August 27, 2026—KB5120998 (OS Builds 26200.9278 and 26100.9278) Preview

Applies To
Windows 11 version 25H2, all editions Windows 11 version 24H2, all editions

This cumulative update for Windows 11, version 25H2 and 24H2 (KB5120998), includes production-quality improvements. 

Announcements and messages

This section provides key notifications related to this release, including announcements, change logs, and end-of-support notices.  

Windows Secure Boot certificate expiration

Important: Secure Boot certificates used by most Windows devices expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices over the past several months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Updated certificates will continue to be delivered through Windows Update in the coming months. For more information, see Windows Secure Boot certificate expiration and CA updates.

End of updates

Windows 11, version 24H2 Home and Pro editions will reach end of updates on October 13, 2026. Devices running these editions will no longer receive fixes for known issues, time zone updates, technical support, or monthly security and preview updates containing protections from the latest security threats. Enterprise and Education editions remain supported until October 12, 2027.

To stay protected and up to date, we recommend you upgrade to the latest version of Windows 11.

Highlights

This update is available through two release phases: gradual rollout and normal rollout. A gradual rollout delivers an update in phases, so features reach devices over time instead of all at once, meaning availability varies by device. A normal rollout is the broad release to all eligible devices at the same time, usually when it reaches general availability (GA). 


Gradual rollout The following summary outlines new Windows 11 PC experiences, along with improvements and fixes. The bold text within the brackets indicates the item or area of the change.

Taskbar

  • This update gives you more ways to customize the taskbar to match how you work and make better use of screen space.

    • New! You can now choose whether the taskbar appears at the bottom, top, left, or right side of your screen. In these other positions, tooltips, flyouts, and animations will still come from the taskbar, and most customization settings, such as never combining taskbar icons, will work with all locations. Search box and smaller taskbar are currently supported only for top and bottom positions. To change the position of the taskbar, go to Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar position

    • New! A smaller taskbar option is now available to help maximize screen space on smaller devices. This experience reduces the size of taskbar icons and the taskbar height while maintaining access to key features such as Start, Search, and the system tray. To change your taskbar size, go to Settings > Personalization > Taskbar > Taskbar behaviors > Taskbar size. When set to Small, both the icons and the taskbar height become smaller.

    • New! The Taskbar behaviors section of the Taskbar settings page is now expanded by default for improved discoverability.

  • This update improves reliability of loading the system tray area of the taskbar for non-touch PCs.

Start menu

  • This update makes the Start menu more personal with several customizations.

    • New! You can choose between a small or large Start menu, in addition to "Automatic (default)" that's available today. To customize this, go to Settings > Personalize > Start > Start menu size.

    • New! The "Recommended" section is renamed "Recent" in the Start menu and Settings page (Settings > Personalize > Start).

    • New! You can now hide your name and profile picture in Start by going to Settings > Personalize > Start > Hide your name and profile picture on Start.

    • New! The Start menu settings page is now redesigned with section-level toggles to independently show or hide Pinned, Recommended, and All.

  • This update includes improvements that make Windows Search more dependable, easier to scan, and clearer before you click.

    • New! Search home has been simplified to reduce visual clutter and make it easier to get back to recent searches quickly.

    • New! Search does a better job showing where a result comes from—app, setting, file, web result, or Store suggestion—so it’s easier to tell what you’re looking at and where you will go before you click.

    • New! A new setting in Settings > Privacy & Security > Search lets you choose whether web and Microsoft Store suggestions appear alongside local results.

    • New! Windows now automatically indexes your most used folders to make those files appear in subsequent search results. You can control the setting at Settings > Privacy & Security > Search > Automatically find additional relevant locations

File Explorer

  • New! Launching File Explorer Home is now faster and more responsive.

  • New! The Recommended section on Home now supports touch scrolling, making it easier to browse files in the carousel.

General design

  • New! This update introduces updated progress indicators across Windows, providing a more consistent and modern experience during startup, sign-in, restart, shutdown, and update installation.

Windows Share

  • New! This update adds the ability for users signed in with a work or school account to discover and install relevant apps directly from the share window. To manage this experience, go to Settings > System > Share and select Show suggested apps in share surfaces.

Administrator Protection

  • New! Administrator protection aims to protect free floating admin rights for administrators. It enables users to perform administrative tasks using just-in-time privileges. Administrator protection is not classified as a formal security boundary; it hardens the security against elevation-of-privilege attacks with the introduction of profile separation. This feature is turned off by default and can be enabled using OMA-URI in Microsoft Intune or through Group Policy. This feature was previously disclosed in October 2025 (KB5067036) and is now beginning to roll out.

Multiple desktops

  • Switching between virtual desktops is now smoother and more responsive.

Display and Graphics

  • This update improves the reliability of navigating to and interacting with Settings > System > Display.

  • This update improves the persistence of previous brightness settings once the energy saver turns off.

Task Manager

  • This update improves the reliability of displaying app history information in Task Manager.

Windows Setup

  • This update streamlines the experience for selecting a secondary keyboard during Windows setup, making it easier to skip when it isn't needed.

  • This update improves the Get Started app with new App install, Site pinning, and Theme pages to help you personalize your device and discover new features.

Windows Update

  • This update improves restart behavior so PCs that were manually put to sleep return to sleep after completing an update, even when automatic sleep is set to Never.

App updates

  • This update adds support for participating apps to coordinate their updates with Windows Update. Supported apps can benefit from improved scheduling and a more streamlined update experience. For more information, see Windows Update Orchestration Platform (UOP).

Microsoft store

  • New! This update provides support for in-app purchases in packaged WinUI 3 apps that require elevation, helping developers offer purchases through Microsoft's integrated commerce platform.

Windows Autopilot device preparation

  • New! Device association for Windows Autopilot device preparation is now generally available. This feature helps organizations identify trusted devices before enrollment, enabling device-targeted policies, automatic corporate device enrollment, and additional setup customization during the out-of-box experience (OOBE). To learn more, see Windows Autopilot device preparation.

Microsoft Execution Containers

  • New! This update introduces Process Isolation for Microsoft Execution Containers (MXC), a fast, lightweight boundary for responsive workloads such as coding agents and model-generated code. It uses Windows operating-system containment capabilities to restrict access to resources such as files, networking, the user interface, and other operating-system capabilities according to policy.

Agentic processes

  • New! This update introduces preview platform support for tagging agentic processes. Authorized components can assign an opaque agent identifier to a process token. Windows protects the marking and automatically passes it to child processes. When an agentic process authenticates through Web Account Manager (WAM), WAM includes the agent identifier from the process token in the authentication request. As a preview capability, the identifier format may change in future releases.

Cryptography

  • New! Post-Quantum Cryptography algorithm ML-KEM can now be used as a standalone algorithm for TLS key exchange, in addition to hybrid groups added previously.

Network

  • This update improves resiliency and recovery from potential VPN process-related background that can cause processes to stop responding.

  • This update improves the output of netsh wlan show wlanreport command for Japanese users.

Input

  • This update improves the reliability of typing with the Japanese IME by reducing potential hangs.

  • This update improves the persistence of voice typing settings for automatic punctuation and launcher.

Windows Management Instrumentation Command-line (WMIC)

  • Starting in August 2026, Windows 11, version 24H2 and 25H2 will no longer include the Windows Management Instrumentation Command-line (WMIC) utility. WMIC is already removed by default in new installations of Windows 11, versions 24H2 and 25H2, and will no longer be available as a Feature on Demand (FoD). This change affects only the WMIC utility; Windows Management Instrumentation (WMI) remains supported. Learn more: Windows Management Instrumentation Command-line (WMIC) removal from Windows. 
Normal rollout This non-security update includes quality improvements. The following summary outlines key issues addressed by the KB update after you install it. Also, included are available new features. The bold text within the brackets indicates the item or area of the change.

Accessibility

  • This update improves the Natural Voices experience in Narrator, helping Natural Voices install and set up successfully from the settings dialog

App

  • This update improves Japanese text input in RemoteApp applications, helping text appear correctly during typing.

Outlook

  • This update improves search in classic Outlook on Japanese-language devices, helping searches in Sent Items and Advanced Find display the correct "To" label and return expected results.

Pointer

  • This update improves touchpad reliability on some devices, helping touchpad gestures and mouse-drag actions respond as expected.

If you installed earlier updates, your device downloads and installs only the new updates contained in this package.


Components updates

AI components

This release updates the following AI components to version 1.2608.951.0: Image Search, Content Extraction, Semantic Analysis, and Settings Model.

To learn more, see Release information for AI components.

Servicing stack update (SSU)

Includes KB5120997 (Build 26100.9270), which improves the reliability of the Windows update installation process. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.

Known issues in this update

Microsoft is not currently aware of any issues with this update.

How to get this update

Before you install this update

Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

Deployment

If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

Note

The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

To ensure the boot.stl file is included as part of the installation media, do one of the following:

  • Use the Update WinPE script to update an existing Windows image. (Recommended)
  • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

Install this update

To install this update, use one of the following Windows and Microsoft release channels.


Available Next Step
Available Open Start > Settings > Windows Update > Advanced options > Optional updates. In the Optional updates available area, you will find the link to download and install available updates.
Check for optional updates

File information

For a list of the files provided in this update, download the file information for cumulative update KB5120998.

For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5120997) - version 26100.9274.

Windows monthly updates explained

Description of the standard terminology used for Microsoft software updates

Microsoft Store for Business and Education with Configuration Manager

Get updates for apps and games in Microsoft Store