KB5079466 - Windows 11 Version 26H1 Security Update (OS Build 28000.1719)
March 2026 cumulative security update for Windows 11 version 26H1, delivering OS build 28000.1719 with Secure Boot, WDAC, and WSIM improvements.

Summary
This is the March 10, 2026 cumulative security update for Windows 11 version 26H1, documented by Microsoft Support. It brings OS build to 28000.1719, released on March 10, 2026. This security update also incorporates non-security improvements carried over from last month's optional preview release.
Highlights
- Secure Boot certificate rollout is expanded, with Windows quality updates now including additional high-confidence device targeting data to increase coverage of eligible devices.
- Windows Defender Application Control (WDAC) now correctly allows COM objects when an endpoint security policy is set higher than the allowlisting policy.
- Windows System Image Manager gains a warning dialog to help confirm that selected catalog files come from a trusted source, improving reliability.
Improvements and fixes
- Secure Boot: Quality updates now carry additional high-confidence device targeting data, which broadens the pool of devices eligible to receive new Secure Boot certificates automatically. Certificates are only delivered after sufficient successful update signals have been recorded, keeping the rollout controlled and phased.
- Windows Defender Application Control: A fix corrects how WDAC handles COM object allowlisting policies. Previously, COM objects were blocked when the endpoint security policy priority was set above the allowlisting policy; they are now permitted as expected.
- Windows System Image Manager: Reliability improvements change how trusted catalog files are selected. A new warning dialog prompts users to confirm that a chosen file originates from a trusted source before proceeding.
- This update contains all fixes and quality improvements from KB5077239, which was released on February 10, 2026. Devices with previous updates installed will download only the new content included in this package.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
Microsoft bundles the latest servicing stack update (SSU) - KB5078262, version 28000.1638 - together with this latest cumulative update (LCU) in a single package. No separate SSU installation is required before applying this update.
The update is available through the following channels:
- Windows Update / Microsoft Update: Downloads and installs automatically.
- Windows Update for Business: Deploys automatically in line with your configured policies.
- Microsoft Update Catalog: The standalone package is available for manual download. Because this KB contains one or more MSU files that must be installed in a specific order, Microsoft provides two installation methods:
- Method 1 - Download all MSU files to a single folder and use DISM with the
/PackagePathargument pointing to that folder; DISM discovers and installs prerequisite files as needed. The equivalent PowerShell cmdlet isAdd-WindowsPackage -Online. - Method 2 - Download and install each MSU file individually using DISM or Windows Update Standalone Installer in the documented order.
- Method 1 - Download all MSU files to a single folder and use DISM with the
- Windows Server Update Services (WSUS): Syncs automatically when Product is set to Windows 11 and Classification is set to Security Updates.
Note: AI component updates included in this package apply only to Windows Copilot+ PCs and will not install on standard Windows PCs or Windows Server.
To remove the LCU after installation, use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the SSU is embedded in it, and the SSU cannot be removed after installation.
Frequently asked questions
Does this update include fixes from previous months?
Yes. This cumulative security update incorporates all fixes and quality improvements from KB5077239, the February 10, 2026 release. If your devices already have that update installed, only the new content introduced in this package will be downloaded and applied.
What is the servicing stack update bundled with this release?
Microsoft includes SSU KB5078262 - version 28000.1638 - directly in this package. The SSU improves the reliability of the component responsible for installing Windows updates, and it does not need to be obtained or applied separately before installing this LCU.
Are the AI component updates in this package applicable to all Windows 11 devices?
No. Although AI component updates for Image Search, Content Extraction, Semantic Analysis, and Settings Model are included in the package, they will only install on Windows Copilot+ PCs. They will not be applied to standard Windows PCs or Windows Server machines.
Can I uninstall this update if I encounter problems after deployment?
You can remove the LCU portion using DISM /online /remove-package and the LCU package name, which you can retrieve with DISM /online /get-packages. However, the SSU component cannot be removed after installation. Microsoft recommends reviewing its guidance on the risks of uninstalling security updates before proceeding.









