Windows Secure Boot certificate expiration
Important Secure Boot certificates used by most Windows devices started to expire in June 2026. Microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months.
Summary
This article lists the security issues and quality improvements included in this cumulative security update.
Applies to: Windows Server 2016
This security update includes fixes and improvements that are a part of the following update:
The following is a summary of the issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting.
- [Backup] File History automatic backups to network shares using Server Message Block (SMB) might fail with an incorrect "invalid credentials" error. When this issue occurs, scheduled backups do not copy any files. This update resolves the issue.
- [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device.
For more information about security vulnerabilities, see the Security Update Guide website and the August 2026 Security Updates.
For more information about Windows Server 2016, see its update history page.
For information about Windows update terminology, see types of Windows updates and monthly quality update types.
Known issues in this update
CompatTelRunner.exe might close unexpectedly
Symptoms
After installing this update, some Windows Server 2016 devices might generate recurring Application Error events (Event ID 1000, with exception code 0xc0000409) associated with CompatTelRunner.exe. Reports have been observed on physical devices and virtual machines, including Azure and VMware environments.
CompatTelRunner.exe performs compatibility inventory and related diagnostic tasks. Although recurring CompatTelRunner.exe failures might generate Application event log entries, they do not affect device functionality. The associated event log warnings can be safely dismissed temporarily until a resolution is released in an upcoming update.
Resolution
This issue is resolved in Windows updates released on and after September 8, 2026 (such as KB5123099). We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
How to get this update
Before you install this update
To install updates released on or after January 14, 2025, we recommend that you first install the latest Servicing Stack Update (SSU). If your device or offline image does not have the latest SSU installed, you might not be able to install this update.
Caution
Until you install the SSU, this update might not be offered to your device. To reduce your security risk, install the SSU as soon as possible.
- If you use Windows Update, the latest SSU (KB5120236) will be offered to you automatically. If the latest SSU is not installed, you might not be able to install this update.
- If you use Windows Update for Business, the latest SSU (KB5120236) will be offered to you automatically. If the latest SSU is not installed, you might not be able to install this update.
- If you use the Update Catalog, we recommend that you download and install the latest SSU (KB5120236). If the latest SSU is not installed, you might not be able to install this update.
- If you are a Windows Server Update Services (WSUS) administrator, you must approve SSU KB5120236 and this update KB5120418. For general information about SSUs, see Servicing stack updates.
Get and install this update
To get and install this update, use one of the following Windows and Microsoft release channels.
| Available | Next step |
|---|---|
|
This update will be downloaded and installed automatically from Windows Update. |
File information
A list of the files included in this update is provided in a CSV (Comma delimited) (*.csv) file. You can open the file in a text editor such as Notepad or in Microsoft Excel.
Note The English (United States) version of this software update might contain files for additional languages.
Download the file information for cumulative update KB5120418.
Related topics
Microsoft Store application updates
Windows updates do not install Microsoft Store application updates. Enterprise users should see Microsoft Store apps - Configuration Manager. Consumer users should see Get updates for apps and games in Microsoft Store.Windows Secure Boot certificate expiration
Important: Secure Boot certificates used by most Windows devices have started expiring in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates.End of support
Microsoft will no longer provide free software updates from Windows Update, technical assistance, or security fixes on the following end dates. For information about the availability of Extended Security Updates (ESUs), see Plan for Windows Server 2016 and Windows 10 2016 LTSB end of support.- Windows 10 Enterprise LTSB 2016 - October 13, 2026
- Windows 10 IoT Enterprise 2016 LTSB - October 13, 2026
- Windows Server 2016 - January 12, 2027
Change log
| Change date | Change description |
|---|---|
| September 8, 2026 | Added resolution for known issue, "CompatTelRunner.exe might close unexpectedly". |
| September 4, 2026 | Added a known issue, "CompatTelRunner.exe might close unexpectedly". |