NAVANEM
Security updateOS build 19045.6937 and 19044.6937

February 10, 2026 - KB5075912 (OS Builds 19045.6937 and 19044.6937)

Monthly security update for Windows 10 version 22H2 and 21H2 LTSC, releasing OS builds 19045.6937 and 19044.6937 on February 10, 2026.

KB5075912: February 10, 2026 - KB5075912 (OS Builds 19045.6937 and 19044.6937) — navanem Microsoft KB cover
KB5075912 · Windows 10 · Security Update

Summary

KB5075912 is a monthly security update for Windows 10, covering version 22H2 (ESU) and version 21H2 (Enterprise LTSC 2021). It brings OS builds to 19045.6937 and 19044.6937 and released on February 10, 2026. The update bundles fixes from three earlier January 2026 releases and includes a combined servicing stack update (SSU KB5077456). Source: Microsoft Support

Highlights

  • Chinese font changes to meet GB18030-2022A compliance
  • Fix for Secure Launch-capable PCs with VSM enabled restarting instead of shutting down or hibernating
  • Fix for custom folder names defined via desktop.ini not appearing in File Explorer
  • Fix for a graphics stability issue affecting certain GPU configurations
  • Secure Boot certificate rollout targeting data added to Windows quality updates

Improvements and fixes

  • Chinese fonts: This update revises Chinese fonts to bring them into compliance with the GB18030-2022A standard.
  • OS security (Secure Launch / VSM): Addresses a previously known issue where PCs capable of Secure Launch and running with Virtual Secure Mode (VSM) enabled would restart instead of successfully shutting down or entering hibernation after the January 13, 2026 security update was applied.
  • File Explorer folder names: Corrects a bug in which renaming a folder whose desktop.ini file specified a LocalizedResourceName value caused that custom folder name to be ignored. Custom folder names now display correctly in File Explorer.
  • Graphics stability: Resolves a stability problem that affected certain GPU hardware configurations.
  • Secure Boot certificate rollout: Windows quality updates now carry targeting data that assesses whether a device is ready to receive updated Secure Boot certificates. Certificates are delivered only after sufficient successful update signals are recorded, supporting a phased and lower-risk rollout ahead of the June 2026 certificate expiration.
  • Servicing stack (KB5077456, builds 19045.6935 and 19044.6935): Includes enhanced logic to verify whether a device is hosted on Azure, using an updated certificate chain for validation. Microsoft strongly recommends installing this SSU before applying additional updates on Azure-hosted devices, and confirms that the device can reach the required certificate update domains.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Prerequisite - servicing stack update (SSU): The latest SSU must be installed before applying KB5075912. Skipping this step may result in the update not being offered.

  • For offline OS image servicing: If the image does not include the July 25, 2023 (KB5028244) or a later LCU, install the standalone October 13, 2023 SSU (KB5031539) first.
  • For WSUS deployment or Microsoft Update Catalog standalone installation: If devices do not have the May 11, 2021 (KB5003173) or a later LCU, install the standalone August 10, 2021 SSU (KB5005260) first.

Delivery channels:

  • Windows Update / Windows Update for Business: The update downloads and installs automatically according to configured policies.
  • Microsoft Update Catalog: The standalone package is available for manual download from the Microsoft Update Catalog website.
  • Windows Server Update Services (WSUS): The update syncs automatically when Products and Classifications are set as follows:
    • Windows 10, version 22H2 - Product: Windows 10, version 1903 and later; Classification: Security Updates
    • Windows 10, version 21H2 - Product: Windows 10 LTSB; Classification: Security Updates

Removing the LCU: Use the DISM /Remove-Package command with the LCU package name as the argument (retrieve the name with DISM /online /get-packages). Running wusa.exe /uninstall against the combined SSU+LCU package will not work, and the SSU cannot be removed after installation.

Frequently asked questions

Does this update apply to Windows 10 21H2 LTSC devices?

Yes. KB5075912 applies to both Windows 10 version 22H2 (ESU) and Windows 10 Enterprise LTSC 2021 (version 21H2). Both editions receive the same set of fixes described in the improvements list. LTSC 2021 devices should be updated to version 21H2 using the enablement package KB5003791 before applying this update.

What is included in the combined servicing stack update?

The bundled SSU is KB5077456, targeting builds 19045.6935 and 19044.6935. It improves the reliability of the update installation process and adds enhanced logic to verify Azure-hosted device identity using an updated certificate chain. Microsoft strongly recommends installing it before applying other updates on Azure-hosted devices.

Should I be concerned about the Secure Boot certificate expiration in June 2026?

Devices that have not yet received newer Secure Boot certificates will continue to start and operate normally, and standard Windows updates will continue to install. This update adds targeting data so that certificates are delivered gradually as devices demonstrate successful update signals. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for detailed guidance.

Will this update also install Microsoft Store app updates?

No. Windows updates do not deliver Microsoft Store application updates. Enterprise users should refer to Microsoft Store apps documentation in Configuration Manager, while consumer users should use the Get Updates function within the Microsoft Store app directly.

#windows-10#security-update#secure-boot#cumulative-update#ltsc-2021#22h2#servicing-stack

Related topics