The September 2026 Windows security update requires a restart for hotpatch‑enabled devices
🚨 The Signal: The September 2026 Windows security update will require a restart for hotpatch-enabled devices due to fundamental component changes. This deviates from the usual hotpatch no-restart model, ensuring critical security improvements are applied.
The Impact
Organisations using Windows hotpatching are affected, facing a temporary disruption to ensure critical OS security updates are fully applied.
- Security Teams: Must plan for a mandatory restart for hotpatch-enabled devices in September 2026.
- IT Operations: Will need to schedule and manage device restarts for hotpatch fleets.
- End Users: May experience brief unavailability of hotpatch-enabled devices during the restart.
- Compliance Teams: Should note this one-off restart for hotpatch systems in their update attestations.
The Action
- Review Windows release health site for Windows 11 and Windows Server hotpatch update calendars.
- Communicate the September 2026 mandatory restart requirement to relevant IT and security teams.
- Plan for the September 2026 update deployment, accounting for the required restart on hotpatch-enabled devices.
- Monitor update history and compliance reports to confirm successful installation post-restart.
Domain: Other · Impact: low · Workload: Other · Essential Eight: Patch Operating Systems · ISM: ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1877, ISM-1889, ISM-1902