Microsoft has published extended security update KB5122878 for Windows 10 Enterprise LTSC and systems enrolled in the ESU program, bundling coverage from the September 2026 Patch Tuesday that addressed 966 vulnerabilities including two actively exploited zero-day flaws. Systems move to build 19045.7725, while Windows 10 Enterprise LTSC 2021 moves to build 19044.7725, with Microsoft reporting no new features and no known issues.

How to install and version impact

The release is intended for remaining supported branches only: Windows 10 Enterprise LTSC and ESU-enrolled PCs. Administrators and users obtain it through the normal in-box updater by opening Settings, selecting Windows Update, then manually initiating a Check for Updates.

After a successful installation, the OS revision changes to:

  • Windows 10: build 19045.7725
  • Windows 10 Enterprise LTSC 2021: build 19044.7725

Microsoft describes the package as security plus bug-fix only, with no feature additions for Windows 10.

Security scope

KB5122878 incorporates the fixes shipped as part of the September 2026 Patch Tuesday. That monthly baseline is described as record-breaking in scale, correcting a massive 966 vulnerabilities across Microsoft products, including two actively exploited zero-day flaws.

No separate CVE list is enumerated in this cumulative KB notice itself; organizations that must triage specific CVEs should correlate their exposure against that September 2026 baseline.

Non-security fixes in this release

Six functional areas are called out:

Secure Boot: Adds additional high-confidence device targeting data, broadening the set of devices qualified to automatically obtain new Secure Boot certificates. Certificate rollout through Windows updates is continuing over the coming months across supported PCs and non-managed business devices.

Date and Time: Revises Morocco Standard Time to account for Morocco's move to permanent UTC+00:00 effective September 20, 2026. The adjustment is intended to keep displayed local time correct after that transition.

OMA DM protocol: Enhances diagnostics for the OMA DM Client component, omadmclient.exe. Connections to a server now retain more debug information.

Windows Code Integrity policies: Eases application compatibility during the Windows certificate-authority rotation by treating Microsoft Windows Production PCA 2026 RSA2048-SHA256 as equivalent to PCA 2011.

Remote Desktop: Corrects a condition affecting Remote Desktop audio redirection, where audio from the remote session might not play on the local computer in certain configurations.

BitLocker Group Policy: Resolves the “Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key” known issue.

Microsoft says there are no known issues with this update.

Technical background

This section is general background on this class of update, not new facts about this incident.

Extended Security Updates keep an otherwise out-of-support Windows 10 branch receiving monthly security fixes without adding features. Secure Boot certificate and Code Integrity PCA rotations are ecosystem-wide trust transitions: endpoints must learn to accept new signing authorities before old certificates expire, or boot validation and allow-listed application checks can fail.

For generic verification on a lab machine, administrators commonly confirm OS build and update state with built-in tools, for example:


winver
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
wmic qfe list brief /format:table

BitLocker policy and recovery posture can likewise be reviewed in general terms before broad deployment, for example:


manage-bde -status
gpresult /h C:\temp\gpreport.html

Test certificate deployment, time-zone behavior, RDP audio redirection, MDM enrollment logging, and BitLocker unlock prompts in a pilot ring before wide rollout.