Microsoft ships final Windows 10 security rollup KB5122878 to ESU customers
The September 2026 update lands alongside a record Patch Tuesday fixing 966 flaws, and reaches only machines enrolled in Extended Security Updates or running the Enterprise LTSC editions.

Key points
- Microsoft released Windows 10 update KB5122878 on September 2026 Patch Tuesday, delivered only to devices in the paid Extended Security Updates programme or running Enterprise LTSC editions.
- The rollup carries fixes from a record 966-vulnerability Patch Tuesday, including two flaws Microsoft says are already being exploited.
- After installing, Windows 10 machines move to build 19045.7725, and Windows 10 Enterprise LTSC 2021 moves to build 19044.7725.
- The update resolves a known BitLocker Group Policy issue that had forced some devices to prompt for a recovery key.
- Microsoft lists no known issues with the update at time of release.
Microsoft has issued KB5122878, a security-only rollup for Windows 10 that is available only to machines enrolled in the company's paid Extended Security Updates (ESU) programme or running the long-term-servicing editions of the operating system.
Mainstream support for Windows 10 ended earlier this cycle. ESU is the arrangement under which Microsoft continues to sell security patches for a defined period after that cutoff. Enterprise LTSC, short for Long-Term Servicing Channel, is a separate edition sold to organisations that need a stable build for equipment like medical devices or factory machines.
If you are not in one of those two groups, this update is not offered to you.
What is actually in the update?
KB5122878 bundles this month's security fixes plus a small set of bug fixes. Microsoft is no longer adding features to Windows 10, so the release is maintenance, not new function. Eligible machines can install it through Settings, Windows Update, and Check for Updates, as first reported by BleepingComputer.
The rollup carries the same security content as the wider September 2026 Patch Tuesday, which Microsoft describes as its largest single release to date. That release addresses 966 vulnerabilities across the company's products, including two zero-day flaws, meaning software bugs that attackers were already using in the wild before a patch existed.
| Item | Detail |
|---|---|
| Update ID | KB5122878 |
| Windows 10 build after install | 19045.7725 |
| LTSC 2021 build after install | 19044.7725 |
| Total flaws fixed this Patch Tuesday | 966 |
| Actively exploited zero-days | 2 |
| Known issues reported | None |
What bugs does it fix?
Beyond the security content, KB5122878 clears up a handful of specific problems.
One fix targets BitLocker, the built-in disk encryption feature. Some machines with an unrecommended Group Policy setup had been asked to enter their BitLocker recovery key, a long code that unlocks the drive, when they should not have been. The update resolves that behaviour.
Another fix restores audio in Remote Desktop sessions, where sound from a remote machine was not always playing on the local PC. A separate change adjusts Morocco Standard Time to reflect that country's move to permanent UTC+00:00 effective 20 September 2026, so clocks display the correct local time.
The update also expands device targeting for the ongoing Secure Boot certificate rollout, and teaches Windows Code Integrity to treat the new Microsoft Windows Production PCA 2026 RSA2048-SHA256 certificate as equivalent to the older PCA 2011 certificate. In plain terms, that helps applications keep running while Microsoft rotates the cryptographic keys that vouch for signed code.
Should ordinary Windows 10 users do anything?
Only if you are covered by ESU or running Enterprise LTSC. For everyone else still on Windows 10, no patch is coming through Windows Update this month, which is the practical risk of staying on an unsupported operating system.
Home users in that position have two realistic options: move to Windows 11 if the hardware supports it, or enrol in the consumer ESU offer that Microsoft has extended for a limited window. Businesses running Windows 10 outside ESU should assume newly disclosed flaws will remain unpatched on those machines.
Check the version number after install. If it reads 19045.7725, or 19044.7725 on LTSC 2021, the update landed cleanly.



