Windows 11: February updates strengthen Secure Boot
The February 2026 updates for Windows 11 bring important security enhancements, bug fixes, and prepare users for changes in the Secure Boot infrastructure related to certificate expiration. New features have also been added, and the system’s capabilities have been expanded.
Crius
The February 2026 Windows 11 updates (KB5077181 and KB5075941) deliver important security enhancements, bug fixes, and new signals to help with Secure Boot deployment ahead of certificate expiration starting in June 2026.
Main Updates and Versions
On February 10, 2026, Microsoft released cumulative security updates for Windows 11. For versions 24H2 and 25H2, the update is labeled KB5077181, which upgrades the OS to builds 26100.7840 (24H2) and 26200.7840 (25H2). For Windows 11 23H2, update KB5075941 raises the build number to 22631.6649.
Both updates include the monthly security patches, as well as “non-security updates” from previous optional preview releases, depending on your system version.
Key Secure Boot Changes
In the release notes, Microsoft highlights the upcoming expiration of Secure Boot certificates used on most Windows devices. These certificates will begin to expire in June 2026. The company recommends updating devices promptly and reviewing the Secure Boot preparation guide to avoid potential issues.
For versions 24H2 and 25H2, the update expands the phased deployment strategy: Windows quality updates now include data to assess device readiness for new Secure Boot certificates. New certificates will only be installed after a sufficient number of successful update signals have been received.
Fixes and Improvements
KB5077181 introduces the following fixes:
- Resolved an issue with permissions for fullscreen games.
- Fixed a bug that could block connections to certain WPA3-Personal Wi-Fi networks after a previous update.
- Updated AI components (Image Search, Content Extraction, Semantic Analysis, and Settings Model) to version 1.2601.1268.0.
As of publication, Microsoft has not reported any known issues with KB5077181.
For Windows 11 23H2, KB5075941 includes a change in Secure Boot/Boot Manager: on devices with the Windows UEFI CA 2023 certificate in the Secure Boot signature database (DB), the update replaces the bootmgfw.efi file signed in 2011 with a version signed in 2023. It also notes that resetting the DB or toggling Secure Boot may trigger a “Secure Boot violation” error, and in rare cases, using a bootable recovery drive may be recommended.
KB5075941 addresses a widely discussed issue where some PCs with Virtual Secure Mode (VSM) enabled could restart instead of shutting down or entering sleep mode after installing security updates released from January 13, 2026, onward.
As with the 24H2/25H2 update, no known issues have been reported for KB5075941 at the time of publication.
New Features and Gradual Rollout
The February 2026 Patch Tuesday update also introduces new features that are being rolled out gradually. These include:
- Expanded Cross-Device Resume functionality.
- Improvements to Windows MIDI Services.
- More detailed settings for Narrator.
- Changes to Smart App Control behavior.
The availability of these features may vary depending on your device, configuration, and rollout status.
These updates are designed to enhance the security, stability, and functionality of Windows 11, as well as to prepare users for upcoming changes in the Secure Boot infrastructure.
