Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fortinet Patches Critical Auth Bypass in FortiWeb, FortiManager, FortiClient
August 13, 2026
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
August 13, 2026
Beacon CRM confirms full database theft after AWS access key breach
August 13, 2026
Home/CyberSecurity News/Windows 11 Update Fails With Error 0x800f0922, Microsoft Confirms
CyberSecurity News

Windows 11 Update Fails With Error 0x800f0922, Microsoft Confirms

Key Takeaways Microsoft has acknowledged a critical installation failure for its Windows 11 May 2026 cumulative update, KB5089549. Affected users are encountering error code 0x800f0922, primarily due...

Marcus Rodriguez
Marcus Rodriguez
May 18, 2026 3 Min Read
72 0

Key Takeaways

  • Microsoft has acknowledged a critical installation failure for its Windows 11 May 2026 cumulative update, KB5089549.
  • Affected users are encountering error code 0x800f0922, primarily due to insufficient space in the EFI System Partition (ESP).
  • This mandatory security update is crucial for applying the latest security fixes and significant Secure Boot infrastructure changes.
  • Microsoft is currently deploying a fix for the issue, with administrators advised to monitor the Windows Release Health Dashboard.

Windows 11 Update KB5089549 Fails with Error 0x800f0922

Microsoft has confirmed a widespread installation failure impacting its May 2026 Patch Tuesday cumulative update for Windows 11, identified as KB5089549. Users attempting to install the update are frequently met with error code 0x800f0922, with some also reporting additional error messages such as 0x80240069 and 0x80240031.

Table Of Content

  • Key Takeaways
  • Windows 11 Update KB5089549 Fails with Error 0x800f0922
  • Mandatory Update for Windows 11 Versions
  • Root Cause Identified: Insufficient ESP Space
  • Other Critical Fixes in This Update
  • What You Should Do

The software giant officially acknowledged this known issue by adding it to the update’s change log on May 15, 2026, merely three days after the patch’s initial release.

Mandatory Update for Windows 11 Versions

Released on May 12, 2026, KB5089549 is a compulsory cumulative update targeting Windows 11 versions 25H2 and 24H2. Its successful installation advances the operating system builds to 26200.8457 and 26100.8457, respectively. The update is comprehensive, bundling the latest May 2026 security fixes, non-security quality improvements from April’s optional preview release (KB5083631), and vital Secure Boot infrastructure modifications.

Given its classification as a required security update, Windows automatically attempts to install it, making the current installation failures particularly disruptive for affected devices and their users.

Root Cause Identified: Insufficient ESP Space

Microsoft has pinpointed the primary cause behind error 0x800f0922: insufficient free space within the EFI System Partition (ESP). The ESP is a critical, typically low-capacity partition on a device’s storage drive, responsible for storing essential boot files.

The KB5089549 update introduces substantial Secure Boot infrastructure enhancements. These include the creation of a new SecureBoot folder under C:Windows on eligible devices, alongside sample automation scripts designed to assist IT administrators in managing certificate updates across large enterprise fleets. These new additions expand the volume of files written to the ESP during the installation process, leading to installation failures on systems where the partition lacks adequate free space.

A significant component of this update is the phased deployment of new Secure Boot certificates. This process incorporates high-confidence device targeting data to broaden the coverage of eligible devices, ensuring new certificates are only deployed after a device demonstrates sufficient successful update signals, thereby maintaining a controlled rollout. Furthermore, the update provides example scripts within the new SecureBoot directory, empowering IT professionals in Active Directory environments to automate Secure Boot certificate deployment through secure, phased mechanisms.

Other Critical Fixes in This Update

Beyond the Secure Boot improvements, KB5089549 delivers resolutions for several other critical issues:

  • BitLocker Recovery Loop Fixed: The update addresses a known problem where devices running April 2026’s KB5083769 could enter a BitLocker Recovery state after boot file updates, particularly affecting systems with invalid PCR7 (Platform Configuration Register 7) TPM validation settings.
  • Boot Manager Reliability: Enhancements to startup reliability ensure devices boot normally after boot file updates, preventing unexpected entry into recovery mode.
  • SSDP Service Stability: Reliability improvements for Simple Service Discovery Protocol (SSDP) notifications mitigate issues where the service could become unresponsive.
  • Daylight Saving Time: The update incorporates support for the 2023 Daylight Saving Time change that impacted the Arab Republic of Egypt.

What You Should Do

  • Monitor Official Channels: System administrators and users should regularly check the Windows Release Health Dashboard for the latest information on remediation status and official guidance from Microsoft.
  • Enterprise Management: Organizations managing enterprise environments can leverage the new Secure Boot automation scripts, available after the update’s installation, to monitor certificate update status and manage phased deployment via Active Directory.
  • Incremental Updates: Users who have previously installed prior cumulative updates may experience reduced ESP space requirements, as only incremental changes are downloaded.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

PatchSecurity

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical MiniPlasma Zero-Day Vulnerability in Windows Lets Attackers Gain SYSTEM Access

Next Post

Critical Avada Builder Flaws Expose 1 Million WordPress Sites

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
CISA Warns of Critical Windows Ancillary Function Driver Zero-Day Exploited in Attacks
August 13, 2026
Likho Stealer’s New Toolkit Steals Telegram Sessions and Records Conversations
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us