KB5070773: Windows 11 Out-of-Band Update for OS Builds 26200.6901 and 26100.6901 (October 20, 2025)
Out-of-band cumulative update for Windows 11 versions 24H2 and 25H2, fixing USB device failure in WinRE after the October 14 security update.

Summary
This is an out-of-band (OOB) cumulative update for Windows 11 versions 24H2 and 25H2, bringing OS builds to 26200.6901 and 26100.6901. Released on October 20, 2025, it includes all security fixes from the October 14, 2025 update (KB5066835) plus a targeted fix for USB devices failing in the Windows Recovery Environment. See the full release notes on Microsoft Support.
Improvements and fixes
- USB fix in WinRE: Resolves an issue introduced by the October 14, 2025 security update (KB5066835) where USB input devices such as keyboards and mice stopped working inside the Windows Recovery Environment (WinRE), blocking navigation of all recovery options. USB devices continued to work normally within the standard Windows OS.
- AI component updates: Updates several AI components to version 1.2509.1022.0, covering Image Search, Content Extraction, Semantic Analysis, and Settings Model. These components apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
- Servicing stack update (KB5067360, build 26100.6893): Includes a servicing stack update that improves the reliability of the component responsible for installing Windows updates, ensuring devices can continue to receive and apply Microsoft updates correctly.
Known issues
Problems playing protected content in some Blu-ray, DVD, and Digital TV apps
Symptom: After installing the August 29, 2025 non-security preview update (KB5064081) or any later update, some Digital TV and Blu-ray/DVD apps may fail to play protected content. Apps using Enhanced Video Renderer with HDCP enforcement or Digital Rights Management (DRM) for digital audio may show copyright protection errors, frequent playback interruptions, unexpected stops, or black screens. Streaming services are not affected.
Workaround: The non-security September 2025 preview update (KB5065789) and later updates address problems affecting apps that use Enhanced Video Renderer (EVR) with HDCP enforcement. The non-security October preview update (KB5067036) includes additional improvements for apps using DRM for digital audio.
IIS websites might fail to load
Symptom: After installing the non-security September update (KB5065789) for Windows 11 version 25H2, or the security October update (KB5066835) for Windows 11 version 24H2, server-side applications relying on HTTP.sys may experience problems with incoming connections. This can cause IIS websites - including those hosted on http://localhost/ - to fail to load and display an error such as "Connection reset - error (ERR_CONNECTION_RESET)" or similar. The issue depends on factors including internet connectivity, update installation timing, and device restarts, and may not occur in all environments. To resolve it where observed: open Settings, go to Windows Update, check for and install any available updates, then restart the device even if no updates were installed.
Workaround: This issue is addressed in KB5067036.
Password icon might be missing or invisible on the lock screen
Symptom: After installing the August 2025 non-security preview update (KB5064081) or later updates, the password icon may not appear in the sign-in options on the lock screen. Hovering over the blank space reveals the button is still present; selecting it opens the password text box and sign-in proceeds normally. This issue primarily affects enterprise or managed IT environments. Users on Windows Home or Pro on personal devices are very unlikely to encounter it.
Workaround: This issue is addressed in KB5074105.
How to get this update
The update is cumulative and already incorporates the latest servicing stack update (SSU), so no separate SSU installation is required beforehand. It is available through the following channels:
- Windows Update and Microsoft Update: The update downloads and installs automatically.
- Windows Update for Business: Available through standard policy-managed deployment.
- Microsoft Update Catalog: Download the standalone package(s) for manual or scripted deployment. The Catalog entry contains multiple MSU files that must be installed in the correct order. You can install all MSU files together using DISM with a shared folder path, or install them individually in sequence - starting with the SSU MSU (KB5043080) before the main update MSU (KB5070773).
- Windows Server Update Services (WSUS): Available through the standard WSUS sync.
If you need to remove only the Latest Cumulative Update (LCU) after installation, use DISM /online /remove-package with the LCU package name. Note that the SSU cannot be removed after installation, and running wusa.exe /uninstall on the combined package will not work.
Frequently asked questions
Why was this update released outside the normal Patch Tuesday cycle?
Microsoft issued this as an out-of-band update to address a specific regression introduced by the October 14, 2025 security update (KB5066835). That update caused USB keyboards and mice to stop functioning inside WinRE, preventing administrators and users from navigating recovery options. The severity of that breakage justified an emergency release rather than waiting for the next scheduled update.
Do I need to uninstall KB5066835 before applying KB5070773?
No. KB5070773 is cumulative and includes all fixes from KB5066835, plus the USB regression fix on top. Simply installing KB5070773 is sufficient. There is no need to uninstall or roll back the previous update first.
Will the AI component updates in this package install on all Windows 11 devices?
No. Although the AI component updates are bundled inside the package, Microsoft states they apply only to Windows Copilot+ PCs. They will not install on standard Windows PCs or Windows Server machines, so there is no action required to prevent them from deploying to non-Copilot+ hardware.
What should I do about the upcoming Secure Boot certificate expiration?
Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been distributing updated certificates to consumer and non-managed business devices for several months. Devices that have not yet received newer certificates will continue to start and operate normally, and standard Windows updates will still install. Microsoft will continue pushing the updated certificates via Windows Update. IT administrators should review the Secure Boot Playbook for Windows clients and Windows Server, and can check device status in the Windows Security app.









