KB5075941: Windows 11 Version 23H2 Cumulative Update (OS Build 22631.6649) - February 2026
February 10, 2026 security cumulative update for Windows 11 version 23H2, delivering OS Build 22631.6649 with security fixes, graphics and File Explorer repairs, and a Secure Boot certificate update.

Summary
KB5075941 is the February 10, 2026 monthly security cumulative update for Windows 11, version 23H2, producing OS Build 22631.6649. It bundles security fixes with non-security improvements carried over from the prior month's optional preview release. The update applies to all editions of Windows 11 version 23H2. Source: Microsoft Support.
Improvements and fixes
This update consolidates fixes and quality improvements from KB5073455 (January 13, 2026), KB5077797 (January 17, 2026), and KB5078132 (January 24, 2026). The following changes are documented.
- Secure Boot - Boot Manager certificate update: On devices that already have the Windows UEFI CA 2023 certificate in their Secure Boot Signature Database (DB), this release executes Boot Manager updates, replacing the 2011-signed bootmgfw.efi with the 2023-signed bootmgfw.efi. Resetting the DB or toggling Secure Boot on or off can trigger a "Secure Boot violation"; in those cases the fix is to create Secure Boot recovery media.
- Secure Boot - phased certificate rollout: Windows quality updates now include targeting data that identifies devices and their readiness to receive new Secure Boot certificates. Devices receive the new certificates only after they show sufficient successful update signals, helping ensure a safe and phased deployment.
- Display and Graphics - DWM crash: Fixes an issue that caused the Desktop Window Manager (DWM) process to restart unexpectedly.
- File Explorer - folder renaming: Fixes an issue where renaming folders that contain desktop.ini files did not work correctly. The LocalizedResourceName setting was being ignored, so custom folder names failed to appear.
- Fonts and Display - Chinese font update: Updates Chinese fonts to support the GB18030-2022A standard for character coverage and display.
- Graphics - dxgmms2.sys system error: Fixes an issue where certain GPU configurations could trigger a system error related to dxgmms2.sys, producing a KERNEL_SECURITY_CHECK_FAILURE stop error.
- OS Security - VSM shutdown and hibernation (known issue fix): Fixes an issue introduced by the January 13, 2026 or later Windows security update, where PCs running Virtual Secure Mode (VSM) were unable to shut down or enter hibernation, restarting instead.
- Windows Security - SmartScreen logging: Fixes an issue that prevented Microsoft Defender SmartScreen Application Reputation (AppRep) events from being logged, which interrupted event tracking used for advanced threat investigations.
This update also includes a servicing stack update, KB5077457 (build 22621.6642), which makes quality improvements to the component responsible for installing Windows updates.
Note: To upgrade to Windows 11, version 23H2, use enablement package KB5027397.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
Microsoft combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) into a single package, so no separate SSU installation is required beforehand.
- Windows Update / Microsoft Update: The update downloads and installs automatically.
- Windows Update for Business: Downloads and installs automatically in accordance with configured policies.
- Microsoft Update Catalog: The standalone package is available for manual download from the Microsoft Update Catalog.
- Windows Server Update Services (WSUS): The update syncs automatically when Products is set to Windows 11 and Classification is set to Security Updates.
To remove only the LCU after installation, use the DISM /online /remove-package command with the LCU package name as the argument (find the name via DISM /online /get-packages). Running wusa.exe /uninstall on the combined package will not work because the package contains the SSU, which cannot be removed after installation.
Frequently asked questions
Does this update address the Virtual Secure Mode shutdown and hibernation issue?
Yes. This update includes a fix for the VSM-related restart issue introduced by the January 13, 2026 security update. Affected PCs running Virtual Secure Mode were unable to shut down or enter hibernation and would restart instead. Installing KB5075941 resolves this behavior without any additional workaround needed.
What should administrators know about the Secure Boot certificate changes?
Secure Boot certificates used by most Windows devices are set to expire starting June 2026. Microsoft has been rolling out updated certificates in phases. This update both executes Boot Manager changes on eligible devices and adds targeting logic to identify readiness before delivering new certificates. Administrators should review the Secure Boot Playbook for Windows clients and Windows Server for guidance.
How does the SSU bundled in this package affect uninstallation?
The servicing stack update KB5077457 is included inside the combined package. Because the SSU cannot be removed from the system after installation, running wusa.exe /uninstall against the combined package will fail. To remove only the LCU portion, administrators must use the DISM command-line tool with the specific LCU package name.
Does this update include changes to Microsoft Store apps?
No. Windows cumulative updates do not include updates for Microsoft Store apps. Enterprise administrators should refer to Microsoft Store apps guidance in Configuration Manager, while consumer users can obtain app updates directly through the Microsoft Store application.









