Microsoft Ships KB5094126 June 2026 Security Update for Windows 11 24H2 and 25H2
The cumulative update patches kernel privilege escalation, a WebView2 remote code execution flaw, and authentication bypass issues on domain-joined systems, and requires a restart.

On this page
Key takeaways
- KB5094126 shipped June 9, 2026 for Windows 11 24H2/25H2 and Windows Server 2025.
- It addresses six CVEs: CVE-2026-26001 through CVE-2026-26006.
- Builds move to 26100.8655 (24H2) and 26200.8655 (25H2).
- A restart is required to complete installation.
- Known issues include install failure error 0x800f0982 on low disk space and display flickering on pre-2025 graphics drivers.
What to do now
High urgency- Test KB5094126 in a pilot ring, then deploy to production.
- Ensure 1 GB free disk space and schedule the required restart.
- Update graphics drivers to post-January 2025 versions.
- Verify installation with Get-HotFix -Id KB5094126.
Microsoft released KB5094126 on June 9, 2026, a cumulative security update for Windows 11 Version 24H2 and Version 25H2, as well as Windows Server 2025. According to the update documentation, the package addresses six vulnerabilities tracked as CVE-2026-26001 through CVE-2026-26006 and raises the OS build to 26100.8655 on 24H2 and 26200.8655 on 25H2.
The fixed flaws include kernel elevation-of-privilege vulnerabilities, a Microsoft Edge WebView2 remote code execution issue, Graphics component memory corruption, an authentication bypass affecting domain-joined systems, and a Windows Shell privilege escalation flaw — meaning unpatched systems remain exposed to local and remote attack paths.
Microsoft's KB5094126 update patches six Windows 11 vulnerabilities and updates 24H2/25H2 builds to the 8655 revision.
Deploy KB5094126 to Windows 11 24H2/25H2 and Server 2025 to patch six CVEs; ensure 1 GB free disk space, plan for a reboot, and update graphics drivers to avoid known display issues.
Affected & context
Microsoft released KB5094126 on June 9, 2026, a security update for Windows 11 24H2 and 25H2 and Windows Server 2025 that addresses six vulnerabilities (CVE-2026-26001 through CVE-2026-26006) and updates builds to 26100.8655 and 26200.8655.
The update fixes kernel elevation-of-privilege flaws, a WebView2 remote code execution vulnerability, and authentication bypass issues affecting domain-joined systems, so unpatched machines remain exposed.
Windows 11 24H2 and 25H2 systems (x64 and ARM64) and Windows Server 2025, including Server Core, across Home, Pro, Enterprise, and Education editions.
- Vendors
- Microsoft
- Products
- Windows 11 Version 24H2Windows 11 Version 25H2Windows Server 2025Microsoft Edge WebView2 Runtime
- Geography
- Global
- CVEs
- CVE-2026-26001CVE-2026-26002CVE-2026-26003CVE-2026-26004CVE-2026-26005CVE-2026-26006
What KB5094126 does
Microsoft released KB5094126 on June 9, 2026 as a cumulative security update for Windows 11 Version 24H2 and Version 25H2, along with Windows Server 2025. The update combines security fixes with quality and stability improvements.
After installation, Windows 11 24H2 systems report build 26100.8655 and 25H2 systems report build 26200.8655. Windows Server 2025 (RTM and Server Core) also moves to the 26100.8655 build. A system restart is required to complete the update.
- Windows 11 Version 25H2 — build 26200.8655 (x64, ARM64)
- Windows 11 Version 24H2 — build 26100.8655 (x64, ARM64)
- Windows Server 2025 RTM and Server Core — build 26100.8655 (x64)
- Released June 9, 2026
- Builds: 26100.8655 (24H2), 26200.8655 (25H2)
- Restart required
Vulnerabilities addressed
According to the update documentation, KB5094126 resolves six vulnerabilities across several Windows components.
- CVE-2026-26001 and CVE-2026-26002 — Windows Kernel elevation-of-privilege flaws that could let a local attacker escalate to SYSTEM.
- CVE-2026-26003 — a Microsoft Edge WebView2 runtime remote code execution vulnerability exploitable via malicious web content.
- CVE-2026-26004 — memory corruption in the Windows Graphics component (GDI and DirectX) that could cause crashes or code execution.
- CVE-2026-26005 — a Windows authentication bypass affecting domain-joined systems, involving Kerberos and NTLM handling.
- CVE-2026-26006 — a Windows Shell privilege escalation flaw involving COM object manipulation.
Verify the fix versions independently
The documentation references an updated WebView2 runtime (build 126.0.2592.87) and specific hardening changes. Confirm CVE severity ratings and exploitation status against Microsoft's official Security Update Guide before prioritizing deployment.
- Six CVEs: CVE-2026-26001 to CVE-2026-26006
Deployment and verification
KB5094126 is delivered automatically through Windows Update and typically appears within 24–48 hours of release. For manual or enterprise deployment, the standalone packages are available from the Microsoft Update Catalog and can be distributed via WSUS, Configuration Manager (SCCM), Microsoft Intune, or Group Policy.
To confirm the update is installed, check the OS build in msinfo32, review Windows Update history, or query the hotfix with PowerShell.
Get-HotFix -Id KB5094126- Ensure at least 1 GB of free space on the system drive.
- Plan for a required restart during a maintenance window.
- Update graphics drivers to versions released after January 2025.
- Test critical and legacy applications in a controlled environment first.
Known issues
- Installation may fail with error 0x800f0982 when disk space is insufficient — free space with Disk Cleanup and retry.
- Some third-party antivirus products may temporarily flag system files after installation, typically resolving as vendors update definitions.
- Systems with pre-2025 graphics drivers may experience display flickering — update drivers from Intel, AMD, or NVIDIA.
Domain controllers
The authentication changes may require updates to domain controller configuration in some environments. Coordinate with your network team before broad deployment.
Timeline
KB5094126 released
Microsoft releases KB5094126 for Windows 11 24H2/25H2 and Windows Server 2025, raising builds to 26100.8655 and 26200.8655.
Source: KB5094126 update documentation
Confidence: Medium
Impact
Unpatched Windows 11 24H2/25H2 and Windows Server 2025 systems remain exposed to kernel privilege escalation, a WebView2 remote code execution flaw, and authentication bypass on domain-joined machines.
Business impact
Deployment requires a reboot and testing cycles; delaying leaves endpoints and servers exposed to escalation and RCE risks.
Technical impact
Raises builds to 26100.8655 (24H2) and 26200.8655 (25H2); updates the WebView2 runtime and hardens kernel, graphics, authentication, and shell components.
Security impact
Patches six CVEs including local privilege escalation to SYSTEM and a remote code execution flaw in WebView2.
Affected audience: IT admins, MSPs, Windows 11 users, Windows Server 2025 admins
Action required.
Technical details
- CVEs
- CVE-2026-26001, CVE-2026-26002, CVE-2026-26003, CVE-2026-26004, CVE-2026-26005, CVE-2026-26006
- Affected versions
- Windows 11 24H2 (before build 26100.8655), Windows 11 25H2 (before build 26200.8655), Windows Server 2025 (before build 26100.8655)
- Patched versions
- 26100.8655, 26200.8655
Detection methods
- Query patch state with Get-HotFix -Id KB5094126
- Verify OS build via msinfo32 or Settings > Windows Update > Update history
Mitigations
- Install KB5094126 via Windows Update or the Microsoft Update Catalog and restart.
Workarounds
- For install error 0x800f0982, free disk space with Disk Cleanup and retry.
- For post-install antivirus false positives, allow time for definition updates.
- For display flickering, update to the latest GPU drivers.
Response
Customer guidance
Microsoft's update documentation advises installing KB5094126 through Windows Update or the Microsoft Update Catalog, ensuring at least 1 GB of free disk space, and restarting to complete installation.
Response status: Patched
Patch available: Yes
Workaround available: Yes
FAQ
What does KB5094126 fix?
It addresses six vulnerabilities (CVE-2026-26001 through CVE-2026-26006) across the Windows Kernel, Microsoft Edge WebView2, the Graphics component, Windows authentication, and Windows Shell, plus quality and stability improvements.
Which systems need KB5094126?
Windows 11 Version 24H2 and 25H2 on x64 and ARM64, and Windows Server 2025 including Server Core. It applies across Home, Pro, Enterprise, and Education editions.
What build does KB5094126 install?
Windows 11 24H2 moves to build 26100.8655 and 25H2 moves to build 26200.8655. Windows Server 2025 moves to 26100.8655.
How do I confirm KB5094126 is installed?
Run Get-HotFix -Id KB5094126 in PowerShell, check Settings > Windows Update > Update history, or verify the OS build via msinfo32.
Is a restart required?
Yes. A system restart is required to complete installation, so plan a maintenance window for production systems.
The bottom line
KB5094126, released June 9, 2026, patches six CVEs in Windows 11 24H2/25H2 and Windows Server 2025 and updates builds to the 8655 revision.
This is a security-critical cumulative update; apply it after testing and address the documented graphics-driver and disk-space issues.
What happens next
Windows Update will roll the patch out automatically over 24–48 hours; admins deploying via WSUS, SCCM, or Intune should pilot and validate against known issues first.
What to do
Verify deployment with Get-HotFix -Id KB5094126 and confirm build 26100.8655 or 26200.8655.
Sources
Microsoft · Jun 9, 2026 · Primary source
Claims supported
- KB5094126 released June 9, 2026 for Windows 11 24H2/25H2 and Server 2025
- Builds updated to 26100.8655 and 26200.8655
- Addresses CVE-2026-26001 through CVE-2026-26006
- Known issues including error 0x800f0982 and display flickering