March 10, 2026 - KB5078740 (OS Build 26100.32522) Windows Server 2025
Security cumulative update for Windows Server 2025 (OS Build 26100.32522), released March 10, 2026, including Secure Boot and hardware error reporting fixes.

Summary
KB5078740 is a security cumulative update for Windows Server 2025, bringing the OS to build 26100.32522. Released on March 10, 2026, it bundles the latest security fixes together with non-security improvements carried over from last month's optional preview release. See Microsoft Support for full details.
Highlights
- Secure Boot updates now include additional high-confidence device targeting data, automatically expanding which devices can receive new Secure Boot certificates in a phased, controlled rollout.
- Windows Server 2025 gains support for modern server platforms that expose more hardware error reporting features, including systems with up to 64 Machine Check Architecture (MCA) banks.
Improvements and fixes
- [Secure Boot] Quality updates now carry expanded device targeting data to increase the pool of devices eligible to receive new Secure Boot certificates automatically. Targeting relies primarily on client device diagnostic data. Because servers generate limited diagnostic data, they are unlikely to qualify for automatic certificate delivery, though they are not explicitly excluded. New certificates are issued only after a device shows sufficient successful update signals, keeping the rollout controlled and phased.
- [System services and reliability] Windows Server 2025 now correctly parses and configures all supported hardware error sources on modern server platforms that expose additional Machine Check Architecture (MCA) features, including systems with up to 64 MCA banks. This ensures hardware errors are reported and handled as expected on platforms such as newer AMD EPYC-based servers.
Known issues
WSUS does not display synchronization error details
Symptom: After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting interface.
Workaround: This functionality has been temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287. No workaround is listed; the removal is intentional pending a longer-term resolution.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) for Windows Server 2025 - KB5078739, version 26100.32500 - together with this latest cumulative update (LCU), so no separate SSU installation step is required before applying KB5078740.
This update is available through the following channels:
- Windows Update / Microsoft Update - downloads and installs automatically.
- Windows Update for Business - deploys automatically in line with configured policies.
- Microsoft Update Catalog - available for manual download and offline deployment. The package includes multiple MSU files that must be installed in a specific order, or together using DISM with a single folder path. For WSUS, configure the product as Microsoft Server operating system-24H2 and the classification as Security Updates.
Note that the cumulative update package includes AI component updates; however, those components apply only to Windows Copilot+ PCs and will not install on Windows Server.
To remove only the LCU after installation, use the DISM /online /remove-package command with the LCU package name. Running wusa.exe /uninstall against the combined SSU and LCU package will not work, and the SSU itself cannot be removed after installation.
Frequently asked questions
Does KB5078740 apply to Windows 11 client devices?
No. According to the page, KB5078740 applies to Windows Server 2025, all editions. The OS build 26100.32522 and all documented improvements and known issues listed here are specific to Windows Server 2025. Client Windows 11 devices receive separate update packages.
Why are servers unlikely to receive new Secure Boot certificates automatically?
The targeting mechanism for new Secure Boot certificates relies primarily on client device diagnostic data. Servers typically generate limited diagnostic telemetry, so few will qualify for automatic certificate delivery. Servers are not explicitly excluded, but sysadmins should review the Secure Boot certificate expiration guidance proactively rather than relying on automatic targeting.
What is the Secure Boot certificate expiration warning about?
Microsoft notes that Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Devices that are not updated in time may lose the ability to boot securely. Administrators should review the Windows Secure Boot certificate expiration guidance and the Windows Server Secure playbook blog to prepare and update certificates before the deadline.
Is the WSUS error-detail loss in this update a bug or intentional?
It is intentional. The removal of synchronization error detail display in WSUS was done deliberately to mitigate the Remote Code Execution vulnerability CVE-2025-59287. The feature was present before KB5070881 and has been temporarily removed in that update and all subsequent ones, including KB5078740, while a longer-term fix is developed.









