Microsoft released cumulative update KB5075941 for Windows 11 version 23H2 (2023 Update) as part of the February Patch Tuesday for 2026. This mandatory security update is intended for Enterprise and Education editions on x64 (amd64) and ARM64 processors and combines fixes from previous releases, including the January update KB5073455 and out-of-band updates KB5077797 and KB5078132. The main goal is to improve system reliability, boot security, and graphics subsystem stability, bringing the build to 22631.6649.
- Secure Boot. Changes have been made to the bootloader for devices with the installed Windows UEFI CA 2023 certificate: the bootmgfw.efi file (signed in 2011) is replaced with a version signed in 2023. The update is deployed in stages — new Secure Boot certificates are installed only on devices that have successfully passed previous checks. When resetting the Secure Boot database or changing its state, a "Secure Boot violation" error may occur, and in rare cases, a special bootable media will be required for recovery.
- Desktop Window Manager (DWM). Fixed an issue where the Desktop Window Manager process could unexpectedly restart, leading to graphics display failures.
- File Explorer. Fixed a folder renaming bug where folders containing a desktop.ini file ignored the LocalizedResourceName parameter, preventing custom folder names from being displayed.
- Fonts and Display. Updated Chinese fonts to support the GB18030-2022A standard, expanded character coverage, and ensured their correct display.
- Graphics (dxgmms2.sys). Fixed an error that, in certain GPU configurations, caused a system crash with a KERNEL_SECURITY_CHECK_FAILURE error related to the dxgmms2.sys file.
- OS Security. Resolved a previously known issue where some PCs with Virtual Secure Mode (VSM) enabled could not properly shut down or enter sleep mode, and instead rebooted.
- Windows Security (SmartScreen). Fixed an error where Microsoft Defender SmartScreen application reputation events (AppRep) were not logged, making it difficult to investigate complex threats.
Installation via Windows Update: cumulative update KB5075941 for PCs is automatically installed via Windows Update for Enterprise and Education editions. To check for availability, open Settings > Windows Update and click Check for updates.
How the new features work:
Secure Boot: During UEFI boot, digital signatures of loaders are verified. The update replaces the old bootmgfw.efi (2011 signature) with a 2023 version signed by the new Windows UEFI CA 2023 certificate. Staged deployment ensures certificates install only on verified devices. Resetting the Secure Boot database may cause integrity violations, requiring bootable recovery media.
Desktop Window Manager (DWM): DWM handles window composition and UI rendering via DirectX. A bug caused unexpected dwm.exe restarts due to improper handle handling or video driver conflicts. The fix stabilizes the rendering loop and prevents crashes that led to black screens or display tearing.
File Explorer: In folders containing desktop.ini, the LocalizedResourceName parameter sets a localized display name. Previously, renaming caused Explorer to ignore this parameter and revert to the default name. The fix correctly syncs user-initiated name changes with system metadata, preserving localized labels.
Fonts and Display: Chinese fonts are updated to the GB18030-2022A standard, adding new characters and symbols. The system uses OpenType and DirectWrite for correct glyph rendering. The update enriches the character substitution table, eliminating missing‑character issues in documents and web pages.
Graphics (dxgmms2.sys): The dxgmms2.sys driver manages video memory and DirectX command scheduling. A bug caused a KERNEL_SECURITY_CHECK_FAILURE crash due to integrity check violations from improper buffer handling on rare GPU configs. The patch fixes input validation and prevents system crashes.
OS Security: Virtual Secure Mode (VSM) creates isolated memory regions called Virtual Trust Levels. A bug prevented correct ACPI command handling during sleep or shutdown, causing a reboot instead. The fix adjusts hypervisor and power driver interaction, allowing proper VSM session termination before power state changes.
Windows Security (SmartScreen): SmartScreen checks executable file reputation. AppRep events were not logged in Windows Defender due to a telemetry channel bug. Logging is now restored, enabling admins to track unknown application blocks and analyze complex attacks via Microsoft Defender for Endpoint.
The last 10 Windows updates:
| Update | Build | Version | Windows | Channel | Date |
|---|---|---|---|---|---|
| KB5101587 | 28020.2539 | 26H1 | Windows 11 | Beta | 2026-07-20 |
| KB5101594 | 26220.8925 | 25H2 | Windows 11 | Beta | 2026-07-20 |
| KB5101589 | 26300.8935 | 26H2 | Windows 11 | Experimental | 2026-07-20 |
| KB5101681 | 28000.2605 | 26H1 | Windows 11 | Preview | 2026-07-20 |
| KB5101684 | 26200.8968 | 25H2 | Windows 11 | Preview | 2026-07-20 |
| KB5121767 | 26200.8894 | 25H2 | Windows 11 | Stable | 2026-07-19 |
| KB5099414 | 22631.7376 | 23H2 | Windows 11 | Stable | 2026-07-14 |
| KB5099539 | 19045.7548 | 22H2 (ESU) | Windows 10 | Stable | 2026-07-14 |
| KB5101649 | 28000.2525 | 26H1 | Windows 11 | Stable | 2026-07-14 |
| KB5101650 | 26200.8875 | 25H2 | Windows 11 | Stable | 2026-07-14 |