Microsoft Issues Windows 10 KB5120249 Extended Security Update for 21H2 & 22H2
What Happened — Microsoft released the August 2026 cumulative update KB5120249 for Windows 10 21H2 and 22H2. The update is mandatory and addresses a File History backup failure on SMB shares and expands the rollout of new Secure Boot certificates.
Why It Matters for Compliance & Audit Readiness
- Unpatched OS vulnerabilities constitute a control gap under SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); timely patching is required evidence of an effective change‑control process.
- Secure Boot certificate updates help maintain the integrity of the boot chain, supporting the “Security” principle (CC3.1) and providing audit‑ready proof of platform hardening.
- The File History fix prevents backup failures that could jeopardize data‑availability commitments in SOC 2’s Availability principle.
Who Is Affected — Enterprises across all verticals that still run Windows 10 21H2/22H2, especially regulated sectors (finance, healthcare, government) that must demonstrate continuous patch‑management compliance.
Recommended Actions
- Verify that all Windows 10 21H2/22H2 endpoints have applied KB5120249; capture the update logs as SOC 2 evidence.
- Map the patch‑deployment to your change‑management control (CC7.1) and update your continuous‑compliance dashboard.
- Test File History backup jobs post‑patch to confirm the SMB credential error is resolved.
Source: BleepingComputer
Technical Notes
- Attack surface: Unpatched OS components could be exploited via SMB credential‑validation flaws or Secure Boot bypass techniques.
- Fixes: File History SMB backup logic, Secure Boot certificate provisioning, assorted bug fixes.
- No CVE identifiers were disclosed in the public advisory.