KB5068840 Hotpatch for Windows Server 2022 Datacenter: Azure Edition (OS Build 20348.4346)
November 11, 2025 hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, bringing the OS to build 20348.4346 with miscellaneous internal security improvements.

Summary
This is a hotpatch security update for Windows Server 2022 Datacenter: Azure Edition, released on November 11, 2025, bringing the OS to build 20348.4346. It delivers miscellaneous internal OS security improvements with no additional documented fixes. The update is available through Windows Update, Microsoft Update, and WSUS. Source: Microsoft Support.
Improvements and fixes
- This update applies miscellaneous security improvements to internal OS functionality. Microsoft notes no additional issues were documented for this release. Devices that have already installed previous updates will download and install only the new content included in this package.
Known issues
WSUS does not display synchronization error details
Symptom: After installing KB5070892 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting interface.
Workaround: This functionality was temporarily removed by Microsoft to address the Remote Code Execution Vulnerability CVE-2025-59287. No additional workaround is documented at this time.
How to get this update
Prerequisite: Microsoft now combines the latest servicing stack update (SSU) for the operating system with the hotpatch update. If you are using Windows Update or WSUS, the latest SSU installs automatically alongside this update. The servicing stack update for this release is KB5068786, version 20348.4400.
This update is available through the following channels:
- Windows Update and Microsoft Update - The update downloads and installs automatically.
- Windows Update Catalog - Available for manual download and deployment.
- Windows Server Update Services (WSUS) - The update syncs automatically when you configure Products and Classifications as follows: Product set to Server 2022 Hotpatch Category, Classification set to Security Updates.
For a full list of files provided in this update, download the file information for cumulative update KB5068840. For the servicing stack file list, download the file information for SSU KB5068786, version 20348.4400.
Frequently asked questions
What is a hotpatch update and how does it differ from a standard cumulative update?
A hotpatch update applies security fixes to running processes in memory without requiring a system restart for those patches to take effect. This is distinct from a standard cumulative update, which typically requires a full reboot. Hotpatch updates are available exclusively for Windows Server 2022 Datacenter: Azure Edition in this context.
Does this update include the servicing stack update?
Yes. Microsoft now bundles the latest servicing stack update with the hotpatch package. If you are deploying through Windows Update or WSUS, the SSU - KB5068786, version 20348.4400 - installs automatically alongside this update. No separate SSU installation step is required.
What should I know about the Windows Secure Boot certificate expiration notice in this release?
Microsoft notes that Secure Boot certificates used by most Windows devices are set to expire beginning in June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices. Devices that have not yet received newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for managed environment guidance.
Why is WSUS not showing synchronization error details after recent updates?
Starting with KB5070892, WSUS no longer displays synchronization error details in its error reporting interface. Microsoft temporarily removed this functionality specifically to remediate the Remote Code Execution Vulnerability tracked as CVE-2025-59287. Administrators should monitor Microsoft documentation for updates on when this reporting capability will be restored.






