Overview
In January 2026 Microsoft released the Patch Tuesday cumulative update KB5074109 for Windows 11 25H2 and 24H2. Shortly after deployment, a wave of boot‑failure reports surfaced. Microsoft has now linked these failures to devices that previously could not install the December 2025 security update and were left in an “improper state” after the rollback.
Timeline of Events
- Early December 2025 – Security update released; a subset of devices fail to install.
- Late December 2025 – Failed installations are rolled back, leaving systems in an unstable “improper state.”
- Early January 2026 – Cumulative update KB5074109 rolled out.
- Mid‑January 2026 – Users report devices that won’t boot after installing KB5074109.
- Late January 2026 – Microsoft issues advisory confirming the correlation.
Impact on Devices
The issue is currently limited to physical hardware; no virtual machines have been reported as affected. Devices that were already in an improper state and then received the January update become unable to boot, requiring manual recovery or a clean reinstall.
Microsoft’s Response
Microsoft states it is working on a “partial resolution” that will block additional devices from entering a no‑boot scenario when an update is applied in the improper state. However, the fix does not:
- Prevent devices from entering the improper state in the first place.
- Repair devices that are already unable to boot.
The company continues to investigate the root cause of the December 2025 update failures and the subsequent rollback behavior.
Mitigation Steps for Affected Users
- Check if the December 2025 security update was successfully installed. If not, avoid installing KB5074109 until a full fix is released.
- If the system is already unbootable, use a Windows 11 installation media to perform a “Startup Repair” or a system restore to a point before the December update attempt.
- For devices that can still boot, run
DISM /Online /Cleanup‑Image /RestoreHealthandsfc /scannowto ensure component store integrity before applying future updates. - Monitor Microsoft’s security advisory page for the upcoming comprehensive fix.
What to Watch For
Future updates from Microsoft are expected to include a full remediation that both prevents the improper state and restores boot capability for affected machines. Administrators should keep an eye on:
- Official patch notes for KB5074109‑R (the planned remedial update).
- Enterprise‑level guidance on deferring the January 2026 cumulative update for vulnerable hardware.
- Community reports on virtual machine behavior, in case the scope expands.