NAVANEM
Out-of-bandOS build 26100.6588

KB5068221 (OS Build 26100.6588): Windows 11 24H2 Out-of-Band Update, September 22 2025

KB5068221 is an out-of-band cumulative update for Windows 11 version 24H2, releasing OS build 26100.6588. It fixes an App-V double handle closure issue and includes all September 2025 security fixes.

KB5068221: KB5068221 (OS Build 26100.6588): Windows 11 24H2 Out-of-Band Update, September 22 2025 — navanem Microsoft KB cover
KB5068221 · Windows 11 · Out-of-Band Update

Summary

KB5068221 is an out-of-band (OOB) cumulative update for Windows 11 version 24H2, producing OS build 26100.6588. Released on September 22, 2025, it carries all security fixes from the September 9, 2025 security update (KB5065426) and adds a targeted quality fix for a crash in Microsoft App-V environments. Source: Microsoft Support.

Improvements and fixes

  • Fixed a problem affecting Microsoft Office applications running inside Microsoft Application Virtualization (App-V) environments. The failure was caused by a double handle closure in the AppVEntSubsystems32 or AppVEntSubsystems64 system component, and this update resolves that condition.
  • Includes all security fixes and improvements delivered in the September 9, 2025 security update (KB5065426), making this a fully cumulative package.
  • Updates several AI components - Image Search, Content Extraction, Semantic Analysis, and Settings Model - all brought to version 1.2508.906.0. Note that these AI component updates apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server devices.
  • Incorporates the Windows 11 servicing stack update KB5064531 (version 26100.5074), which improves the reliability of the component responsible for installing Windows updates.

Known issues

SMBv1 protocol connectivity failure

Symptom: After installing Windows updates released on or after September 9, 2025, connections to shared files and folders using the Server Message Block (SMB) v1 protocol over NetBIOS over TCP/IP (NetBT) may fail. The issue can occur when either the SMB client or the SMB server has the September 2025 security update installed. Deployments using SMBv2 or SMBv3 are not affected. Note that SMBv1 is deprecated and is no longer installed by default in modern Windows and Windows Server versions.

Workaround: This issue is addressed in KB5065789.

Protected content playback failures in Blu-ray, DVD, and Digital TV apps

Symptom: Some Digital TV and Blu-ray/DVD applications may not play protected content correctly after installing the August 29, 2025 non-security preview update (KB5064081) or later updates. Apps using Enhanced Video Renderer with HDCP enforcement or Digital Rights Management (DRM) for digital audio may show copyright protection errors, frequent playback interruptions, unexpected stops, or black screens. Streaming services are not affected.

Workaround: The non-security September 2025 Windows preview update (KB5065789) and later updates address problems affecting applications using Enhanced Video Renderer (EVR) with HDCP enforcement. The non-security October Windows preview update (KB5067036) includes additional improvements for applications using DRM for digital audio.

Password icon missing or invisible on the lock screen

Symptom: After installing the August 2025 non-security preview update (KB5064081) or later updates, the password icon may not be visible in the sign-in options on the lock screen. Hovering over the area where the icon should appear confirms the password button is still present and functional. Selecting the placeholder opens the password text box and allows normal sign-in. This issue primarily affects enterprise or managed IT environments; users on Windows Home or Pro on personal devices are very unlikely to encounter it.

Workaround: This issue is addressed in KB5074105.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) together with the latest cumulative update (LCU), so no separate SSU installation is required before applying this package.

  • Windows Update / Windows Update for Business: The update is available automatically for eligible devices.
  • Microsoft Update Catalog: Download the standalone package directly from the Catalog website. This KB contains more than one MSU file that must be installed in a specific order.
    • Method 1 - Install all MSU files together: Download all MSU files for KB5068221 into a single folder and use DISM.exe to install the target update; DISM will automatically discover and install any prerequisite MSU files from that folder.
    • Method 2 - Install each MSU file individually in order: First install windows11.0-kb5043080-x64_953449672073f8fb99badb4cc6d5d7849b9c83e8.msu, then install windows11.0-kb5068221-x64_99f1d28d2ad67768689819e500449f633ee7d8b9.msu.
  • WSUS (Server Update Services): The update is available through this channel as well.

To remove the LCU after installing the combined SSU and LCU package, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall on the combined package will not work because the SSU component cannot be removed after installation.

Frequently asked questions

Why was this update released out-of-band rather than on Patch Tuesday?

Microsoft releases out-of-band updates outside the regular monthly schedule when a specific quality or reliability issue is serious enough to warrant an immediate fix. In this case, the double handle closure bug in App-V environments was causing Microsoft Office application failures that could not wait until the next scheduled release.

Do I need to install any prerequisite updates before applying KB5068221?

No separate prerequisite step is required. Microsoft has combined the servicing stack update (KB5064531, version 26100.5074) with this cumulative update. If you are installing from the Microsoft Update Catalog using Method 2, install the KB5043080 MSU file first, then the KB5068221 MSU file.

Will the AI component updates in this package install on all Windows 11 devices?

No. Although the AI component updates - Image Search, Content Extraction, Semantic Analysis, and Settings Model, all at version 1.2508.906.0 - are bundled in the package, they will only install on Windows Copilot+ PCs. They will not install on standard Windows PCs or Windows Server devices.

What should I do about the Secure Boot certificate expiration warning?

Microsoft notes that Secure Boot certificates on most Windows devices are set to expire starting June 2026. Devices that have not yet received updated certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should review the Secure Boot Playbook for Windows clients and Windows Server. Device certificate status can be checked through the Windows Security app.

#windows-11#out-of-band#24h2#app-v#cumulative-update#servicing-stack#smb

Related topics