Windows 10 ESU Patch Fixes Backup, Expands Secure Boot
August 2026 Patch Tuesday update for Windows 10 resolves File History SMB errors and broadens Secure Boot certificate rollout.
Microsoft has begun pushing out the August 2026 Patch Tuesday update for Windows 10, and for organizations still running the aging OS through the Extended Security Updates program, it carries more than the usual crop of fixes. The update, designated KB5120249, targets both Windows 10 22H2 and 21H2 and addresses a nagging File History backup failure while quietly widening the reach of Microsoft's Secure Boot certificate deployment.
The update is mandatory for ESU subscribers and arrives as Windows 10 approaches the tail end of its extended support lifecycle. With the OS no longer receiving mainstream updates, each Patch Tuesday release becomes a critical checkpoint for businesses that have not yet migrated.
Mandatory August 2026 Security Rollup
KB5120249 is not an optional quality-of-life patch. Microsoft has made clear that this month's release is required, bundling in all the security fixes from the August 2026 Patch Tuesday cycle. For those still on Windows 10, skipping it means leaving known vulnerabilities unpatched.
Users can trigger the installation through the standard Windows Update path—Start > Settings > Update & Security > Windows Update—or manually pull the update from the Microsoft Update Catalog. After applying it, systems will move to OS Builds 19045.7663 for version 22H2 and 19044.7663 for version 21H2.
File History Backup Failure Addressed
A notable fix in this release targets File History, the built-in backup tool. Microsoft says that scheduled backups to network shares using Server Message Block (SMB) could fail with an incorrect "invalid credentials" error. When that happened, no files were copied during the backup job, potentially leaving users without recent copies of their data.
The update resolves this glitch, ensuring that File History can once again write to network locations without being blocked by a false credential rejection. For small businesses relying on network-attached storage for backup, this is a meaningful correction—silent backup failures are the kind of problem that only surfaces when disaster strikes.
Secure Boot Certificate Deployment Broadened
Beyond the backup fix, Microsoft is expanding the rollout of new Secure Boot certificates. The company explains that the update includes "additional high confidence device targeting data," which increases the pool of devices eligible to automatically receive the new certificates.
Secure Boot relies on certificates to verify the integrity of the boot process, and Microsoft has been transitioning to updated certificates over time. The new targeting data helps ensure more machines get the necessary updates without manual intervention. Microsoft also noted that Secure Boot certificate deployment via Windows updates will continue across supported PCs and non-managed business devices in the coming months.
No Known Issues Reported
Microsoft has stated it is not aware of any new issues introduced by this month's Patch Tuesday update. That is a standard disclaimer, but it is worth noting given the track record of some previous Windows 10 updates. The company said it will update its documentation if major problems surface after wider deployment.
ESU: A Lifeline with Limits
For organizations still on Windows 10, the Extended Security Updates program is the only way to keep receiving patches after mainstream support ended. This update is a reminder that the program is not just about security fixes—it also delivers operational corrections like the File History repair.
However, the program has its caveats. Each year of ESU coverage costs more, and Microsoft has been clear that it is not a permanent solution. The company's broader push toward Windows 11, coupled with the gradual winding down of Windows 10 support, means that every Patch Tuesday like this one brings the end of the road closer.
Why It Matters
This update underscores the reality for the remaining Windows 10 install base: each month, the gap between patched and unpatched systems grows more consequential. The File History fix is a practical win for those who use network backups, and the Secure Boot expansion strengthens platform integrity—but both are incremental steps in a support lifecycle that is nearing its finale.
For businesses that have delayed migration, this release is a nudge to plan for the inevitable. Extended Security Updates can keep systems technically viable, but they do not stop the clock. The longer an organization waits, the more it spends on a bridge that leads nowhere except a future upgrade.
Sources
- BleepingComputer Original source
- Microsoft Update Catalog Also reporting
Continue Reading
Fusion fuel factory rises in Tennessee
Kyoto Fusioneering lands U.S. grants to build a fuel breeding device at Oak Ridge.
Bumble Ends Women-First Messaging Rule
Bumble drops the women-message-first rule, extending response windows to 72 hours, signaling a strategic pivot.
Spotify moves to curb AI Persona slop
New badges and recommendation bans target AI-generated artist identities on Spotify.