Microsoft released Windows 11 cumulative update KB5089573 to permanently fix an installation bug introduced by KB5089549 that caused some systems running versions 24H2 and 25H2 to fail during reboot. Affected devices typically stalled at about 35–36% completion, rolled back the update, and returned error 0x800f0922, with logs indicating insufficient free space in the EFI System Partition (ESP). Microsoft had already applied a Known Issue Rollback and provided a registry-based workaround for enterprise administrators before issuing the permanent fix.
The update raises Windows 11 builds to 26100.8524 and 26200.8524, includes servicing stack and AI component updates, and is available through Windows Update, Microsoft Update Catalog, Windows Update for Business, and WSUS. Microsoft said no known issues were identified at release and indicated that the fix will also be included in subsequent cumulative updates, reducing the need for users and administrators to manually resize the ESP or remove security updates.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Before issuing a permanent fix, Microsoft mitigated the problem with a Known Issue Rollback and provided a registry-based workaround for enterprise administrators. The mitigation targeted failures tied to insufficient EFI System Partition free space.
Microsoft said the May 2026 cumulative update KB5089549 introduced an installation issue on some Windows 11 24H2 and 25H2 devices with limited free space in the EFI System Partition. Affected systems stalled around 35–36% during reboot, rolled back changes, and could show error 0x800f0922.
On 2026-05-26, Microsoft released optional cumulative update KB5089573 for Windows 11 24H2 and 25H2 to permanently resolve the installation failure caused by KB5089549. Microsoft said the update was available through Windows Update and related servicing channels and that no known issues were identified at release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcescworld.com
Open sourcewindowslatest.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.