven vulnerability discovery system that identifies more flaws in its codebase before attackers can exploit them.
Three zero-days fixed, including one exploited by Lazarus
The August 2026 Patch Tuesday fixes three zero-day vulnerabilities, one of which was actively exploited and two publicly disclosed:
CVE-2026-68820 — Actively exploited zero-day (privilege escalation)
This use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows a locally authenticated attacker to gain SYSTEM privileges. According to a report from Check Point published the same day, this flaw was exploited by the North Korean threat group Lazarus to deploy a new version of FudModule, its kernel-mode rootkit. The vulnerability was discovered by Moshe Marelus and David Driker of Check Point.
Exploitation does not require user interaction: the attacker simply needs to run a specially crafted application on the target system to trigger a race condition.
CVE-2026-62832 — Publicly disclosed zero-day (privilege escalation)
This vulnerability in the Windows User Profile Service allows an authenticated attacker to load another user's registry hive and gain administrative privileges. The details correspond to a flaw referred to as “LegacyHive,” which was publicly disclosed in July 2026 by a researcher named Nightmare Eclipse. Will Dormann, a senior analyst at Tharros, indicated that non-administrator users could exploit LegacyHive to modify the registry hive and execute commands with administrative privileges when the admin account logs in.
CVE-2026-72971 — Publicly disclosed zero-day (spoofing)
This link following vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authenticated attacker to perform spoofing operations locally. The discovery has been attributed to researchers “yhw” and “txz”.
The Windows 10 ESU program: context and extension
The release of KB5120249 makes sense in the context of the Extended Security Updates (ESU) program for Windows 10. It is important to remember that Windows 10 reached its end of support on October 14, 2025: Microsoft no longer provides feature updates or free security patches for the operating system, except for LTSC versions.
For users unable to migrate to Windows 11, Microsoft established an ESU program initially intended to last a year (until October 2026). However, in June 2026, Microsoft quietly extended this free program for one additional year, until October 12, 2027, as revealed by BleepingComputer.
“We understand that transitioning to a new PC can take time. As part of our ongoing commitment to help customers stay secure during the transition, the Windows 10 ESU program for personal devices is extended by one year.” — Microsoft
Consumers can enroll for free in the ESU program through one of the following methods:
- Pay $30 (refundable via Microsoft Rewards)
- Back up Windows settings to their Microsoft account
- Exchange 1,000 Microsoft Rewards points
- In the European Economic Area (EEA): sign in to Windows 10 with a Microsoft account
An ESU license can cover up to 10 devices associated with the same Microsoft account. The program is limited to personal devices: systems joined to an Active Directory domain, Entra, or managed via MDM are not eligible (except for Entra-registered devices). Businesses must subscribe to a separate paid ESU program, which can cost up to $427 per device over three years.
Comparison with previous months
| Month | Fixed flaws | Zero-days | Actively exploited |
|---|---|---|---|
| August 2026 | 400 | 3 | 1 |
| July 2026 | 570 | 3 | 2 |
| June 2026 | ~340 | — | — |
The trend shows a general increase in the volume of patches, directly related to Microsoft's use of its AI-assisted vulnerability discovery system. While this means more updates for users to install, it also indicates that more flaws are being identified and fixed before they can be exploited.
How to install KB5120249
- Via Windows Update: Start > Settings > Update & Security > Windows Update > Check for updates
- Via the Microsoft Update Catalog: search for “KB5120249” on catalog.update.microsoft.com and download the package appropriate for your architecture.
- Via WSUS/Intune: for managed environments, the update is available through the usual management channels.
Microsoft has reported no known issues with this update so far, unlike some previous Patch Tuesdays that introduced regressions.
Recommendations
- Install KB5120249 as soon as possible: given the presence of an actively exploited zero-day (CVE-2026-68820) in this patch cycle, timely application is crucial, especially in environments where sophisticated actors like Lazarus may be active.
- Check your ESU enrollment: if you are still using Windows 10, ensure that your device is properly enrolled in the ESU program to continue receiving these patches until October 2027.
- Plan for migration to Windows 11: the ESU program will only postpone the deadline. The extension to October 2027 provides approximately 14 additional months to plan a transition to a supported system.