Microsoft released mandatory Windows 11 cumulative updates KB5083769 for versions 25H2/24H2 and KB5082052 for 23H2, delivering April Patch Tuesday security fixes alongside reliability and feature improvements. The 25H2 and 24H2 releases share the same changes because both are based on 24H2, and the update moves those branches to builds 26200.8246 and 26100.8246. Microsoft said the packages include protections against phishing through malicious .rdp files, Secure Boot certificate management improvements, and a fix for an issue that had pushed some systems into BitLocker Recovery after Secure Boot updates; the release also bundles servicing stack update KB5088467.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-19, Microsoft said it had already rolled out a server-side fix for the Windows 11 KB5083769 issue that could trigger BitLocker recovery prompts on a limited set of devices with a specific unrecommended Group Policy configuration. The company continued investigating separate reports that the update required multiple reboots or failed to install on some systems.
With the release, Microsoft detailed improvements including stronger protections against malicious .rdp phishing files, Secure Boot certificate management changes, a fix for some BitLocker Recovery boot issues, and reliability fixes across File Explorer, display handling, Remote Desktop, audio, and other components. Microsoft also noted a known issue where devices with an unrecommended BitLocker Group Policy configuration may require a recovery key after installation.
On 2026-04-14, Microsoft released the mandatory April 2026 cumulative updates for Windows 11, including KB5083769 for versions 25H2/24H2 and KB5082052 for version 23H2. The updates included security fixes, bug fixes, feature improvements, and bundled servicing stack update KB5088467 for affected builds.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcereddit.com
Open sourcewindowslatest.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.