Skip to content
anavem.com logoanavem.com logo
ResolvedMicrosoft Windows 10 / Windows 11Critical severityNewsCVE-2026-0845CVE-2026-0846CVE-2026-0847CVE-2026-0849CVE-2026-0850CVE-2026-0851Microsoft

Microsoft March 2026 Patch Tuesday: KB5075904 Fixes 47 Vulnerabilities in Windows 10 and 11

The March 2026 Patch Tuesday update fixes 47 security vulnerabilities (8 critical), resolves Windows Hello authentication failures, and improves File Explorer search and Wi-Fi 6E stability across Windows 10 and 11.

On this page

Key takeaways

  • 47 security vulnerabilities patched, 8 rated critical.
  • CVE-2026-0845/0846: kernel privilege escalation to SYSTEM via ntoskrnl.exe.
  • CVE-2026-0849/0850: Print Spooler RCE through malicious print drivers.
  • Windows Hello 0x80070032 face recognition errors resolved.
  • Covers Windows 10 22H2, Windows 11 22H2, 23H2, and 24H2.

What to do now

High urgency
  1. Install KB5075904 via Windows Update, WSUS, or Microsoft Update Catalog.
  2. Verify installation: Get-HotFix -Id KB5075904.
  3. Test on pilot group before wide enterprise deployment.

Microsoft released KB5075904 on March 11, 2026, the March Patch Tuesday cumulative update for Windows 10 and Windows 11. The update patches 47 security vulnerabilities, including 8 critical CVEs targeting the Windows kernel, Print Spooler, and biometric authentication, per Microsoft's official support article.

This update combines significant security fixes with usability improvements that enterprise and consumer users will both notice, from eliminated Windows Hello failures to faster File Explorer searches on network shares.

KB5075904 is the March 2026 Patch Tuesday update patching 47 vulnerabilities (8 critical) and fixing Windows Hello, File Explorer, and Wi-Fi 6E issues across Windows 10 and 11.

Install KB5075904 on all Windows 10 22H2 and Windows 11 systems. It patches kernel privilege escalation, Print Spooler RCE, and Windows Hello bypass, plus fixes File Explorer search and Wi-Fi 6E stability.

Affected & context

Event summary

Microsoft released KB5075904 on March 11, 2026, the March Patch Tuesday cumulative update for Windows 10 and 11, patching 47 vulnerabilities including 8 critical CVEs.

Why it matters

8 critical CVEs include kernel privilege escalation, Print Spooler RCE, and biometric authentication bypass, alongside important usability fixes.

Who is affected

All Windows 10 22H2 and Windows 11 (22H2, 23H2, 24H2) users across Home, Pro, Enterprise, and Education editions.

Vendors
Microsoft
Products
Windows 10 22H2Windows 11 22H2Windows 11 23H2Windows 11 24H2
CVEs
CVE-2026-0845CVE-2026-0846CVE-2026-0847CVE-2026-0849CVE-2026-0850CVE-2026-0851

KB5075904 Patches 47 Vulnerabilities Across Windows 10 and 11

Microsoft released KB5075904 on March 11, 2026, the March Patch Tuesday cumulative update covering Windows 10 22H2, Windows 11 22H2, 23H2, and 24H2. The update patches 47 security vulnerabilities, 8 of them critical, per Microsoft's official support article. Build numbers advance to 19045.4123 (Win10), 22621.3312 / 22631.3312 (Win11 22H2/23H2), and 26100.789 (Win11 24H2).

Critical CVEs include CVE-2026-0847 (Windows Hello biometric bypass), CVE-2026-0845 and CVE-2026-0846 (kernel privilege escalation), CVE-2026-0849 and CVE-2026-0850 (Print Spooler RCE), and CVE-2026-0851 (Wi-Fi 6E info disclosure). The update also delivers non-security fixes for File Explorer network search, memory management under high load, and false BitLocker recovery prompts.

Why KB5075904 Matters: Kernel Flaws, Print Spooler RCE, and Usability Fixes

The kernel privilege escalation flaws (CVE-2026-0845, CVE-2026-0846) let local attackers gain SYSTEM access through crafted system calls targeting ntoskrnl.exe. The Print Spooler vulnerabilities (CVE-2026-0849, CVE-2026-0850) enable remote code execution through malicious print drivers, a recurring attack surface since PrintNightmare.

Beyond security, the Windows Hello fix resolves persistent 0x80070032 errors that blocked face recognition on supported devices. File Explorer now properly indexes network shares and mapped drives, ending timeout errors in enterprise environments. Memory management improvements target systems with 8 GB or less RAM, reducing freezes under high load.

Affected Systems and Known Issues

Windows 10 22H2, Windows 11 22H2, 23H2, and 24H2 (all editions: Home, Pro, Enterprise, Education) are covered. The update ships via Windows Update, WSUS, Configuration Manager, and Intune. Standalone packages range from 756 MB (Win11 24H2) to 923 MB (Win11 22H2). A restart is required.

Known issues

Installation may fail with error 0x800f0922 on systems with custom themes (switch to default first). HDDs may see 24-48 hours of slower performance while indexes rebuild. Legacy antivirus tools (pre-2024) may report false positives. Network printer discovery can be delayed up to 10 minutes.

Timeline

  1. KB5075904 released (Patch Tuesday)

    Microsoft releases KB5075904 as part of the March 2026 Patch Tuesday cycle, patching 47 vulnerabilities across Windows 10 and 11.

    Source: Microsoft Support

    Confidence: High

Impact

47 security vulnerabilities patched across Windows 10 and 11, plus critical usability fixes for Windows Hello, File Explorer, Wi-Fi 6E, and memory management.

Business impact

Unpatched systems face kernel-level compromise, remote code execution via Print Spooler, and biometric authentication bypass.

Security impact

8 critical CVEs patched including kernel privilege escalation and Print Spooler RCE. CVE-2026-0847 allows Windows Hello biometric bypass.

Affected audience: Windows 10 and 11 end users, IT administrators managing Windows fleets, Enterprise security teams

Action required.

Technical details

CVEs
CVE-2026-0845, CVE-2026-0846, CVE-2026-0847, CVE-2026-0849, CVE-2026-0850, CVE-2026-0851
Affected versions
Windows 10 22H2 Build 19045.4046 and earlier, Windows 11 22H2 Build 22621.3235 and earlier, Windows 11 23H2 Build 22631.3235 and earlier, Windows 11 24H2 Build 26100.712 and earlier
Patched versions
Windows 10 22H2 Build 19045.4123, Windows 11 22H2 Build 22621.3312, Windows 11 23H2 Build 22631.3312, Windows 11 24H2 Build 26100.789

Mitigations

  • Install KB5075904 immediately.
  • Restrict Print Spooler service on servers that don't need printing.

Technical references

Response

Vendor statement

Microsoft recommends installing the update during a maintenance window. A restart is required. Post-installation optimization runs automatically over 24-48 hours.

Response status: Patched

Patch available: Yes

Workaround available: No

FAQ

What does KB5075904 fix?

KB5075904 patches 47 security vulnerabilities (8 critical CVEs), fixes Windows Hello face recognition errors (0x80070032), improves File Explorer search on network shares, resolves Wi-Fi 6E connection drops, and improves memory management for systems with 8 GB RAM or less.

Which Windows versions does KB5075904 cover?

Windows 10 22H2 (build 19045), Windows 11 22H2 (build 22621), Windows 11 23H2 (build 22631), and Windows 11 24H2 (build 26100). All editions including Home, Pro, Enterprise, and Education.

Are there known issues with KB5075904?

Known issues include installation failures with error 0x800f0922 on systems with custom themes, 24-48 hours of slower performance on HDDs while indexes rebuild, false positives from legacy antivirus tools, and brief delays in network printer discovery.

Is this a critical security update?

Yes. KB5075904 patches 8 critical CVEs including kernel privilege escalation (CVE-2026-0845, CVE-2026-0846), Print Spooler remote code execution (CVE-2026-0849, CVE-2026-0850), and Windows Hello biometric bypass (CVE-2026-0847).

The bottom line

KB5075904 patches 47 vulnerabilities (8 critical) across Windows 10 and 11, fixes Windows Hello 0x80070032 errors, improves File Explorer network search, and stabilizes Wi-Fi 6E connectivity.

KB5075904 is a critical Patch Tuesday update. Deploy it across all Windows 10 22H2 and Windows 11 systems to close kernel, Print Spooler, and biometric bypass vulnerabilities.

What happens next

Microsoft's next Patch Tuesday update is scheduled for April 8, 2026. Monitor MSRC for any out-of-band patches if active exploitation is detected.

What to do

Install the update via Windows Update or Microsoft Update Catalog and verify with Get-HotFix -Id KB5075904.

Sources

Reader actions
Was this helpful?
Rate this articleRate
3 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.