NAVANEM
Security updateOS build 19045.7058 and 19044.7058

March 10, 2026 - KB5078885 (OS Builds 19045.7058 and 19044.7058)

Security update for Windows 10 ESU and Enterprise LTSC 2021, releasing OS builds 19045.7058 and 19044.7058 on March 10, 2026.

KB5078885: March 10, 2026 - KB5078885 (OS Builds 19045.7058 and 19044.7058) — navanem Microsoft KB cover
KB5078885 · Windows 10 · Security Update

Summary

KB5078885 is a security update for Windows 10 ESU (version 22H2) and Windows 10 Enterprise LTSC 2021 (version 21H2), producing OS builds 19045.7058 and 19044.7058. Released on March 10, 2026, it delivers security fixes and quality improvements, and is available through Windows Update, Windows Update for Business, WSUS, and the Microsoft Update Catalog. See the Microsoft Support page for full details.

Highlights

  • A warning dialog is added to Windows System Image Manager to help users confirm that a selected catalog file comes from a trusted source.
  • File History in Control Panel now correctly backs up files whose names contain certain Chinese and Private Use Area characters.
  • A stability issue affecting certain GPU configurations has been addressed.
  • Windows quality updates now include additional high-confidence device targeting data to increase coverage of devices eligible to automatically receive new Secure Boot certificates.

Improvements and fixes

  • Windows System Image Manager: A new warning dialog prompts users to verify that the catalog file they have selected originates from a trusted source before proceeding.
  • File History: The Control Panel File History feature has been improved so that newly created files with names that include certain Chinese characters or Private Use Area characters can now be backed up without issue.
  • Graphics: A stability problem that was affecting specific GPU configurations has been resolved.
  • Secure Boot certificate rollout: This update adds additional high-confidence device targeting data to Windows quality updates. The targeting is based primarily on client device diagnostic data, which means servers are unlikely to qualify for automatic certificate delivery, though they are not explicitly excluded. Devices receive the new certificates only after demonstrating sufficient successful update signals, keeping the rollout controlled and phased.
  • Servicing stack update (KB5081263) - builds 19045.7052 and 19044.7052: The bundled SSU replaces the 2011-signed bootmgfw.efi with the 2023-signed bootmgfw.efi when the 2023 PCA is present in the DB. The SSU also includes enhanced logic to verify whether a device is hosted on Azure, using an updated certificate chain for that validation.

Known issues

Microsoft lists no known issues for this update at the time of writing.

How to get this update

Before applying KB5078885, confirm that the latest servicing stack update (SSU) is installed. Skipping this step may prevent the update from being offered.

  • Offline OS image servicing: If the image does not have the July 25, 2023 (KB5028244) or a later LCU, install the standalone October 13, 2023 SSU (KB5031539) first.
  • WSUS or Microsoft Update Catalog (standalone package): If devices do not have the May 11, 2021 (KB5003173) or a later LCU, install the standalone August 10, 2021 SSU (KB5005260) first.

Once prerequisites are met, the update is available through the following channels:

  • Windows Update / Windows Update for Business: Downloaded and installed automatically according to configured policies.
  • Microsoft Update Catalog: Obtain the standalone package directly from the Microsoft Update Catalog website.
  • WSUS: The update syncs automatically when Products and Classifications are configured correctly - for Windows 10 version 22H2, set Product to "Windows 10, version 1903 and later" and Classification to "Security Updates"; for Windows 10 version 21H2, set Product to "Windows 10 LTSB" and Classification to "Security Updates".

To remove only the LCU after installation, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch against the combined package will not work because the package contains the SSU, and the SSU cannot be removed once installed.

Frequently asked questions

Does this update apply to both Windows 10 version 22H2 and Windows 10 Enterprise LTSC 2021?

Yes. KB5078885 targets Windows 10 ESU (version 22H2) and Windows 10 Enterprise LTSC 2021 (version 21H2). Both editions land on OS builds 19045.7058 and 19044.7058 respectively. The improvements and fixes documented for each edition are identical in this release.

What prerequisite update is required before installing KB5078885?

The latest SSU must be installed before applying this update. For offline image servicing without KB5028244 or a later LCU, apply standalone SSU KB5031539 first. For WSUS or Catalog deployments without KB5003173 or a later LCU, apply standalone SSU KB5005260 first. Skipping this step may result in the LCU not being offered.

Will this update push new Secure Boot certificates to my servers automatically?

Not likely. The Secure Boot certificate targeting in this update relies primarily on client device diagnostic data. Microsoft states that servers are unlikely to qualify for automatic certificate delivery due to limited diagnostic data available from them, though they are not explicitly excluded from eligibility.

How do I check whether my devices have received the updated Secure Boot certificates?

On consumer and non-managed business devices, the Windows Security app shows the PC's current Secure Boot certificate status. IT administrators managing enterprise or server environments should follow the guidance provided in the Secure Boot Playbook for Windows clients and Windows Server, as referenced by Microsoft in this update's documentation.

#windows-10#security-update#secure-boot#ltsc-2021#esu#file-history#cumulative-update

Related topics