IMPORTANT: This notice is only relevant for environments where:
- Windows 11, version 26H1, 25H2, or 24H2 is deployed
- Scan Cab is used to check for update compliance
- The September 2026 Scan Cab was deployed before 10:00 AM PDT on September 14, 2026
What and why:
An updated version of the September 2026 Scan Cab was made available at 10:00 AM PDT on September 14, 2026. This Scan Cab includes new metadata corresponding to new updates for Windows 11, versions 26H1, 25H2 and 24H2.
The new Microsoft update for Windows 11, versions 26H1, 25H2 and 24H2 released on September 14, 2026, included additional security protections to address CVE-2026-62721: Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability. The update for Windows 11, version 26H1 also addressed CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability. See the additional information section of this message for details.
Rollout schedule:
The updated September 2026 Scan Cab was made available at 10:00 AM PDT on September 14, 2026.
Who is affected:
IT administrators who downloaded the Scan Cab before 10:00 AM PDT on September 14, 2026, should re-acquire and re-deploy it if the Scan Cab is used to assess updates for environments running Windows 11, versions 26H1, 25H2 or 24H2.
No action is required on environments where Scan Cab is not employed and that do not run Windows 11, versions 26H1, 25H2 or 24H2. However, please note that there might be non-Microsoft applications that utilize Scan Cab. Review the documentation for any software and update deployment tools that might be in use for your organization, to understand if this is applicable in your environment.
What will happen:
Administrators can re-deploy the updated Scan Cab via their usual processes. For detailed guidance, see the Additional information section below.
Additional information:
- Updated Scan Cab: Download the new Scan Cab here
- Announcing a smaller WSUS Scan Cab - Microsoft Tech Community: Learn more about WSUS and the Scan Cab process
- CVE-2026-62721: Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability
- CVE-2026-85921: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- Using WUA to Scan for Updates Offline - Win32 apps: Windows Update Agent (WUA) can be used to scan computers for security updates without connecting to Windows Update
- WSUS and the Catalog Site: The Catalog Site used by WSUS to import updates and drivers