NAVANEM
Security updateOS build 26200.7171 and 26100.7171

KB5068861: Windows 11 Security Update for Builds 26200.7171 and 26100.7171 (November 2025)

November 11, 2025 cumulative security update for Windows 11 versions 25H2 and 24H2, delivering OS builds 26200.7171 and 26100.7171 with security fixes and quality improvements.

KB5068861: Windows 11 Security Update for Builds 26200.7171 and 26100.7171 (November 2025) — navanem Microsoft KB cover
KB5068861 · Windows 11 · Security Update

Summary

This is the November 11, 2025 cumulative security update for Windows 11, versions 25H2 and 24H2, producing OS builds 26200.7171 and 26100.7171. Released on November 11, 2025, it delivers the latest security fixes alongside non-security improvements carried forward from last month's optional preview release. See the Microsoft Support page for full details.

Highlights

  • This update addresses security issues for the Windows operating system.

Improvements and fixes

This update incorporates all fixes and quality improvements from KB5067036 (released October 28, 2025). The following changes are included:

  • Gaming - battery drain fix: Corrects an issue on gaming handheld devices that prevented the devices from staying in low-power states, which caused faster than expected battery drain.
  • Gaming - controller delay fix: Addresses a problem on some handheld gaming devices where, after signing in with the built-in Gamepad, the controller stopped responding in apps for approximately five seconds. As part of this fix, the touch keyboard on the sign-in screen now hides automatically after a password or PIN is submitted.
  • Storage Spaces fix: Resolves a problem that could cause some Storage Spaces to become inaccessible, or cause Storage Spaces Direct to fail when creating a storage cluster.
  • Task Manager fix: Corrects a known issue introduced by KB5067036 in which closing Task Manager using the Close button did not fully end the process, leaving background instances running that could slow system performance over time.
  • Voice Access fix: Fixes a failure during the initial Voice Access setup that occurred when no microphone was connected and the voice model had not been installed.
  • Window management fix: Addresses a problem where clicking on the desktop would unexpectedly open Task View.
  • Networking - HTTP.sys fix: Fixes a parsing issue in the HTTP.sys request parser. The parser was permitting a single line break within HTTP/1.1 chunk extensions, whereas the RFC 9112 standard requires a carriage return and line feed (CRLF) sequence to terminate each chunk. This discrepancy could cause problems when front-end proxies are part of the setup. Administrators who need to turn off strict parsing can set the following registry value to 1: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Http\Parameters - HttpAllowLenientChunkExtParsing (DWORD).

This release also updates the following AI components to version 1.2510.1159.0: Image Search, Content Extraction, Semantic Analysis, and Settings Model. These components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.

Known issues

Password icon missing on lock screen

Symptom: After installing the August 2025 non-security preview update (KB5064081) or any later update, the password icon may not be visible in the sign-in options on the lock screen. The password button is still functional - hovering over the area where the icon should appear reveals the button, and selecting it opens the password text box for normal sign-in. This issue primarily affects enterprise or managed IT environments; users on Windows Home or Pro editions on personal devices are very unlikely to see it.

Workaround: This issue is addressed in KB5074105.

Mirror networking on WSL may fail with VPN

Symptom: After installing the October 2025 non-security preview update (KB5067036, released October 28, 2025) or a later update, mirrored networking mode in Windows Subsystem for Linux (WSL) may cause problems with some third-party VPNs. Affected systems may show a "No route to host" error even though the Windows host can still reach the same destinations, potentially blocking access to corporate resources over VPN. This occurs because the VPN application's virtual interface does not respond to ARP requests. Cisco Secure Client (formerly Cisco AnyConnect) and OpenVPN are reported as affected. Home users on Windows Home or Pro editions are unlikely to experience this issue.

Workaround: This issue is addressed in KB5074109.

How to get this update

Microsoft bundles the latest servicing stack update (SSU) for the operating system with the latest cumulative update (LCU) in a single package. The included SSU for this release is KB5067035, version 26100.7010.

  • Windows Update and Microsoft Update: The update downloads and installs automatically.
  • Windows Update for Business: The update deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: Download the standalone package from the Microsoft Update Catalog website. This KB contains MSU files that must be installed in a specific order. You can install them together using DISM (pointing it at a folder containing all MSU files), or individually in the following order: windows11.0-kb5043080-x64.msu first, then windows11.0-kb5068861-x64.msu. DISM commands can be run from an elevated Command Prompt or elevated PowerShell prompt against both running systems and offline installation media.
  • WSUS: The update syncs automatically when Products is set to Windows 11 and Classification is set to Security Updates.

Note: To remove the LCU after installation, use DISM /online /remove-package. Running wusa.exe /uninstall against the combined package will not work because the SSU is included and cannot be removed after installation.

Frequently asked questions

Does this update include non-security improvements, or only security fixes?

This update includes both. It delivers the latest security fixes for Windows 11 and also incorporates non-security quality improvements that were first published in last month's optional preview release (KB5067036, released October 28, 2025). Devices that already installed KB5067036 will only download the new content added in this package.

Will the AI component updates install on all Windows 11 devices?

No. Although the AI component updates are bundled within this cumulative update package, they apply exclusively to Windows Copilot+ PCs. The updated components - Image Search, Content Extraction, Semantic Analysis, and Settings Model - will not install on standard Windows PCs or Windows Server machines.

Will there be a non-security preview update in December 2025?

No. Microsoft has announced that due to reduced operations during the Western holidays in December and New Year's Day, no non-security preview update will be released in December 2025. The regular monthly security update will still be available as scheduled. Both security and non-security preview updates will resume in January 2026.

Should I be concerned about Secure Boot certificate expiration?

Microsoft notes that Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices over recent months. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should follow guidance in the Secure Boot Playbook for Windows clients and Windows Server to check and manage device status.

#windows-11#security-update#cumulative-update#november-2025#gaming#networking#storage-spaces

Related topics