Skip to main content
CybersecurityVulnerability Management

Microsoft Releases KB5120249 Update to Fix Security Vulnerabilities

Windows 10 laptop on a desk showing a Windows update screen with progress bar.

"Microsoft has released the Windows 10 KB5120249 cumulative update for versions 22H2 and 21H2 to fix security vulnerabilities and bugs," BleepingComputer reports.

Key fixes: File History backup and Secure Boot certificate expansion

The August 2026 cumulative update, KB5120249, addresses two named problems. First, it resolves a File History automatic backup failure that could occur when backing up to network shares using Server Message Block (SMB). In affected machines, backups could fail with an incorrect "invalid credentials" error and scheduled backups would not copy any files; the update resolves that condition.

Second, the update "includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates," the bulletin states. That targeting data expands the set of devices Microsoft identifies as eligible for automatic certificate delivery.

Installation paths and resulting OS builds

The update is mandatory because it contains the August 2026 Patch Tuesday security updates. Administrators and end users can install it by going to Start > Settings > Update & Security > Windows Update and clicking "Check for updates." The update can also be manually downloaded and installed from the Microsoft Update Catalog.

After installation, Windows 10 will show the following OS builds: 19045.7663 for 22H2 and 19044.7663 for 21H2.

Rollout scope: supported PCs and non-managed business devices

BleepingComputer notes that certificate deployment "via Windows updates continues across supported PCs and non-managed business devices in the coming months." That language frames the Secure Boot certificate change as a staged expansion: targeting data increases device coverage, and the deployment mechanism remains Windows Update.

The bulletin does not list a specific timeline beyond "the coming months" or enumerate particular device models; it emphasizes that deployment will occur through the Windows Update channel to both fully managed and non-managed business devices that are supported and identified as eligible.

What this means for technologists, enterprises, and end users

  • Technologists and security teams: The update is mandatory and includes Patch Tuesday security fixes, so teams responsible for patch management will need to plan deployment to reach OS builds 19045.7663 or 19044.7663 and verify that File History backups to SMB shares resume normal operation.
  • Enterprises and procurement leaders: The Secure Boot certificate expansion will be delivered through Windows Update and will touch "non-managed business devices" as well as supported PCs; organizations should be aware that certificate deployment will broaden in the coming months and account for that in asset inventories and update policies.
  • End users: Those relying on File History for scheduled backups should install the update to eliminate the "invalid credentials" SMB failure, and users can obtain the update either through Settings > Update & Security > Windows Update or by downloading it from the Microsoft Update Catalog.

Defensive context: prevention scores and the Blue Report 2026

The article places the update against a snapshot of defensive performance: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." It cites the Blue Report 2026, which "measures defenses technique by technique across 338 million simulations run in customer production environments." Those figures underline why resolving a backup failure and expanding Secure Boot certificate coverage matter in operational terms: both affect recovery and platform integrity once systems face threat activity.

Microsoft states it is "not aware of any new issues with this month's Patch Tuesday update," and the bulletin says the article will be updated if major problems are discovered. For organizations and users, the immediate steps are straightforward: apply KB5120249 through Windows Update or the Microsoft Update Catalog, confirm that File History backups to SMB shares function correctly, and track the Secure Boot certificate deployment as it expands across supported and non-managed devices.

https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5120249-cumulative-update-released-with-fixes/