Quick Answer
Windows 11’s July 2026 update, KB5101650, is a mandatory security release that patches a record 570 vulnerabilities and adds real features — Point-in-time restore, much faster Bluetooth, and a quicker File Explorer. Most people should install it. Only a limited set of Dell PCs with a specific Intel driver have been held back by Microsoft.
Key Takeaways
- KB5101650 moves Windows 11 25H2 and 24H2 to builds 26200.8875 and 26100.8875; it is a required update
- It fixes a record 570 vulnerabilities including three zero-days — but only around 57 are rated Critical
- Headline new feature is Point-in-time restore, a full-system rollback, plus a big Bluetooth and File Explorer fix
- Microsoft placed a compatibility block on some Dell PCs over an Intel driver issue; those users should wait
- Larger updates are becoming normal as AI helps researchers find more bugs — bigger is not the same as less secure
What is the Windows 11 July 2026 update?
KB5101650 is the July 2026 Patch Tuesday release, and it is mandatory because it carries the month’s security fixes. It moves Windows 11 version 25H2 to build 26200.8875 and version 24H2 to build 26100.8875 — the same fixes reach both. Windows 11 23H2 gets the equivalent update as KB5099414 (build 22631.7376). You install it from Start > Settings > Windows Update > Check for updates.
What makes this particular update notable is its sheer size. It addresses roughly 570 vulnerabilities, which is a record — about a 316% increase over the 137 fixes in July 2025, and nearly triple last month’s total. That number has generated alarming headlines, so it is worth unpacking what it actually means before deciding whether to worry.
Does “570 vulnerabilities” mean Windows is falling apart?
No, and this is where most coverage overstates things. The “570 fixes” figure is real, but the framing around it is often misleading in two ways.
First, “570 vulnerabilities” is not “570 critical holes.” By independent counts, only around 57 to 59 of them were rated Critical; the large majority were rated Important or lower. The total is also inflated by counting methodology — it includes an unusually large batch of Edge and Chromium fixes and spans many Microsoft products, not just the Windows you run at home.
Second, a big patch count is not a measure of how broken Windows is. It counts how many vulnerabilities were assigned and fixed in one reporting window, not how many exploitable holes sit on your specific PC. A larger update means Microsoft found and closed more issues before attackers could use them, which is the system working as intended. Bigger, in this case, is closer to safer than to scarier.
Why are Windows updates getting so big?
Because AI is changing how vulnerabilities are found, and Microsoft has said so openly. The company uses an AI-assisted analysis system to help its researchers surface flaws faster and across more code than manual review can cover — it credits the system with helping find a batch of serious networking and authentication bugs in this release, including remote-code-execution flaws in core components like the TCP/IP stack, as Windows Central has reported.
The honest version of this story matters, though. It is tempting to say updates are exploding “because criminals are using AI to attack Windows,” and that claim is too strong. AI is accelerating both sides — defensive research and offensive experimentation — but patch volume mostly reflects how much more ground defenders can now cover, not a surge in successful attacks. Microsoft has warned that these larger monthly updates are the new normal, so it is worth getting comfortable with the trend rather than reading every record month as a crisis. The broader shift toward AI-accelerated vulnerability discovery is one we have covered as its own emerging risk.
What new features does KB5101650 add?
Unusually for a security release, this one bundles several genuinely useful features that had been testing in Insider builds:
| Feature | What it does |
| Point-in-time restore | A full-system rollback that lets you return Windows to an earlier working state — a proper recovery safety net |
| Faster Bluetooth | The biggest Bluetooth reliability fix in years, including noticeably better behaviour with AirPods |
| Quicker File Explorer | A more responsive, more reliable File Explorer, addressing a long-standing complaint |
| Accessibility & Widgets | New accessibility tools and quieter, less intrusive Widgets |
| Secure Boot certificates | Continued phased rollout of the 2023 Secure Boot certificates |
Point-in-time restore is the standout. It gives Windows a cleaner way to undo a bad state than the old System Restore, and it pairs naturally with good backup habits — if you have ever needed our guide to recovering deleted files on Windows 11, this is the kind of safety net that reduces those situations. The Bluetooth fix is the one most people will actually feel day to day, especially anyone who has fought with Bluetooth problems on Windows 11.
Is KB5101650 safe to install?
For the large majority of PCs, yes — and because it is a mandatory security update, installing it is the right default. Microsoft has not published any known issue linking this update to widespread problems on standard consumer hardware.
There is one clear exception. Microsoft placed a compatibility block on a limited number of Dell PCs tied to the Intel Innovation Platform Framework driver, over reported thermal, power, and stability concerns. Affected machines simply will not be offered the update until a fix ships, which is Microsoft’s safeguard working correctly — if your Dell has not received it yet, that is likely why, and you should wait rather than force it. Separately, Microsoft confirmed the Secure Boot portion was failing on some PCs and promised a resolution.
The practical advice: let it install through Windows Update rather than manually forcing it, so the compatibility checks can protect you. If the update stalls or errors out, our guide to fixing a stuck Windows 11 update walks through the fixes, and if your PC feels slower afterward, see what to do when Windows 11 is slow after an update.
What about Secure Boot and older PCs?
This update continues Microsoft’s phased rollout of the 2023 Secure Boot certificates, which widens the pool of devices eligible to receive them automatically. The background is that the older 2011 certificates expired in June 2026; most consumer PCs received the new ones months ago, but the rollout is deliberately gradual, so some machines are only getting them now. We explain what this means and how to check your status in our guide to the expiring Secure Boot certificate.
One more note for anyone still on Windows 10: it reached the end of standard support in October 2025, so it no longer receives these monthly security updates unless you are enrolled in Extended Security Updates. With patch volumes climbing, running an unsupported version is a bigger risk than it used to be, and this is a reasonable moment to plan an upgrade or replacement.
Should you install it now or wait?
Install it, unless Windows Update is deliberately holding it back from your machine. The security fixes are the priority — three of the flaws are zero-days, meaning they were known before the patch existed — and the bundled features are a genuine bonus rather than a risk. The only groups who should wait are affected Dell users, whom Microsoft is already protecting automatically, and anyone on a mission-critical machine who prefers to let a release sit for a week and watch for reports first. For everyone else, the math is simple: the risk of skipping a security update now outweighs the small risk of a well-tested one causing trouble.
FAQ
What is KB5101650?
KB5101650 is the mandatory July 2026 Patch Tuesday update for Windows 11 versions 25H2 and 24H2, moving them to builds 26200.8875 and 26100.8875. It patches around 570 security vulnerabilities, including three zero-days, and adds features such as Point-in-time restore, faster Bluetooth, and a more responsive File Explorer. Windows 11 23H2 gets the equivalent update as KB5099414.
Does the July 2026 update really fix 570 critical flaws?
No. It addresses roughly 570 vulnerabilities in total, but only about 57 to 59 were rated Critical by independent researchers; most were rated Important or lower. The large total also reflects counting methodology and a big batch of Edge and Chromium fixes across many Microsoft products, not 570 critical holes in the Windows on your PC.
Is KB5101650 safe to install?
For most PCs, yes, and installing it is recommended because it is a security update. The main exception is a limited set of Dell computers with a specific Intel driver, which Microsoft has blocked from receiving the update until a fix ships. Let the update install through Windows Update so its compatibility checks can protect your device.
What is Point-in-time restore in Windows 11?
Point-in-time restore is a new full-system rollback feature in the July 2026 update that lets you return Windows to an earlier working state. It is a more capable recovery safety net than the older System Restore, useful if an update or change leaves your PC misbehaving. It reached broad rollout with KB5101650 after testing in Insider builds.
Why are Windows security updates getting bigger?
Microsoft says AI is helping researchers find more vulnerabilities across more code, so more fixes are bundled into each monthly release. A larger update means more issues were found and closed before attackers could use them, not that Windows is less secure. Microsoft has said these larger updates are becoming the norm going forward.
