The June 2026 security update is now available for all supported versions of Windows. We recommend that you install these updates promptly. For more information about the contents of this update, see the release notes, which are easily accessible from the Windows 11 update history page. To learn more about the different types of monthly quality updates, see Windows monthly updates explained.
Highlights for the Windows 11, version 25H2 update:
- This security update includes improvements that were a part of update KB5089573 (released May 26, 2026).
- This update expands high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Devices receive the new certificates only after demonstrating sufficient successful update signals, maintaining a controlled and phased rollout.
- This update includes a resolution for CVE‑2026‑45585 (BitLocker security feature bypass). The mitigation script remains part of the guidance and does not need to be reverted.
Short on time? Watch our Windows 11 release notes video for this month's tips.
For instructions on how to install this update, see the KB for your operating system listed below:
• Windows 11, version 26H1: KB5095051
• Windows 11, versions 25H2 and 24H2: KB5094126
• Windows 11, version 23H2: KB5093998
• Windows 11 Enterprise LTSC 2024: Baseline KB5094126
• Windows 10, versions 22H2 and 21H2: KB5094127
• Windows 10 Enterprise LTSC 2019 and Windows Server 2019: KB5094123
• Windows 10 LTSB 2016 and Windows Server 2016: KB5094122
• Windows Server 2025: KB5094125
• Windows Server 2025 Datacenter: Azure Edition: Baseline KB5094125
• Windows Server 2022: KB5094128
• Windows Server 2022 Datacenter: Azure Edition: Baseline KB5094128
• Windows Server 2012 R2: KB5094041
• Windows Server 2012: KB5094042
Note: With recent and upcoming Windows updates over the next few months, a limited number of consumer and business devices might experience one additional restart during installation. This one‑time restart occurs after a Secure Boot certificate update is applied as part of the Secure Boot update process.