NAVANEM
Security updateOS build 22631.6783

KB5078883: Windows 11 version 23H2 Security Update (OS Build 22631.6783) - March 2026

March 10, 2026 cumulative security update for Windows 11 version 23H2, bringing OS build to 22631.6783 with security fixes and quality improvements.

KB5078883: Windows 11 version 23H2 Security Update (OS Build 22631.6783) - March 2026 — navanem Microsoft KB cover
KB5078883 · Windows 11 · Security Update

Summary

KB5078883 is a cumulative security update for Windows 11 version 23H2, releasing on March 10, 2026 and raising the OS build to 22631.6783. It delivers the latest security fixes together with non-security quality improvements carried forward from February's optional preview release. A bundled servicing stack update (KB5079275) is included. Source: Microsoft Support

Improvements and fixes

  • Secure Boot - certificate targeting: Windows quality updates now include additional high-confidence device targeting data, broadening the set of devices that automatically receive updated Secure Boot certificates. Certificates are delivered only after successful update signals are confirmed, keeping the rollout phased and controlled.
  • Secure Boot - new PowerShell tools: Two PowerShell cmdlet improvements help administrators manage the Secure Boot key rollout. The Get-SecureBootUEFI cmdlet gains a -Decoded option that displays Secure Boot keys and certificates in a readable format. The new Get-SecureBootSVN cmdlet lets you query a device's UEFI firmware and bootloader Secure Boot Security Version Number (SVN) and check whether the device follows the latest Secure Boot policy.
  • File History reliability: File History in Control Panel is now more reliable when backing up files whose names contain Chinese characters or Private Use Area characters, so those files are protected and recoverable as expected.
  • Graphics stability - shutdown: A stability problem affecting certain GPU configurations during system shutdown has been addressed, helping devices power off more reliably.
  • Graphics stability - games and 3D apps: A separate graphics stability improvement helps games and 3D applications run more reliably under intensive graphics workloads on certain GPU configurations.
  • Texts and Fonts - Saudi Riyal symbol: Windows fonts have been updated to include the new Saudi Riyal currency symbol, keeping text accurate and visually consistent across apps.
  • Windows System Image Manager (WSIM) - trusted catalog files: WSIM now shows a warning dialog when you select a catalog file, prompting you to confirm the file comes from a trusted source and improving overall reliability of the trusted-catalog selection workflow.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Microsoft bundles the latest servicing stack update (SSU KB5079275, version 22621.6773) together with this cumulative update, so no separate SSU installation step is required before applying KB5078883.

The update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in line with your configured policies.
  • Microsoft Update Catalog: Download the standalone package directly from the Catalog if you need offline or manual deployment.
  • Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are set to Product - Windows 11 and Classification - Security Updates.

If you need to remove the cumulative update after installation, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded in it, and the SSU itself cannot be removed once installed.

Frequently asked questions

Do I need to install the servicing stack update separately before applying KB5078883?

No. Microsoft combines the latest servicing stack update (SSU KB5079275) with the cumulative update in a single package. You do not need to download or install the SSU manually before applying this update. The two components are delivered and installed together through the standard update channels.

What should IT administrators know about the Secure Boot certificate expiration notice?

Secure Boot certificates on most Windows devices are scheduled to begin expiring in June 2026. Microsoft has been rolling out updated certificates to consumer and non-managed business devices for several months. Devices that have not yet received newer certificates will continue to start and operate normally, and standard Windows updates will still install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for managed-environment guidance.

Are Microsoft Store app updates included in this cumulative update?

No. Microsoft Store app updates are distributed separately and are not part of Windows cumulative updates. Enterprise users should refer to Microsoft Store apps - Configuration Manager guidance, while consumer users should use the Get Updates option within the Microsoft Store app itself.

How do I upgrade to Windows 11 version 23H2 before applying this update?

Use the enablement package KB5027397 to update a compatible device to Windows 11 version 23H2. Once on version 23H2, KB5078883 can be applied through any of the standard delivery channels listed above.

#windows-11#23h2#cumulative-update#secure-boot#security-update#march-2026#servicing-stack

Related topics