Quick prep (4 steps)
- Press Windows + R, type
winver. If it shows 24H2 on Home or Pro, upgrade to 25H2 or 26H2 first. - Back up your files, free 20 GB and save your BitLocker recovery key.
- Run
DISM /Online /Cleanup-Image /RestoreHealththensfc /scannowin an administrator Terminal and restart. - On October 13, read the release-day checklist before installing. If an install fails, use the error table.
Written before the release, updated after it
This guide was published on October 1, 2026, twelve days before Patch Tuesday. Nothing here describes what the October 13 release contains, because it does not exist yet. We will update this page after release with the real numbers and the real known issues. Until then it gives you everything that does not depend on the release: what is already scheduled, how to prepare, which commands to run, what each error means, and how to roll back.
What we know today about October 2026 Patch Tuesday
October 2026 Patch Tuesday falls on Tuesday, October 13, 2026, the second Tuesday of the month. Microsoft normally publishes its monthly security updates in the morning Pacific time, which is the afternoon in Europe and the evening in Africa and Asia. The exact release content is unknown today, so this page deals only with facts that are already published and with preparation that works whatever the release contains.
Patch Tuesday is the monthly release of security fixes for Windows, Office, .NET, Edge and other Microsoft products. For Windows 11 it arrives as a cumulative update, a single package that includes everything from earlier months, identified by a KB number. Home users usually receive it through Windows Update without doing anything. Businesses often delay it by a few days or weeks while they test. Both approaches are reasonable, and later sections show how to choose between them.
October is not an ordinary month, and that is why searches for this topic climb every year in the days before. Three separate Microsoft deadlines land within a week of each other this year. If you manage even one computer, the sensible approach is to treat October 13 as a small project rather than a background event. Here is what is confirmed and what is not.
| Question | Status on October 1, 2026 | What to do |
|---|---|---|
| Patch Tuesday date | Tuesday, October 13, 2026 | Plan your maintenance window |
| Contents of the October 13 release | Not published yet. We make no claim about it. | Read Microsoft's release notes on the day |
| Known issues of the new release | Unknown until it ships | Check Windows release health on the day |
| Windows 11 24H2 Home and Pro | End of servicing October 13, 2026 | Move to 25H2 or 26H2 first |
| Office LTSC 2021 | Support ends October 13, 2026 | Plan the replacement now |
| Secure Boot certificate (Windows Production PCA 2011) | Expires October 19, 2026 | Check status, save BitLocker key |
| Windows 11 26H2 | Released September 29, 2026 | Optional: longest support runway |
The three deadlines that make October different
Besides the monthly update itself, three scheduled events matter this month: Windows 11 24H2 Home and Pro stop being serviced on October 13, Office LTSC 2021 reaches end of support the same day, and the last of the 2011 Secure Boot certificates expires on October 19. None of them stops a computer from working on the day. All of them change how safe the computer is over the following months.
Windows 11 24H2 Home and Pro: end of servicing
Microsoft's lifecycle page for Windows 11 Home and Pro lists the end of servicing for version 24H2 as 10/14/2026 at 06:59 UTC, which is the evening of October 13 in North America. After that moment the Home, Pro, Pro Education and Pro for Workstations editions of 24H2 no longer receive monthly security updates. That means the October 13 update is the last one a 24H2 Home or Pro PC can receive. Version 25H2 is serviced until October 13, 2027 (06:59 UTC), and version 26H2, released on September 29, 2026, until October 10, 2028 (06:59 UTC). The upgrade is a free, small update that keeps your files and programs. We cover it step by step in our guide to Windows 11 24H2 end of support and the upgrade to 25H2 or 26H2, so this page only covers how it interacts with Patch Tuesday.
The interaction is the important part. If you upgrade on October 12, you receive the October 13 update on a release that stays supported. If you wait, you may get one last update on 24H2 and then nothing. The order in which you do things therefore matters: upgrade the feature release first, then install the monthly update.
Office LTSC 2021: end of support
The Long Term Servicing Channel edition of Office 2021, the one sold for volume licensing and kiosks, reaches the end of its support period on October 13, 2026. Your Word, Excel and Outlook will keep opening. What stops is the stream of security fixes and the right to technical support. If you run it, now is the time to decide between Microsoft 365, a newer perpetual edition, or an exception with compensating controls. It is a licensing decision, so do not leave it to the last evening.
Secure Boot: the October 19 certificate expiry
Microsoft is replacing the 2011 generation of Secure Boot certificates with 2023 versions. Our dedicated guide on the Secure Boot certificate expiry in 2026 lists the dates: the Microsoft Corporation KEK CA 2011 on June 24, 2026, the Microsoft UEFI CA 2011 on June 27, 2026, and the Microsoft Windows Production PCA 2011 on October 19, 2026. The last one is the certificate behind the Windows Boot Manager signature, and it falls six days after Patch Tuesday. Your computer does not stop booting on October 19. The practical risk is falling behind on boot-level protections, and the practical preparation is to save your BitLocker recovery key and install firmware and Windows updates. Because certificate and firmware updates are delivered through the same monthly channel, the October update is part of that story.
Why prepare before the release instead of after it
The best time to prepare for a Windows update is before it is published, because a backup, free disk space and a healthy update system are the three things that decide whether the install goes smoothly, and none of them can be fixed quickly once the update is already failing. Most failed updates we see are not caused by a bad release. They are caused by the machine: a nearly full drive, a half-installed earlier update, a damaged component store, or a disconnected laptop battery.
There is a second reason. Search traffic and support queues spike in the first 48 hours after Patch Tuesday. Forums fill with posts from people whose installs failed, many of them with the same preventable cause. If your machine is already clean and backed up, the release-day install is a ten-minute event. If it is not, you are doing repairs under time pressure, possibly with a deadline such as a payroll run or an invoice.
A third reason is specific to this month. Because 24H2 stops being serviced, a Home or Pro PC that has been quietly stuck on a pending restart or a paused update may miss the last update it can ever get on that release. Checking now costs nothing, and the next section gives you a checklist you can run in about fifteen minutes. If your Windows Update has been misbehaving for weeks, read our general guide to fixing Windows Update when it is stuck or failing first, then come back.
What this guide gives you
- A 15 minute preparation checklist and the exact commands to run.
- A home path and an enterprise path for installing the update.
- A decision table for the install errors people hit most often.
- How to pause updates and how to roll back, with the limits of each.
- A release-day checklist of what to read and in which order.
- Three illustrative scenarios and what the work costs in Canadian dollars.
Preparation checklist: the 15 minutes that prevent most failures
Before any Patch Tuesday, check six things: your Windows version, a backup you have tested, at least 20 GB of free space, no pending restart, a healthy component store, and your BitLocker recovery key. Together they take about fifteen minutes and remove the large majority of install failures. Each item below has the click path and, where useful, a command you can copy and paste.
1. Know your version and edition
Press Windows + R, type winver and press Enter. Note the version (24H2, 25H2 or 26H2) and the edition in Settings, System, About. If you are on 24H2 Home or Pro, upgrade the feature release before Patch Tuesday. If you prefer a command, open PowerShell and run:
Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber, OsHardwareAbstractionLayer
To list the last updates installed, which is useful to compare with the release notes on the day:
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 8 HotFixID, Description, InstalledOn
2. Make a backup you have actually opened
Copy documents, photos, desktop files, browser bookmarks and exported passwords to an external drive, and confirm any cloud-synced folder shows the files on a second device. A backup nobody has opened is a hope, not a backup. Our article on data recovery versus data backup explains the difference. For a small office, add a copy of the accounting file and the mailbox export, because these are the two things people ask for first when a PC will not start.
3. Free at least 20 GB on the system drive
Monthly cumulative updates are smaller than feature updates, but they still need space to download, stage and apply. Open Settings, System, Storage, then Temporary files and remove the Windows Update cleanup and Recycle Bin entries. Check free space from a command prompt:
Get-PSDrive C | Select-Object @{n='FreeGB';e={[math]::Round($_.Free/1GB,1)}}, @{n='UsedGB';e={[math]::Round($_.Used/1GB,1)}}
Never delete files inside the Windows folder by hand. If you need more space, move videos and old downloads to the external drive.
4. Clear any pending restart
A computer that shows "Restart required" has an earlier update waiting, and stacking a new one on top is how stuck installs start. Restart now, from the Start menu, and then check again. To see whether Windows believes a restart is pending, run this in an administrator PowerShell:
Test-Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'
If it returns True, restart and run it again until it returns False.
5. Check the health of the update system
Two built-in tools check Windows system files and the component store, the local repository Windows uses to build updates. Run them in an administrator Command Prompt or Terminal. They can take 10 to 25 minutes and may sit at a percentage for a while, which is normal:
DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
sfc /scannow
If ScanHealth reports the store is repairable, run DISM /Online /Cleanup-Image /RestoreHealth, restart, and run sfc /scannow once more. Doing this before the update, not after a failure, saves you from the most frequent root cause of error 0x800f0993 and its relatives. Our fix for the KB5129195 problem, KB5129195 install error 0x800f0993, walks through the same repair with screenshots of what the output looks like.
6. Save your BitLocker recovery key
Many modern laptops encrypt the drive automatically with BitLocker or Device Encryption. A firmware or boot-related update can make the computer ask for the 48 digit recovery key at the next start. If you cannot find it, the data is unreachable. Find yours now at account.microsoft.com/devices/recoverykey for a personal Microsoft account, in your organization's directory for a work PC, or in the printout you may have saved. We wrote a full guide on BitLocker recovery after a Windows update. Writing the key on paper and keeping it away from the laptop takes two minutes. Given the Secure Boot certificate work scheduled for the same weeks, this step moves from "good idea" to "do it today".
Patch Tuesday preparation checklist (print or screenshot this)
- I ran
winverand wrote down my version (24H2, 25H2 or 26H2) and edition. - If I am on 24H2 Home or Pro, I upgraded to 25H2 or 26H2 first.
- My important files exist in two places, and I opened the second copy to check.
- I have at least 20 GB free on the C: drive.
- I restarted, and the RebootRequired check returns False.
- DISM and sfc ran without unrepaired errors.
- My BitLocker recovery key is saved somewhere other than the laptop itself.
- My laptop will be plugged in, and I have an hour with no deadline.
- I know my Microsoft account email and password.
- I created a restore point (next section) or an image of the system drive.
- I know who to call if it goes wrong: 1 (888) 711-9428.
Create a restore point and know its limits
A System Restore point lets you return system files and settings to an earlier state if an update misbehaves, but it does not protect your documents and it is turned off by default on many Windows 11 installs, so check that it is on before relying on it. Think of it as a seatbelt, not an insurance policy. It helps with a bad driver or a broken update, and it does nothing for a failing disk or ransomware.
To turn it on and create a point: press the Start button, type Create a restore point, open the result, select the C: drive, choose Configure, enable Turn on system protection and allow a few percent of the disk. Then choose Create, name it "Before October 2026 updates" and wait for confirmation. From PowerShell, in administrator mode:
Enable-ComputerRestore -Drive "C:\"
Checkpoint-Computer -Description "Before October 2026 updates" -RestorePointType MODIFY_SETTINGS
Windows limits how often it creates restore points, normally one per 24 hours through this command, so create yours the day before rather than ten minutes before. Windows also creates one automatically before some installations, but you should not count on that. If the update later fails, Recovery in Settings, or the Advanced options screen shown when the PC cannot start, offers System Restore to return to the point you named.
Know your recovery options before you need them
Write down how you would get into Windows Recovery if the PC would not start normally. Windows opens it by itself after repeated failed starts, and you can force it by holding Shift while choosing Restart. From there you reach Startup Settings and Safe Mode, System Restore, Uninstall Updates and Command Prompt. Our guide to Windows 11 Safe Mode: how to start, exit and fix when stuck explains each route, including what to do when the usual keyboard shortcuts do not work. Practising once on a quiet afternoon turns a frightening black screen into a known menu.
Two small habits that help
Create the image once a quarter. A full system image of the drive takes longer than a restore point but restores everything, including programs. Windows still includes the older Backup and Restore (Windows 7) tool for this, and many third-party tools exist.
Keep a plain text file of your key settings: printer names, VPN profile names, mapped drives and the licence keys you own. After an upgrade or a reset, this saves an hour of memory work.

How to install the update safely: the home and small office path
For a home PC, the safest routine is to wait one to three days after Patch Tuesday, confirm that Microsoft has not posted a serious known issue for your version, then install from Settings, Windows Update with the laptop plugged in and your work saved. Waiting briefly costs very little security risk for most households, and it avoids being among the first to hit a rare problem.
That advice has one caveat this month. If your PC is on Windows 11 24H2 Home or Pro, upgrade the feature release first, because 24H2 no longer receives updates after this one. If you have already moved to 25H2 or 26H2, you can follow the normal routine.
Step by step on a home PC
- Read before you click. On release day, open the Windows release health page and the support article for your version (the exact KB number appears in Windows Update). Spend five minutes on the Known issues section.
- Prepare. Close your programs, plug in the laptop, and confirm your backup and recovery key are in order using the checklist above.
- Open Settings, Windows Update, Check for updates. If the cumulative update appears, choose Download and install. Do not interrupt the "Working on updates" screens, even if they seem slow. On an SSD, expect 15 to 40 minutes in total; older mechanical drives can take an hour or more.
- Restart when asked, not before and not much later. Many updates finish their work only during the restart.
- Verify. Run
winver, then open Settings, Windows Update, Update history and confirm the KB shows "Successfully installed". Open your key programs: browser, email, printer and VPN. - Check the Secure Boot and BitLocker status if you applied firmware updates, using the commands in our Secure Boot article.
The settings worth knowing about
Windows 11 lets you control how eager updates are. Under Settings, Windows Update, Advanced options you can switch off Get the latest updates as soon as they are available. When this setting is on, Windows may offer the non-security preview updates early; turning it off makes your PC wait for the regular monthly schedule. Active hours stop automatic restarts during your working day. Pause updates postpones installations for a chosen period; the maximum you can pause from the interface is limited (currently up to five weeks in one-week steps), and Windows installs pending updates once the pause ends.
Do not switch off Windows Update permanently. Disabling the service or blocking Microsoft servers with a hosts file or firewall leaves the PC without security fixes, and as the 24H2 case shows, it also leaves it behind on its feature release.
Do not use "optimizer" or debloat tools right before Patch Tuesday
Scripts and tools that disable services, remove Windows components or change telemetry settings are a leading cause of cumulative updates that fail or loop. If you have run one, expect trouble, and check the error table in the next section before panicking.
The enterprise and managed path: rings, pilots and deferral
A business should never push a monthly update to every computer on the same day: patch a small pilot ring first, wait 24 to 72 hours, then widen in stages, with a documented rollback and a faster path for actively exploited vulnerabilities. This is the standard approach for Windows Update for Business, Intune and WSUS or Configuration Manager alike.
A four-ring plan fits most small and mid-sized organizations:
| Ring | Who is in it | Timing after Patch Tuesday | Gate to the next ring |
|---|---|---|---|
| 0: IT and test | IT staff PCs, one virtual machine per image | Day 0 to 1 | Boot, sign-in, VPN, printing, line-of-business app all pass |
| 1: Pilot | 5 to 10 percent of users across departments | Day 2 to 3 | No new tickets about the update and no blocking known issue |
| 2: Broad | Most users | Day 4 to 7 | Pilot clean, Microsoft's known issues reviewed again |
| 3: Critical | Servers, shared PCs, machines with special software | Day 7 to 14 | Backup verified, maintenance window approved |
Where the controls live
In Intune, create update rings under Devices, Windows, Update rings for Windows 10 and later. The ring settings include a quality update deferral period and a deadline after which restarts are forced. In Group Policy, the Windows Update for Business settings sit under Computer Configuration, Administrative Templates, Windows Components, Windows Update, in the sections for managing updates offered from Windows Update. Menu wording varies slightly between ADMX template versions, so check the policy search box if a path does not match. With WSUS or Configuration Manager, approve the update for the pilot group first and add the broad group after the gate.
For emergencies, Microsoft publishes an exploited-vulnerability flag in its Security Update Guide. If a fix on your platform addresses a vulnerability that is already being exploited, shorten the schedule: patch internet-facing systems and remote-access infrastructure first. The US Cybersecurity and Infrastructure Security Agency keeps a public Known Exploited Vulnerabilities catalogue that helps you decide, and the Canadian Centre for Cyber Security publishes alerts for Canadian organizations.
Commands for administrators
Verify the installed update on a remote or local PC, and compare it with your expected KB:
Get-HotFix -Id KB0000000 # replace with the KB number from the release notes
Get-WindowsUpdateLog # builds a readable log on the Desktop for failed installs
dism /online /get-packages /format:table | more
Note that on the day you will substitute the real KB number; we cannot print it before it exists. To see which updates are waiting on a managed machine without opening the interface, use the Windows Update client from an administrator PowerShell:
(New-Object -ComObject Microsoft.Update.Session).CreateUpdateSearcher().Search("IsInstalled=0").Updates | Select-Object Title
Review failed devices by event log. Event ID 20 in the Microsoft-Windows-WindowsUpdateClient/Operational log records a failed installation with the error code, which you can match to the decision table in this guide.
Planning the 24H2 problem in a managed fleet
Enterprise and Education editions of 24H2 follow a longer timeline, so a managed fleet of those editions is not on the October 13 clock. Pro editions in an office are. Inventory your devices by edition and version first. In Intune, the Feature update deployment policy can pin a version, such as 25H2, and move devices to it in controlled waves. Group Policy offers Select the target Feature Update version for the same purpose. Do the feature update wave before the quality update wave, and keep a short list of exceptions with an owner and a date.
If your office also holds Windows 10 machines, they follow a separate lifecycle. Our article on the Windows 10 ESU free extension in October 2026 explains what that program covers and what to enroll in before you rely on it. Do not let the Windows 11 work make you forget those PCs.
Small office of 5 to 15 computers with no IT staff
Pick one person as the update owner. Ask them to patch their own PC on Wednesday, October 14, to check for problems, then patch the rest on Friday afternoon or the weekend with a short written note to staff. Keep the accountant's and the receptionist's PCs for last, because they cannot afford the downtime. If you do not want to own this, a remote support provider can do it for you in a scheduled window.
Install error decision table: what each code usually means
Most Windows Update failures fall into five families: damaged component store, full or undersized partitions, permission or security-software conflicts, interrupted downloads, and driver conflicts during restart. Match your error code to the table, apply the first fix, and only move down the ladder if it fails. The table lists the typical cause for each code. Typical does not mean certain, so a code is a starting point and the event log is the evidence.
| Error code | Usual meaning | First fix to try | Go deeper |
|---|---|---|---|
| 0x800f0993 | Package cannot be applied, often a damaged component store | Restart twice, free 20 GB, run DISM RestoreHealth and sfc | 0x800f0993 guide |
| 0x80070643 | Fatal installation error, often a small recovery partition or broken .NET or installer component | Check the recovery partition size, repair .NET, retry | Three-code guide |
| 0x80070005 | Access denied: permissions or security software | Pause third-party antivirus, run as admin, check folder permissions | 0x80070005 fix |
| 0x800f0922 | Full System Reserved or EFI partition, VPN active, or damaged store | Disconnect VPN, free the reserved partition, run DISM | 0x800f0922 fix |
| 0x80073712 | A file the update needs is missing or corrupt in the component store | DISM RestoreHealth, then sfc, then retry | 0x80073712 fix |
| 0x800f081f | Source files for a repair were not found | Run DISM with an install media source | 0x800f081f fix |
| 0x80070002 | File not found, often a damaged update cache | Reset the update cache (SoftwareDistribution) | 0x80070002 fix |
| 0x80070bc2 | Update installed but needs a restart to finish | Restart, then check update history | Run the RebootRequired check above |
| 0x80240034 or 0x8024a105 | Download failed or the update client is out of sync | Reset update components, check disk space and clock | Reset script in the ladder below |
| 0xc1900101 family | A driver or software conflict forced a rollback at restart | Unplug extras, update chipset, graphics and storage drivers, remove third-party security | Safe Mode guide |
| Stuck at a percentage | Often just slow, sometimes a hung install | Wait at least an hour with disk activity before forcing a restart | Repair loop guide |
If your code is not listed, search for the code on its own and include your Windows version. Be careful about sites that tell you to download a "fixer" program: Microsoft does not distribute repair tools through third-party download pages, and fake fixers are a common malware route. Use the built-in tools and Microsoft's own pages.
The fix ladder: from least risky to most
Work down the ladder in order: restart and free space, run the built-in troubleshooter, repair the component store, reset the update cache, install the update manually, and only then consider an in-place repair upgrade. Each step is more invasive than the last, and most problems are solved by step three. Take notes at each step so a technician, if you call one, can skip what you have already done.
Step 1: restart, free space, disconnect extras
Restart the computer twice. Make sure at least 20 GB is free. Unplug USB drives, docks, smart-card readers and printers you do not need. Disconnect the VPN, because some VPN clients block the Windows Update network path and trigger 0x800f0922. Retry the update.
Step 2: the built-in troubleshooter
Open Settings, System, Troubleshoot, Other troubleshooters and run Windows Update. Microsoft has been moving some troubleshooters into the Get Help app, so the screen may differ slightly. It resolves simple permission and service-state problems and costs nothing to try.
Step 3: repair the component store
In an administrator Terminal:
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
shutdown /r /t 0
If DISM reports that it cannot find source files (the 0x800f081f case), mount a Windows 11 ISO of the same version and point DISM to it. Replace D: with the mounted drive letter and the index with your edition:
DISM /Online /Cleanup-Image /RestoreHealth /Source:WIM:D:\sources\install.wim:1 /LimitAccess
If your ISO contains an install.esd instead, use /Source:ESD:D:\sources\install.esd:1. List the indexes with DISM /Get-WimInfo /WimFile:D:\sources\install.wim.
Step 4: reset the update cache
This clears the folders where Windows keeps downloaded and partly installed updates. The old folders are renamed, not deleted, so you can go back. In an administrator Command Prompt:
net stop wuauserv
net stop cryptSvc
net stop bits
net stop msiserver
ren C:\Windows\SoftwareDistribution SoftwareDistribution.old
ren C:\Windows\System32\catroot2 catroot2.old
net start wuauserv
net start cryptSvc
net start bits
net start msiserver
Retry Windows Update. The first scan may take several minutes, and the update history may appear empty, which is cosmetic. Once things work you can delete the .old folders to reclaim space.
Step 5: install the package manually
Take the KB number shown in Windows Update, search for it in the Microsoft Update Catalog, download the package matching your system type (x64 or Arm64) and run it. Standalone packages bypass the download part of the update client, which is why this works when downloads fail. A .msu installs by double-click, or from a Terminal:
wusa.exe "C:\Users\You\Downloads\windows11.0-kbXXXXXXX-x64.msu" /quiet /norestart
Cumulative updates for newer releases may be split into several files that must be installed in order; the catalogue entry and the support article say so. Check the architecture with systeminfo | findstr /C:"System Type".
Step 6: the in-place repair upgrade
If the earlier steps fail, an in-place repair reinstalls Windows over itself while keeping files and applications. Download the Windows 11 ISO from Microsoft's official download page, mount it, run setup.exe and choose to keep personal files and apps. It is slower, around an hour, but it replaces the damaged system files and component store with a clean copy. It is the step most technicians use before considering a full reinstall. Back up first, always.
Stop and get help if you see any of these
- The PC reboots in a loop and never reaches the sign-in screen.
- The screen asks for a BitLocker recovery key and you do not have it.
- The drive makes clicking sounds or the disk health tool reports failure.
- Files you need are missing and the only copy was on this PC.
Power the machine off, do not try more repairs that write to the disk, and call 1 (888) 711-9428. Writing to a failing drive can turn a recoverable situation into a lost one.
Reading the real error in the logs
Do not rely only on the code that Windows Update shows. Open Event Viewer, then Applications and Services Logs, Microsoft, Windows, WindowsUpdateClient, Operational, and look for the entries with Event ID 20 (installation failure) around the time of the problem. The error message and code there are the exact evidence. For deeper analysis, the commands below build the readable update log and show the servicing log:
Get-WindowsUpdateLog
notepad C:\Windows\Logs\CBS\CBS.log
The CBS log is large. Search it for the word error and read the lines near the first match, since later errors are often only consequences of the first. If this looks like too much, a technician reads these logs in minutes, and a remote session lets them do it while you watch.
How to roll back a monthly update
If an update causes a problem, you can usually remove it from Settings, Windows Update, Update history, Uninstall updates, or from the Windows Recovery Environment if the PC will not start. Rolling back is a temporary measure: it removes the security fixes too, so plan to reinstall once the problem is understood. Rollback is not available for every package, and removing the wrong thing can create new trouble, so treat it as a controlled step.
Rollback when Windows still starts
- Open Settings, Windows Update, Update history, scroll to Uninstall updates under Related settings.
- Find the cumulative update by its KB number and installation date, select it and choose Uninstall.
- Restart, then confirm the problem has gone before changing anything else.
- Pause updates (next section) so it does not reinstall tonight.
From the command line, with the KB number (digits only) in place of XXXXXXX:
wusa /uninstall /kb:XXXXXXX
Some cumulative updates are bundled with a servicing stack update that cannot be removed this way. If wusa says the update cannot be uninstalled, the package list helps you find the exact name for DISM:
DISM /Online /Get-Packages /Format:Table
DISM /Online /Remove-Package /PackageName:Package_for_RollupFix~31bf3856ad364e35~amd64~~VERSION
Only use the DISM removal if you know the exact package name. A typing error does nothing harmful, but a wrong choice of package can.
Rollback when Windows will not start
Force the Recovery Environment: turn the PC on and power it off with the button during the logo three times in a row, or hold Shift while choosing Restart from the sign-in screen. Choose Troubleshoot, Advanced options, Uninstall Updates, then pick Uninstall latest quality update. This works even from a PC that cannot reach the desktop. If you are prompted for a BitLocker key, enter it. If recovery still fails, Advanced options also offers System Restore and Startup Repair. Our article on the Windows 11 automatic repair loop goes further for a PC that keeps rebooting.
What rollback does not do
It does not undo a feature update after the roll-back window closes (the "Go back" option in Settings, Recovery is available for a limited time, usually ten days, after a feature release), it does not repair a damaged disk, and it does not restore deleted files. A feature update also installs differently from a monthly one, so the steps above are for monthly cumulative updates. If the 25H2 or 26H2 enablement package is what you want out, use Settings, System, Recovery, and read the on-screen limits first.
Known Issue Rollback: a Microsoft feature you do not control
Microsoft sometimes disables a faulty change remotely through a mechanism it calls Known Issue Rollback. When this applies, Windows fetches the setting change automatically and a restart completes it, with no uninstall needed. Enterprise administrators can also deploy a Group Policy for it. You will find such cases mentioned in the release health page, which is why we ask you to read it on release day. We cannot say whether it will apply to the October release.
How to pause updates, and the limits of pausing
You can pause Windows updates from Settings, Windows Update, Pause updates for up to five weeks, or defer them with an update ring on managed devices. Pause for a reason and with an end date, because a paused PC is an unpatched PC. Pausing is the right answer when you are mid-project, travelling with a laptop you depend on, or waiting for a vendor to confirm compatibility.
| Method | Who it suits | Duration | Risk |
|---|---|---|---|
| Pause updates (Settings) | Home users and travellers | Up to five weeks in one-week steps | Low if you resume on schedule |
| Active hours | Anyone who dislikes surprise restarts | Permanent setting | None, but updates still install |
| Metered connection | Mobile hotspots | Until you switch it off | Delays some downloads only; not a security control |
| Update ring deferral (Intune) | Managed fleets | Quality deferral in days, per policy | Low with a pilot ring |
| Group Policy deferral | Domain-joined PCs | Per policy | Low with documentation |
| Stopping the Windows Update service | Nobody | Until Windows restarts it | High and unreliable: Windows restores the service |
When you pause, put a reminder on your calendar for the day before it ends, with the task "Review release health and install". Windows will install pending updates when the pause ends, and if you have forgotten, that can be at an inconvenient hour. For a managed device, document the deferral and who approved it.
One more limit worth knowing: pausing does not extend the life of a release that has reached the end of servicing. A PC on 24H2 Home or Pro that is paused past October 13 is not "waiting for a fix"; there will be no further fix for that release.
Special cases for October: BitLocker, Secure Boot and Office
October combines a monthly update with boot-level certificate work, so a small number of PCs may show a BitLocker recovery prompt after a restart. Save your recovery key in advance and the prompt becomes a two-minute inconvenience instead of a lockout. We do not know whether the October release changes boot components; we only know that the 2011 Secure Boot certificate expiry is scheduled for October 19 and that Microsoft delivers the replacement through updates and firmware.
Secure Boot status commands
Use these in an administrator PowerShell. They only read the state; they do not change anything:
Confirm-SecureBootUEFI
Get-WinEvent -FilterHashtable @{LogName='System'; Id=1801,1808} -MaxEvents 5 | Format-List TimeCreated, Id, Message
As explained in our Secure Boot certificate guide, a True result means Secure Boot is on, Event ID 1808 indicates the new certificates were applied, and 1801 indicates they were not yet applied. If Secure Boot is off or unsupported on an older machine, the guide explains why that is not a reason to panic and not a reason to disable anything else. Do not turn Secure Boot off in the firmware to avoid the topic, because that can itself trigger BitLocker recovery.
Office LTSC 2021
If your office uses the volume-licensed perpetual edition, October 13 is its last supported day. Check Word's Account page for the product name: it will say "Office LTSC 2021" or similar. Options include moving to Microsoft 365 Apps, buying a current perpetual edition, or keeping the old edition on machines that are not exposed to email attachments from outside. Office fixes normally ship on Patch Tuesday too, but after the end-of-support date a product no longer receives them, so treat the updates released on or before October 13 as the last ones for that edition. Plan the license change in the weeks ahead, because ordering, deployment and training take longer than an update.
If you also manage Windows 10 machines
Windows 10 sits on a separate timeline. Consumers can enroll in the Extended Security Updates program, and we summarized what is reported about the free extension in our Windows 10 ESU guide. For October, ask whether each Windows 10 PC is enrolled before you assume it will receive the monthly update.
What to check on release day: October 13, 2026
On release day, read four things in this order: Microsoft's Windows release health page for known issues, the support article for your version's KB, the Security Update Guide for exploited vulnerabilities, and your own pilot machine. Decide whether to install now or wait only after that. This section is a script you can follow the moment the update appears. It deliberately contains no claims about the contents, because the contents are not published yet.
Release-day checklist (October 13, 2026)
- Open the Windows release health page and read the Known issues for your version (24H2, 25H2 or 26H2).
- Open the support article for the cumulative update. Note the KB number, the OS build and the list of improvements.
- Open the Security Update Guide and look for vulnerabilities marked as exploited or publicly disclosed.
- Check the Canadian Centre for Cyber Security and CISA alerts if you run internet-facing systems.
- Install on the IT or pilot machine first. Run
winverand confirm the build matches the article. - Test sign-in, VPN, printing, the line-of-business app, and the Office apps.
- Check whether the Secure Boot Event IDs 1801 or 1808 appear and that your BitLocker key is in hand.
- Decide: install now, wait 48 to 72 hours, or defer a non-exploited fix for one week.
- Record the decision, the KB number and the date in your change log.
How to read the release notes quickly
Start with the Highlights and Known issues sections of the support article. The first tells you whether new features or changed behaviour arrive; the second tells you whether Microsoft has acknowledged a problem and whether a workaround exists. Then look at the build number (for example 26100.xxxx or a newer build for later releases) and match it with winver after installing. If your PC shows an older build, the update has not applied, even if the interface says "up to date".
In the Security Update Guide, filter by product and by month. The important markers are Exploited: Yes and Publicly disclosed: Yes, plus the severity rating and the impact (remote code execution, elevation of privilege and so on). Those markers, not the total count of vulnerabilities, tell you how fast you need to move. A large month with no exploited flaws can wait a few days; a short month with an actively exploited remote-code-execution flaw cannot. This is the reason we do not predict anything: the number says little, the flags say much.
Install now or wait: a decision table
| Situation on release day | Home user | Business |
|---|---|---|
| An exploited vulnerability affects your Windows version | Install within 24 hours | Patch pilot today, internet-facing systems within 24 to 48 hours |
| Microsoft lists a known issue that matches your setup | Wait; apply the workaround if given | Hold that ring, document the exception |
| No exploited flaw and no known issue for you | Install within a few days | Follow the ring schedule |
| You are on 24H2 Home or Pro | Upgrade to 25H2 or 26H2, then install | Upgrade wave first, then quality update |
| Critical deadline this week (payroll, tax, exam) | Postpone to a quiet window, with a pause set | Schedule a maintenance window after the deadline |
| Update fails with an error | Use the error table above | Triage by event log, escalate after two failed attempts |
Where we will update this page
After the release, this page gets a dated section with the KB numbers, the build numbers, the headline known issues Microsoft acknowledges and any new error codes people report. The preparation advice above will not change, which is the point: it works for every month. We will also add the date of our last review at the top. If you read this before October 13, the release-day section is a plan; if you read it afterwards, look for the update note.
Three realistic scenarios (illustrative)
These are illustrative examples based on common situations, not specific clients. They show how the preparation steps change the outcome of Patch Tuesday for a family, a small office and a mixed fleet. Numbers are rounded and meant to give a sense of scale.
Scenario 1: the family laptop on 24H2 with updates paused
A four-year-old laptop has had updates paused since a summer trip. Winver shows 24H2 Home. The owner resumes updates on October 5, installs 25H2 in about 30 minutes, restarts, and waits two days after October 13 before installing the monthly update. Total effort: 45 minutes, cost: nothing. The step that mattered was noticing that the pause banner was still on, because a paused 24H2 Home PC would have missed its last supported update.
Scenario 2: the 9-person accounting office
The office has nine Windows 11 Pro PCs, six on 25H2 and three on 24H2. The owner picks one person to patch. On Thursday the three 24H2 machines are upgraded one at a time, each tested with the accounting software and the printer. On October 14 the update owner installs the monthly update on their own PC, and on Friday evening the rest follow. One PC shows error 0x800f0922 because a VPN client is connected; disconnecting it solves the problem in five minutes. Without the plan the error would have appeared on a Monday morning with the whole office waiting.
Scenario 3: the 40-seat office with Intune
A managed fleet has 40 PCs in four rings. Ring 0 is two IT machines, ring 1 is four users, and the rest follow at day 7. On release day the administrator reads the release notes, sees an acknowledged issue affecting a printing feature that the office does not use, and proceeds. A different office, with the same plan, might hold the ring for a week: the point is that the decision is based on documentation, not on guesswork. One PC fails with 0x80073712; a DISM repair fixes it. The administrator finishes in an afternoon instead of reacting to forty tickets at once.
What it costs in Canadian dollars
For a single PC, doing everything in this guide yourself costs nothing but time, about 45 to 90 minutes including backup. A remote session with IT Cares costs 119.99 $ CAD for a 60 minute Expert Consultation, which typically covers preparing, updating and verifying one or two machines. A failed update that turns into a data-recovery job costs much more, which is why preparation is cheaper than repair.
| Option | Cash cost (CAD) | Time | Best for |
|---|---|---|---|
| Do it yourself with this guide | 0 $, plus an external drive if you have none (roughly 60 to 120 $) | 45 to 90 minutes | Home users comfortable with Settings |
| Remote support session | 119.99 $ for 60 minutes | One hour, you watch | Offices with one to three PCs, or any stuck update |
| Managed rollout for a small office | Depends on the number of machines; ask for a quote | Scheduled window | Offices with no IT person |
| Ignoring it | 0 $ now | None now | No one: the cost shows up later as risk and downtime |
The hidden cost is downtime. If a five-person office loses a day to a failed update, the lost working hours dwarf the price of a technician. Counting even a modest 40 $ an hour per person, five people for a day equals 1,600 $. This is the logic behind patch windows: you pay a little in advance to avoid a big bill later.
Common mistakes and myths
- "I will turn updates off to be safe." This leaves you without security fixes. Pause with an end date instead.
- "Patch Tuesday always breaks things." Most months pass without trouble for most users. Preparation is cheap insurance against the rare month that does not.
- "My antivirus protects me, so updates are optional." Antivirus catches many threats, but it does not replace operating system fixes.
- "Up to date" means I am current. Check the build number with
winverand compare it to the release notes. - "I will install the update the minute it comes out." Unless an exploited flaw affects you, waiting a day or two is a reasonable choice.
- "A fixer download will solve my error." Third-party fixers are a common malware route. Use built-in tools.
- "24H2 will keep working, so why upgrade?" It works, but without fixes. October 13 is the last update that release can receive.
When to stop and call a professional
Call a technician if the PC will not start after an update, if you meet the same error after the fix ladder, if a BitLocker prompt appears and you have no key, if you manage more than a handful of computers, or if the machine holds data you cannot lose. Calling early is cheaper than repairing late, and a technician who sees the logs can often tell in minutes what would take you an afternoon.
IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. A remote session lets a technician connect to your PC while you watch, prepare it for Patch Tuesday, repair update components, move the upgrade forward and explain what was wrong. Our Google rating is 4.9 stars from 78 reviews.
To talk to someone now, call 1 (888) 711-9428 or book a remote session. If you have a failed update and a deadline, say so on the call; we triage by urgency.
Still stuck? Get a technician on it now
Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.
Frequently asked questions
Related guides
- Windows 11 24H2 end of support: upgrade to 25H2 or 26H2
- KB5129195 install error 0x800f0993 fix
- Error 0x80070643, 0x80070005, 0x800f0922: Windows Update fix
- Windows 10 ESU free extension in October 2026
- Windows 11 Safe Mode: start, exit and fix when stuck
- Secure Boot certificate expiry in 2026: what to do
- BitLocker recovery key after a Windows update
- Windows 11 automatic repair loop and stuck updates
- Windows Update stuck or failing: how to fix it
- April 2026 Patch Tuesday guide
- July 2026 Patch Tuesday guide for small business
- Fix error 0x80073712
Sources and official references
Last verified: October 1, 2026
- Microsoft Lifecycle: Windows 11 Home and Pro (end of servicing dates for 24H2, 25H2, 26H2)
- Microsoft Windows release health
- Microsoft Support: Windows Secure Boot certificate expiration and CA updates
- Microsoft Security Update Guide
- CISA Known Exploited Vulnerabilities Catalog
- Canadian Centre for Cyber Security: alerts and advisories
- Microsoft: Download Windows 11 (ISO and Installation Assistant)
