KB5074109: Windows 11’s First Patch Tuesday of 2026 — NPU Battery Drain Fixed, 114 Vulnerabilities Patched, and One Breaking Change

Microsoft released KB5074109 on January 13, 2026 — the first Patch Tuesday of 2026 and the mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. It moves systems to OS builds 26200.7623 and 26100.7623.

This is the third Patch Tuesday release for version 25H2, but as it is based on version 24H2, there are no exclusive or special changes. You get the same fixes across both versions of Windows 11.

January 2026 Patch Tuesday is not a big release in terms of new features — the changelog is really just about bug fixes. But the security content is substantial: 114 CVEs fixed across Windows, Office, SQL Server, and Azure components, including three zero-day vulnerabilities — one of which was being actively exploited in the wild before Microsoft’s patch was ready.

The most practically impactful fix is a battery drain issue affecting devices with Neural Processing Units — a problem that had been draining laptop batteries faster than expected on Copilot+ PCs and other NPU-equipped hardware.

There is also one breaking change that a small group of users needs to know about before installing: KB5074109 permanently removes legacy modem drivers from Windows.

What Is KB5074109?

KB5074109 is the January 13, 2026 mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. It applies to supported versions of Windows 11, including 24H2 and 25H2, and includes fixes for security vulnerabilities, performance improvements, and reliability enhancements. It also bundles all previously released updates into a single package.

It appears in Windows Update as “2026-01 Security Update (KB5074109) (26200.7623)” and downloads automatically in the background unless updates are paused.

One administrative note worth flagging: starting with the January 2026 security update, Windows Server 2025 has its own KB identifiers and build numbers. This change affects enterprise administrators who previously tracked Windows 11 and Windows Server 2025 updates under shared KB identifiers — from January 2026 onward, they are separated.

114 Vulnerabilities and Three Zero-Days

The January 2026 Patch Tuesday bundle addresses 114 CVEs across Windows, Office, SQL Server, Azure components, and other products, with eight vulnerabilities rated Critical and dozens more marked Important.

Three of those are zero-days. One was actively exploited before the patch was ready — meaning attackers were using it against real targets on unpatched systems. The other two were publicly disclosed before Microsoft’s fix was available.

CVE-2026-20805 — Desktop Window Manager — Actively Exploited

CVE-2026-20805 is an information disclosure vulnerability in the Desktop Window Manager with active exploitation detected.

The Desktop Window Manager — DWM — is the Windows component responsible for compositing the visual display of all running application windows. An information disclosure vulnerability in DWM can allow an attacker to extract sensitive data from memory — content that should be isolated between processes or users.

The active exploitation status makes this the highest priority zero-day in KB5074109. Systems that had not installed KB5074109 before active exploitation was detected were at risk of having sensitive information exposed without the user’s knowledge.

CVE-2026-21265 — Secure Boot Certificate Expiration Bypass

CVE-2026-21265 is a Secure Boot certificate expiration security feature bypass vulnerability.

Secure Boot is the firmware-level security feature that prevents unauthorized or malicious software from loading during the boot process. This vulnerability allowed an attacker to bypass the certificate expiration check that Secure Boot relies on — potentially allowing a device to boot with an untrusted or malicious bootloader that should have been rejected due to expired certificate status.

This zero-day is particularly relevant given the broader Secure Boot certificate renewal work Microsoft has been conducting throughout 2025 and 2026.

CVE-2023-31096 — Windows Agere Soft Modem Driver Elevation of Privilege

CVE-2023-31096 is a Windows Agere Soft Modem Driver elevation of privilege vulnerability.

This is an unusual zero-day — the CVE identifier begins with 2023, meaning this vulnerability was originally discovered and assigned in 2023 but is being patched now. The Agere Soft Modem driver is one of the legacy modem drivers that KB5074109 removes from Windows entirely as part of its compatibility change. Patching the CVE and removing the driver simultaneously closes the vulnerability permanently rather than just patching the vulnerable code.

The NPU Battery Drain Fix — Most Impactful for Users

The first update of 2026 is now rolling out with important fixes — including one that impacts battery life on PCs with an NPU.

KB5074109 resolves an issue where devices with Neural Processing Units could experience unexpected battery drain.

Neural Processing Units are dedicated AI processing chips present in Copilot+ PCs — devices like the Surface Pro 11, various Qualcomm Snapdragon X laptops, and newer AMD and Intel laptops with NPU hardware. These chips are designed to handle AI tasks efficiently while consuming less power than using the CPU or GPU for the same work.

The battery drain issue meant that the NPU was remaining in an active power state longer than intended — consuming power even when no AI workloads were actively running. On laptops, this translated to noticeably shorter battery life that was difficult for users to diagnose because Task Manager and other monitoring tools might not clearly attribute the drain to NPU power state.

For Copilot+ PC users who had noticed their battery life declining unexpectedly since late 2025, KB5074109 is the fix. The NPU now correctly enters low-power states when AI processing is not actively required.

Every Fix in KB5074109

WSL Mirrored Networking — VPN Fix

This update addresses an issue where mirrored networking in Windows Subsystem for Linux could fail causing “No route to host” errors and preventing access to corporate resources over VPN connections, even when the Windows host remained connected. This might occur after installing KB5067036.

Windows Subsystem for Linux’s mirrored networking mode — which mirrors the Windows host’s network interfaces into the WSL environment — was failing in specific VPN configurations. Developers using WSL to access corporate resources over VPN found that WSL would lose connectivity while the Windows host maintained its VPN connection. KB5074109 resolves the networking stack issue that caused this divergence.

Azure Virtual Desktop RemoteApp Fix

This update addresses an issue where you might experience RemoteApp connection failures in Azure Virtual Desktop environments. This might occur after installing KB5070311.

Azure Virtual Desktop users running RemoteApp — the feature that delivers individual Windows applications through AVD rather than a full remote desktop — experienced connection failures after the December 2025 update KB5070311. KB5074109 addresses the underlying incompatibility.

Windows Server 2025 KB Identifier Separation

Starting with the January 2026 security update, Windows Server 2025 will have its own KB identifiers and build numbers.

This is an administrative change rather than a user-facing fix. Previously, Windows 11 24H2/25H2 and Windows Server 2025 shared KB identifiers and build numbers, since they share the same underlying codebase. From January 2026 onward, they diverge into separate KB numbers, making it easier for administrators to track and deploy updates independently for each platform.

The Breaking Change — Legacy Modem Driver Removal

This is the change that affects a small but specific group of users — and unlike bugs, it is intentional and permanent.

This update removes the following modem drivers: agrsm64.sys for x64, agrsm.sys for x86, smserl64.sys for x64, and smserial.sys for x86. Modem hardware dependent on these specific drivers will no longer work in Windows.

The Agere Soft Modem drivers are legacy dial-up and fax modem drivers that date back to the early 2000s. They represent old hardware that is used by an increasingly small number of systems. The removal is connected to CVE-2023-31096 — the Agere Soft Modem driver elevation of privilege vulnerability patched in this update. Rather than patching the vulnerable driver code and leaving the old hardware support in place, Microsoft removed the drivers entirely.

Who is affected:

Users with physical dial-up modems or fax modems that specifically use Agere Soft Modem chipsets and the driver files listed above. This hardware is rare on modern systems but is still found in some older office environments with fax workflows.

What to do if your hardware is affected:

If you use a modem that relies on these drivers, check with the hardware manufacturer for updated drivers before installing KB5074109. If no updated drivers are available and the hardware is essential to your workflow, consider delaying this update until you have a replacement solution.

This removal cannot be undone by uninstalling KB5074109 once it has been applied — the driver removal is permanent after the update installs.

Full Fix Summary Table

FixTypeDetails
CVE-2026-20805 DWMZero-dayInformation disclosure — actively exploited
CVE-2026-21265 Secure BootZero-dayCertificate expiration bypass
CVE-2023-31096 Modem driverZero-dayElevation of privilege — driver removed
NPU battery drainFixedCopilot+ PCs and NPU-equipped laptops
WSL mirrored networkingFixedVPN connectivity failure resolved
AVD RemoteApp failuresFixedConnection issues after KB5070311
Agere modem driversRemovedLegacy drivers permanently removed
Windows Server 2025 KB IDsChangedNow separate from Windows 11 KB numbers

Known Issues After KB5074109

Azure Virtual Desktop Credential Prompt Failures

After installing KB5074109, credential prompt failures occurred during Remote Desktop connections using the Windows App on Windows client devices, impacting Azure Virtual Desktop and Windows 365. The issue affects Windows App on specific Windows builds, causing sign-in failures.

This is an introduced bug — KB5074109 fixed one AVD issue (RemoteApp failures) but introduced a different AVD sign-in problem. Microsoft addressed this in KB5077744 — a later update in the January-February 2026 cycle.

If you installed KB5074109 and are experiencing credential failures in Azure Virtual Desktop or Windows 365 using the Windows App, install KB5077744 or any subsequent update that includes it.

Apps May Fail to Launch

Some applications report launch failures after KB5074109 in specific configurations. This is documented but not fully characterized in Microsoft’s release notes. If you experience application launch failures after this update, check whether the application vendor has released a compatibility update.

How to Install KB5074109

Method 1 — Windows Update (Recommended)

Go to Settings, Windows Update, Check for updates. KB5074109 appears as “2026-01 Security Update (KB5074109) (26200.7623)” on Windows 11 25H2. Click Download and install. Restart when prompted.

For most users, KB5074109 will download and install automatically through Windows Update unless updates are paused.

Method 2 — Microsoft Update Catalog

Go to catalog.update.microsoft.com. Search for KB5074109. Select the package matching your Windows version — 25H2 or 24H2 — and architecture — x64 or ARM64. Download the .MSU file and run it.

If you encounter error 0x80244022 during the download, our complete error fix guide covers every resolution step.

KB5043080 — the September 2024 checkpoint servicing stack update — must be installed before KB5074109. Most systems already have it. If KB5074109 fails with error 0x800F0838, install KB5043080 first.

Verifying KB5074109 Is Installed

Go to Settings, System, About. Under Windows specifications, check the OS build number.

Successful installation shows build 26200.7623 on Windows 11 25H2 or build 26100.7623 on Windows 11 24H2.

Alternatively, press Win + R, type winver, and verify the build number matches. Or check Settings, Windows Update, Update History for KB5074109 with a Successfully installed status dated January 13, 2026.

KB5074109 in the 2026 Update Chain

KB5074109 is the first update in the 2026 Windows 11 update sequence for 25H2 and 24H2.

KB5074109 — January 13, 2026. This article. 114 vulnerabilities, 3 zero-days, NPU battery fix.

KB5079473 — March 10, 2026. Emoji 16, built-in Sysmon, Taskbar speed test, 79 vulnerabilities.

KB5083769 — April 14, 2026. 167 vulnerabilities, Narrator Copilot, Smart App Control toggle.

KB5094126 — June 9, 2026. Shared Audio, Low Latency CPU Profile, 200 vulnerabilities.

KB5101650 — July 14, 2026. 570 vulnerabilities — record. Point-in-Time Restore.

Each update is cumulative — KB5101650 contains all security content from KB5074109 and every update after it. A device that missed the January update and installed the July one directly received all of January’s security patches automatically as part of that cumulative package.

KB2267602 — Microsoft Defender’s daily definition update — continues running independently alongside all of these monthly cumulative updates.

Should You Install KB5074109?

Yes — unless a later update is already installed.

If your system is on any build higher than 26200.7623 or 26100.7623, a subsequent cumulative update has already incorporated KB5074109’s security content. No separate action is needed.

If your system is still on a pre-January 2026 build — which would be unusual for a system with automatic updates enabled — install KB5074109 or, better, check Windows Update for the latest available update, which will include all prior security content cumulatively.

If you use legacy modem hardware:

Check whether your modem uses the Agere Soft Modem drivers listed in the breaking change section before installing. The driver removal is permanent and irreversible.

For Azure Virtual Desktop environments:

Be aware of the credential prompt failure known issue and plan to deploy KB5077744 alongside or shortly after KB5074109.

Frequently Asked Questions

What is KB5074109?

KB5074109 is the January 13, 2026 Patch Tuesday mandatory cumulative security update for Windows 11 versions 25H2 and 24H2. It is the first Patch Tuesday of 2026 and moves systems to OS builds 26200.7623 and 26100.7623. It fixes 114 vulnerabilities including three zero-days and resolves an NPU battery drain issue on Copilot+ PCs.

What zero-days does KB5074109 fix?

KB5074109 patches three zero-days: CVE-2026-20805, an actively exploited information disclosure vulnerability in Desktop Window Manager; CVE-2026-21265, a Secure Boot certificate expiration bypass; and CVE-2023-31096, an elevation of privilege vulnerability in the Agere Soft Modem driver.

What is the NPU battery drain fix in KB5074109?

KB5074109 resolves an issue where Neural Processing Units on Copilot+ PCs and other NPU-equipped laptops remained in an active power state longer than intended, causing unexpected battery drain. After the fix, NPUs correctly enter low-power states when AI processing is not actively running.

What modem drivers does KB5074109 remove?

KB5074109 permanently removes agrsm64.sys, agrsm.sys, smserl64.sys, and smserial.sys — legacy Agere Soft Modem drivers. Hardware dependent on these drivers will no longer function in Windows after installation. Check with your hardware manufacturer for alternatives before installing if you use modem hardware dependent on these drivers.

What OS build does KB5074109 install?

KB5074109 installs OS build 26200.7623 on Windows 11 25H2 and build 26100.7623 on Windows 11 24H2.

How many vulnerabilities does KB5074109 fix?

KB5074109 fixes 114 CVEs across Windows, Office, SQL Server, and Azure components. Eight vulnerabilities are rated Critical and three are zero-days.

What is the Azure Virtual Desktop issue with KB5074109?

After installing KB5074109, some users experienced credential prompt failures during Remote Desktop connections using the Windows App on Windows client devices, affecting Azure Virtual Desktop and Windows 365. Microsoft addressed this in KB5077744.

Does KB5074109 include new features?

KB5074109 does not include new surface-level features — it is primarily a security and bug fix release. New features for Windows 11 in early 2026 were delivered through the optional preview updates and began rolling out with the March 2026 update KB5079473.

Leave a Reply

Your email address will not be published. Required fields are marked *