Windows 10 may be past its mainstream feature era, but it is not past its security responsibilities for organizations and enthusiasts who still depend on it. Microsoft’s August 2026 Patch Tuesday release, identified as KB5120249 for Windows 10 version 22H2, is now available for PCs covered by the Extended Security Updates program. For most eligible systems, this is a routine cumulative update rather than a feature release, but it is still an important maintenance milestone.
The practical message is simple: if a Windows 10 machine remains in service and is enrolled for ESU, this update should be treated as a normal security deployment priority. It does not bring a redesigned interface or new productivity tools, but it does move protected Windows 10 22H2 devices to Build 19045.7663 and includes the current month’s security fixes.
Who should install KB5120249
KB5120249 is intended for Windows 10 PCs that are still supported through Microsoft’s Extended Security Updates program. That distinction matters. Microsoft has posted offline installer packages through the Microsoft Update Catalog, but availability of an .msu file does not mean every Windows 10 system can successfully apply it. Devices still need to meet the ESU eligibility requirements.
For IT teams, this means the update belongs in the same workflow as other post-end-of-support Windows 10 security maintenance: validate ESU licensing, confirm update channel health, test on a small representative group, and then expand deployment using your normal management platform. For home users or enthusiasts maintaining older systems, the key question is whether the PC is actually enrolled and entitled to receive ESU updates.
What changes in this release
Windows Latest reports that the update installs as the “2026-08 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5120249)” and advances Windows 10 22H2 to Build 19045.7663. Windows 10 Enterprise LTSC 2021 moves to Build 19044.7663. Users should not expect visible user interface changes because Windows 10 is now in a security-focused servicing phase.
The most relevant operational fix highlighted in the report concerns File History automatic backups in enterprise scenarios using Server Message Block. A previous issue could trigger invalid credential errors and cause scheduled backups to fail when SMB was involved. For organizations that still rely on File History workflows, this is a worthwhile fix to validate after deployment.
The report also notes broader Secure Boot certificate rollout behavior. In practice, that makes this a good time for administrators to pay attention to firmware, recovery media, imaging processes, and older boot dependencies. Secure Boot certificate changes are necessary for platform trust, but they can expose fragile boot environments if an organization has legacy tooling or outdated recovery processes.
Use Windows Update first when possible
Although offline installers are available, Windows Update remains the better default path for most systems. Catalog downloads are useful when a device is isolated, Windows Update is stuck, or an administrator needs to stage a package manually. However, full .msu packages are often larger than the optimized payload delivered through Windows Update.
A sensible deployment approach is to let Windows Update, Windows Server Update Services, Microsoft Intune, or your existing endpoint management stack handle the update wherever possible. Reserve the Update Catalog route for troubleshooting, controlled offline servicing, or special network environments. If you do use the standalone installer, document which systems received it and confirm that the final build number matches the expected result.
Watch for adjacent August updates
Patch Tuesday rarely arrives as a single package. The Windows Latest article notes related servicing activity, including a Windows Recovery Environment update and a .NET Framework update. Administrators should review the full update set rather than treating KB5120249 in isolation. Recovery environment updates are especially important because they can affect repair, reset, BitLocker recovery, and disaster recovery workflows.
After installation, check update history, confirm the build number, and make sure normal endpoint protections remain healthy. On business systems, verify backup tasks, SMB access, VPN connectivity, line-of-business applications, and any device encryption recovery procedures that are part of your standard post-patch checklist.
OneDrive Photos is a separate rollout
One notable detail in the source report is that some Windows 10 users may see the newer OneDrive Photos app appear around the same time. That should not be automatically attributed to KB5120249. The app is reportedly being delivered through the OneDrive sync client rather than through this cumulative update.
This distinction is useful for help desks. If a user reports a new Photos-related OneDrive component after Patch Tuesday, the timing may overlap with the security update, but the delivery mechanism is different. Organizations that manage OneDrive should review their OneDrive client policies separately from their Windows cumulative update policies.
Practical recommendation
For eligible Windows 10 systems, deploy KB5120249 after normal testing and do not delay simply because the release lacks visible features. Security-only maintenance is the point of the ESU period. The longer Windows 10 remains in production, the more important it becomes to maintain a disciplined patch process, a current recovery plan, and an exit strategy toward a supported platform.
For non-ESU systems, this update is also a reminder that relying on Windows 10 without an extended servicing path is increasingly risky. If a machine cannot move to Windows 11, consider whether it should be isolated, replaced, converted to a limited-purpose role, or covered by an appropriate support arrangement.
Source: Windows Latest source