Microsoft has released the Windows 10 KB5122878 extended security update, targeting devices running Windows 10 Enterprise LTSC or enrolled in the Extended Security Updates program. Users in those categories can install the update by navigating to Settings, selecting Windows Update, and running a manual check for updates. The patch will bring Windows 10 to build 19045.7725 and Windows 10 Enterprise LTSC 2021 to build 19044.7725. As Microsoft no longer ships new features for Windows 10, this update is limited to security improvements and bug fixes.

The KB5122878 build includes fixes from the September 2026 Patch Tuesday release, which Microsoft has described as record-breaking for the number of vulnerabilities addressed. That monthly rollout closed 966 flaws across the company鈥檚 product lineup, including two zero-day vulnerabilities that were actively exploited in the wild. For US-based enterprise customers still on Windows 10, the update also carries a Secure Boot component that adds high confidence device targeting data, expanding the pool of systems eligible to automatically receive new Secure Boot certificates. Certificate deployment through Windows updates will continue over the coming months on supported PCs and non-managed business devices.

Separately, the update adjusts Morocco Standard Time to reflect that country鈥檚 permanent move to UTC+00:00, effective September 20, 2026. This change is designed to keep local time displays accurate after the transition. The patch also improves logging in the OMA DM Client component, saving more debug information when the client connects to a server. That change applies to the omadmclient.exe process.

For application compatibility, the update makes Windows Code Integrity policies recognize the Microsoft Windows Production PCA 2026 RSA2048-SHA256 certificate as equivalent to the older PCA 2011. This adjustment eases compatibility during Microsoft鈥檚 certificate-authority rotation. Additionally, the release addresses a Remote Desktop bug that could prevent audio from a remote session from playing on the local computer in certain configurations.

The update also fixes a known issue involving BitLocker Group Policy, where devices with an unrecommended configuration might be forced to prompt for a BitLocker recovery key. Beyond those fixes, Microsoft shared broader security context from its Blue Report 2026, noting that overall prevention scores can hide what occurs after an attacker gains initial access. The report indicates that once attackers use valid credentials, prevention effectiveness drops sharply. That finding is based on 338 million simulations run across customer production environments, with defenses measured technique by technique.

Microsoft鈥檚 previous July 2026 Patch Tuesday addressed 570 flaws, including three zero-days, according to the company鈥檚 earlier disclosure. The September release, however, dwarfs that total with its 966 patched vulnerabilities, underscoring the scale of this month鈥檚 security work for Windows 10 users in the ESU program.

More software news from TechManNews.