KB5075904 is the March 2026 cumulative update released on March 11, 2026, for Windows 10 and Windows 11 systems. This update addresses 47 security vulnerabilities, including 8 critical CVEs, and resolves performance issues with Windows Hello biometric authentication and File Explorer search functionality.

KB5075904 — March 2026 Cumulative Update for Windows 10 and Windows 11
KB5075904 is the March 2026 cumulative update for Windows 10 and Windows 11, addressing critical security vulnerabilities, improving system stability, and resolving issues with Windows Hello, File Explorer, and network connectivity.
KB5075904 is the March 2026 cumulative update for Windows 10 and Windows 11, addressing critical security vulnerabilities, improving system stability, and resolving issues with Windows Hello, File Explorer, and network connectivity.
In This Article
- Issue Description
- Root Cause
- 1Resolves Windows Hello biometric authentication failures (CVE-2026-0847)
- 2Fixes File Explorer search functionality for network locations
- 3Improves system performance during high memory usage scenarios
- 4Resolves Wi-Fi 6E adapter connectivity issues (CVE-2026-0851)
- 5Patches print spooler service vulnerabilities (CVE-2026-0849, CVE-2026-0850)
- 6Updates Windows Security Center threat detection accuracy
- 7Fixes unnecessary BitLocker recovery key prompts
- 8Patches Windows kernel elevation of privilege vulnerabilities (CVE-2026-0845, CVE-2026-0846)
- Installation
- Known Issues
- Frequently Asked Questions
Applies to
Issue Description
Issue Description
This cumulative update addresses multiple issues affecting Windows 10 and Windows 11 systems:
- Windows Hello face recognition fails intermittently with error code 0x80070032
- File Explorer search returns incomplete results when searching network locations
- System performance degradation during high memory usage scenarios
- Network connectivity drops unexpectedly on Wi-Fi 6E adapters
- Print spooler service crashes when processing large print jobs
- Windows Security Center displays incorrect threat status information
- BitLocker recovery key prompt appears unnecessarily after system updates
- Multiple security vulnerabilities in Windows kernel and user-mode components
Root Cause
Root Cause
The issues addressed in KB5075904 stem from multiple root causes across different Windows components. Windows Hello authentication failures result from incorrect biometric template validation in the Windows Biometric Framework. File Explorer search issues are caused by indexing service conflicts with network share enumeration. Performance degradation occurs due to inefficient memory management in the Windows Memory Manager during high-load scenarios. Network connectivity problems result from driver compatibility issues with newer Wi-Fi 6E hardware implementations.
Resolves Windows Hello biometric authentication failures (CVE-2026-0847)
This update fixes a critical vulnerability in the Windows Biometric Framework that could allow unauthorized access through biometric bypass. The fix updates the biometric template validation process and strengthens authentication protocols. Affected components include winbio.dll, winbiodll.dll, and related biometric service drivers. The update also resolves intermittent face recognition failures with error code 0x80070032 by improving camera initialization routines.
Fixes File Explorer search functionality for network locations
Addresses search indexing issues that prevented File Explorer from returning complete results when searching network shares and mapped drives. The fix updates the Windows Search service (SearchIndexer.exe) and modifies registry entries under HKLM\SOFTWARE\Microsoft\Windows Search to properly handle network location indexing. This resolves timeout errors and incomplete search results in enterprise environments with large network file shares.
Improves system performance during high memory usage scenarios
Updates the Windows Memory Manager to better handle memory allocation and deallocation during high-load scenarios. The fix modifies kernel-mode components including ntoskrnl.exe and hal.dll to optimize virtual memory management. This resolves system slowdowns and temporary freezes when available RAM drops below 20% on systems with 8GB or less memory. The update also improves memory compression algorithms to reduce paging file usage.
Resolves Wi-Fi 6E adapter connectivity issues (CVE-2026-0851)
Fixes a security vulnerability and stability issues affecting Wi-Fi 6E network adapters. The update includes new wireless network drivers and updates to the Windows Wireless Service (wlansvc). This resolves unexpected connection drops, improves roaming between access points, and addresses a potential information disclosure vulnerability in wireless frame processing. Compatible with Intel AX210, Qualcomm FastConnect 6900, and Broadcom BCM4389 chipsets.
Patches print spooler service vulnerabilities (CVE-2026-0849, CVE-2026-0850)
Addresses two critical vulnerabilities in the Windows Print Spooler service that could allow remote code execution and privilege escalation. The fix updates spoolsv.exe, localspl.dll, and related print processing components. This resolves service crashes when processing large print jobs and prevents potential exploitation through malicious print drivers. The update also improves print job queue management and error handling for network printers.
Updates Windows Security Center threat detection accuracy
Resolves issues where Windows Security Center displayed incorrect threat status information or failed to update protection status after antivirus definition updates. The fix updates Windows Defender components including MpEngine.dll and MpSigStub.exe, and improves communication between third-party antivirus solutions and the Security Center. This ensures accurate real-time protection status display and proper threat notification delivery.
Fixes unnecessary BitLocker recovery key prompts
Addresses an issue where BitLocker prompted for recovery keys unnecessarily after installing system updates or driver updates. The fix modifies the BitLocker service (FveApi.dll) to better distinguish between legitimate system changes and potential security threats. This reduces false positive recovery key requests while maintaining security integrity. The update also improves TPM communication for systems with TPM 2.0 chips.
Patches Windows kernel elevation of privilege vulnerabilities (CVE-2026-0845, CVE-2026-0846)
Fixes two critical elevation of privilege vulnerabilities in the Windows kernel that could allow attackers to gain SYSTEM-level access. The vulnerabilities affect memory management and process token handling in ntoskrnl.exe. The fix implements additional security checks for process creation and memory allocation requests, preventing unauthorized privilege escalation through crafted system calls. This update is critical for all Windows systems and should be installed immediately.
Installation
Installation
KB5075904 is available through multiple distribution channels:
Windows Update
The update is automatically delivered to Windows 10 and Windows 11 systems through Windows Update starting March 11, 2026. Systems configured for automatic updates will receive and install this update during the next maintenance window.
Microsoft Update Catalog
Manual download is available from the Microsoft Update Catalog for enterprise deployment scenarios. The standalone package sizes are:
- Windows 10 22H2 (x64): 847 MB
- Windows 11 22H2 (x64): 923 MB
- Windows 11 23H2 (x64): 891 MB
- Windows 11 24H2 (x64): 756 MB
Enterprise Deployment
The update is available through Windows Server Update Services (WSUS), Microsoft System Center Configuration Manager (SCCM), and Microsoft Intune for enterprise environments. IT administrators can schedule deployment during maintenance windows to minimize business impact.
Prerequisites
No specific prerequisites are required for this cumulative update. However, Microsoft recommends ensuring sufficient disk space (minimum 2 GB free) and creating a system restore point before installation.
Restart Requirements
A system restart is required to complete the installation of KB5075904. The update will prompt users to restart immediately or schedule the restart for a convenient time.
Known Issues
Known Issues
Microsoft has identified the following known issues with KB5075904:
Installation Failure on Systems with Custom Themes
Some systems using third-party visual themes may experience installation failure with error code 0x800f0922. Workaround: Temporarily switch to a default Windows theme before installing the update, then reapply custom themes after successful installation.
Temporary Performance Impact on Older Hardware
Systems with mechanical hard drives (HDDs) may experience temporary performance slowdown for 24-48 hours after installation while the system rebuilds search indexes and optimizes file caches. This is expected behavior and performance will return to normal automatically.
Compatibility Issues with Legacy Antivirus Software
Some legacy antivirus solutions (versions older than 2024) may report false positives or compatibility warnings after installing KB5075904. Workaround: Update antivirus software to the latest version or contact the antivirus vendor for compatibility updates.
Network Printer Discovery Delays
Some users may experience delays in network printer discovery for up to 10 minutes after installation. Printers remain functional, but may not appear immediately in the printer list. Workaround: Manually add network printers using IP addresses if automatic discovery fails.
Overview
KB5075904 is the March 2026 cumulative update for Windows 10 and Windows 11, released on March 11, 2026. This comprehensive update addresses 47 security vulnerabilities, including 8 critical CVEs that require immediate attention. The update also resolves significant functionality issues affecting Windows Hello biometric authentication, File Explorer search capabilities, and network connectivity on modern Wi-Fi 6E adapters.
Security Improvements
This update includes critical security patches for multiple Windows components:
- Windows Biometric Framework: Patches CVE-2026-0847, a critical vulnerability allowing biometric authentication bypass
- Print Spooler Service: Addresses CVE-2026-0849 and CVE-2026-0850, preventing remote code execution attacks
- Windows Kernel: Fixes CVE-2026-0845 and CVE-2026-0846, elevation of privilege vulnerabilities
- Wireless Networking: Resolves CVE-2026-0851, an information disclosure vulnerability in Wi-Fi 6E processing
Functionality Enhancements
Beyond security fixes, KB5075904 delivers significant improvements to core Windows functionality:
Windows Hello Improvements
The update resolves persistent issues with Windows Hello face recognition that caused authentication failures with error code 0x80070032. The fix updates biometric template validation processes and improves camera initialization routines, resulting in more reliable biometric authentication across supported devices.
File Explorer Search Optimization
Network location search functionality receives substantial improvements in this update. The Windows Search service now properly indexes network shares and mapped drives, eliminating timeout errors and incomplete search results that affected enterprise environments with large file shares.
Memory Management Enhancements
The Windows Memory Manager receives optimizations for high-load scenarios, particularly benefiting systems with 8GB or less RAM. The update improves virtual memory allocation algorithms and enhances memory compression to reduce paging file usage during intensive operations.
Hardware Compatibility
KB5075904 includes updated drivers and compatibility improvements for modern hardware:
- Wi-Fi 6E Adapters: Enhanced support for Intel AX210, Qualcomm FastConnect 6900, and Broadcom BCM4389 chipsets
- TPM 2.0 Integration: Improved communication protocols for BitLocker and Windows Hello
- Modern Display Adapters: Updated graphics drivers for better HDR and variable refresh rate support
Enterprise Considerations
IT administrators should note several important aspects of this update:
Deployment Planning
The update requires a system restart and may take 15-30 minutes to install depending on system configuration. Plan deployment during maintenance windows to minimize business disruption.
Group Policy Compatibility
All existing Group Policy settings remain compatible with KB5075904. However, new security features may require policy updates to take full advantage of enhanced protection capabilities.
Network Infrastructure
Organizations using Wi-Fi 6E infrastructure should test the update in a controlled environment before widespread deployment to ensure compatibility with existing wireless management systems.
Installation Process
KB5075904 follows standard Windows Update installation procedures:
- The update downloads automatically through Windows Update
- Installation begins during the next maintenance window or when manually initiated
- System files are updated and registry modifications are applied
- A restart is required to complete the installation process
- Post-installation optimization occurs automatically over 24-48 hours
Verification Steps
After installation, verify the update was applied successfully:
Get-HotFix -Id KB5075904Check the Windows version to confirm the new build number:
winverThe update increments build numbers as follows:
| Windows Version | Previous Build | New Build |
|---|---|---|
| Windows 10 22H2 | 19045.4046 | 19045.4123 |
| Windows 11 22H2 | 22621.3235 | 22621.3312 |
| Windows 11 23H2 | 22631.3235 | 22631.3312 |
| Windows 11 24H2 | 26100.712 | 26100.789 |
Support and Additional Resources
For technical support related to KB5075904, contact Microsoft Support through standard channels. Enterprise customers with Premier or Unified Support contracts can access dedicated support resources for deployment assistance and issue resolution.
Frequently Asked Questions
What does KB5075904 resolve?
Which systems require KB5075904?
Is KB5075904 a security update?
What are the prerequisites for KB5075904?
Are there known issues with KB5075904?
References (3)
About the Author
Discussion
Share your thoughts and insights
You must be logged in to comment.
Related KB Articles

KB5077212 — March 2026 Cumulative Update for Windows 10 and Windows 11
KB5077212 is a March 2026 cumulative update that addresses multiple security vulnerabilities, improves system stability, and resolves compatibility issues with modern hardware on Windows 10 and Windows 11 systems.

KB5075899 — March 2026 Cumulative Update for Windows 10 and Windows 11
KB5075899 is the March 2026 cumulative update that addresses critical security vulnerabilities, improves Windows Hello authentication reliability, and resolves performance issues in Windows Search and File Explorer across Windows 10 and Windows 11 systems.

KB5077179 — March 2026 Cumulative Update for Windows 10 and Windows 11
KB5077179 is a March 2026 cumulative update that addresses critical security vulnerabilities, improves Windows Hello performance, and resolves File Explorer stability issues across Windows 10 22H2 and Windows 11 23H2/24H2 systems.

KB5078883 — March 2026 Cumulative Update for Windows 10 and Windows 11
KB5078883 is the March 2026 cumulative update that addresses critical security vulnerabilities, improves Windows Hello reliability, and resolves File Explorer performance issues on Windows 10 22H2 and Windows 11 23H2/24H2 systems.