NAVANEM
Out-of-bandOS build 26200.7093

November 20, 2025 Hotpatch KB5072753 (OS Build 26200.7093) Out-of-Band

Out-of-band hotpatch for Windows 11 Enterprise LTSC 2024, OS build 26200.7093, fixing a re-offer loop after the November 2025 security update.

KB5072753: November 20, 2025 Hotpatch KB5072753 (OS Build 26200.7093) Out-of-Band — navanem Microsoft KB cover
KB5072753 · Windows 11 · Out-of-Band Update

Summary

This is a cumulative out-of-band (OOB) hotpatch update for Windows 11, version 25H2, released November 20, 2025, reaching OS Build 26200.7093. It applies to Windows 11 Enterprise LTSC 2024 and carries forward all fixes from the November 11, 2025 security update (KB5068966), plus one targeted quality fix. No device restart is required. Source: Microsoft Support.

Improvements and fixes

  • This OOB update is cumulative and includes all security fixes and improvements from the November 11, 2025 security update (KB5068966).
  • Fixed an issue where, after installing the November 2025 Hotpatch update (KB5068966) on Windows 11, version 25H2, Windows Update could download and install the update a second time. This re-offer did not affect functionality - only the update history would reflect the latest installation timestamp.
  • No restart is required after installing this OOB update.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Before installing, note that Microsoft bundles the latest servicing stack update (SSU) with the hotpatch update. The SSU in question is KB5067035, version 26100.7010. If you are using Windows Update, the latest SSU installs automatically alongside this update.

This update is available through the following channels:

  • Windows Update / Microsoft Update - downloads and installs automatically.
  • Microsoft Update Catalog - available for manual download.
  • Windows Server Update Services (WSUS) - available for enterprise deployment.

File information for the cumulative update (KB5072753) and the SSU (KB5067035, version 26100.7010) can be downloaded from Microsoft.

Arm64 prerequisites: To use Hotpatch on Arm64 devices, the device must run Windows 11 Enterprise version 25H2 or 24H2 (Build 26100.4929 or later) with the current baseline update installed, be managed via Microsoft Intune with a Hotpatch-enabled Windows quality update policy, hold an eligible license (Windows 11 Enterprise E3/E5, Microsoft 365 F3, Windows 11 Education A3/A5, Microsoft 365 Business Premium, or Windows 365 Enterprise), have Virtualization-based Security (VBS) enabled, and have Compiled Hybrid PE (CHPE) disabled.

To disable CHPE on Arm64, either apply the CSP setting ./Device/Vendor/MSFT/Policy/Config/Hotpatch/DisableCHPE = 1 via Microsoft Intune or Group Policy, or set the registry value HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\HotPatchRestrictions = 1, then restart the device once.

To enroll Arm64 devices, go to the Microsoft Intune admin center, navigate to Devices > Windows updates > Quality updates, create or edit a Windows quality update policy, and ensure that "When available, apply without restarting the device" is set to Allow, then assign the policy to your Arm64 device group.

Note: Hotpatch is now generally available for Windows 11, version 25H2 and 24H2 (Arm64) devices.

Important - Secure Boot certificate expiration: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Microsoft will continue to deliver the newer certificates via Windows updates. IT administrators should follow the guidance in the Secure Boot Playbook for Windows clients and Windows Server.

Frequently asked questions

Does installing KB5072753 require a device restart?

No. Microsoft explicitly states that no restart is required after installing this OOB hotpatch update. This is consistent with the core benefit of Hotpatch technology, which applies security and quality fixes to in-memory code without interrupting active user sessions or forcing a reboot cycle.

What problem does this out-of-band update specifically fix?

It resolves a re-offer loop where Windows Update could download and install the November 2025 Hotpatch (KB5068966) a second time after it had already been applied. The issue had no functional impact on the operating system - only the update history was affected, showing a newer installation timestamp.

Is the servicing stack update included, or does it need to be installed separately?

Microsoft bundles the latest SSU (KB5067035, version 26100.7010) with this hotpatch update. If you are installing via Windows Update, the SSU deploys automatically alongside KB5072753. You do not need to locate or install it as a separate step.

Which devices and license types are eligible for Hotpatch on Arm64?

Arm64 devices must run Windows 11 Enterprise version 25H2 or 24H2 at Build 26100.4929 or later, be managed through Microsoft Intune with a Hotpatch-enabled quality update policy, and hold one of the following licenses: Windows 11 Enterprise E3 or E5, Microsoft 365 F3, Windows 11 Education A3 or A5, Microsoft 365 Business Premium, or Windows 365 Enterprise. VBS must be enabled and CHPE must be disabled.

#hotpatch#out-of-band#windows-11#ltsc-2024#servicing-stack#arm64#november-2025

Related topics