December 9, 2025 Hotpatch KB5072014 (OS Build 26100.7392) for Windows Server 2025
Hotpatch KB5072014 delivers security improvements to Windows Server 2025 Datacenter and Standard machines on Azure Arc at OS Build 26100.7392, released December 9, 2025.

Summary
This is a Hotpatch security update for Windows Server 2025 Datacenter and Standard machines connected to Azure Arc, released on December 9, 2025, at OS Build 26100.7392. Hotpatch servicing lets eligible machines install OS security updates without requiring a restart. See the full details on Microsoft Support.
Improvements and fixes
- This update applies miscellaneous security improvements to internal OS functionality.
Known issues
WSUS does not display synchronization error details
Symptom: After installing KB5070893 or later updates, Windows Server Update Services (WSUS) no longer displays synchronization error details in its error reporting. This functionality was temporarily removed to address the Remote Code Execution Vulnerability CVE-2025-59287.
Workaround: No workaround is listed beyond the explanation above. Administrators should monitor official guidance for a resolution.
Some Hotpatch-enabled machines may receive updates that require a restart
Symptom: The out-of-band update for Windows Server 2025 (KB5070881) was briefly offered to all Windows Server 2025 machines regardless of Hotpatch enrollment. Machines that installed KB5070881 will temporarily stop receiving Hotpatch updates and will instead receive security updates that require a restart.
Workaround: This issue is addressed in KB5073379.
Announcements
Microsoft has flagged an important notice about Secure Boot certificate expiration. Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been deploying updated certificates to consumer and non-managed business devices over recent months. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Microsoft states it will keep pushing updated certificates through Windows Update in the coming months. IT administrators can check device status in the Windows Security app and should follow the Secure Boot Playbook for Windows clients and Windows Server.
How to get this update
Before installing KB5072014, note that Microsoft now bundles the latest servicing stack update (SSU) with the Hotpatch update package. If you are using Windows Update, the SSU installs automatically alongside the Hotpatch update. The SSU for this release is KB5071142, version 26100.7295.
This update is available through the following channels:
- Windows Update and Microsoft Update - the update downloads and installs automatically.
- Windows Update Catalog - available for manual download and deployment.
- Windows Server Update Services (WSUS) - available for distribution through WSUS infrastructure.
For a full list of files included in the cumulative update, download the file information for cumulative update 5072014. For SSU file details, download the file information for KB5071142.
Frequently asked questions
Does this update require a machine restart?
No - this is a Hotpatch update, which is specifically designed to install OS security improvements without requiring a machine restart. However, machines that previously installed the out-of-band update KB5070881 may temporarily fall back to receiving standard updates that do require a restart, until they apply KB5073379.
Which machines are eligible for Hotpatch servicing?
Hotpatch servicing is available to Windows Server 2025 Datacenter and Standard machines connected to Azure Arc. Machines must be enrolled in Hotpatch servicing to receive updates through this channel rather than the standard monthly update cycle.
Is the servicing stack update handled separately for this release?
No - Microsoft now combines the latest SSU with the Hotpatch update package. If you deploy through Windows Update, the SSU (KB5071142, version 26100.7295) installs automatically. You do not need to stage or install the SSU independently before applying this Hotpatch.
What should administrators do about the WSUS error-detail issue introduced after KB5070893?
WSUS currently does not display synchronization error details after KB5070893 or later updates, because that functionality was temporarily removed to mitigate CVE-2025-59287. Administrators should rely on alternative logging or monitoring tools to review WSUS synchronization status and watch for further Microsoft guidance on restoration of this functionality.








