The September 2026 Windows security update requires a restart for hotpatch‑enabled devices

🚨 The Signal: The September 2026 Windows security update will require a restart for hotpatch-enabled devices due to fundamental component changes. This deviates from the usual hotpatch no-restart model, ensuring critical security improvements are applied.

The Impact

Organisations using Windows hotpatching are affected, facing a temporary disruption to ensure critical OS security updates are fully applied.

  • Security Teams: Must plan for a mandatory restart for hotpatch-enabled devices in September 2026.
  • IT Operations: Will need to schedule and manage device restarts for hotpatch fleets.
  • End Users: May experience brief unavailability of hotpatch-enabled devices during the restart.
  • Compliance Teams: Should note this one-off restart for hotpatch systems in their update attestations.

The Action

  1. Review Windows release health site for Windows 11 and Windows Server hotpatch update calendars.
  2. Communicate the September 2026 mandatory restart requirement to relevant IT and security teams.
  3. Plan for the September 2026 update deployment, accounting for the required restart on hotpatch-enabled devices.
  4. Monitor update history and compliance reports to confirm successful installation post-restart.

Domain: Other · Impact: low · Workload: Other · Essential Eight: Patch Operating Systems · ISM: ISM-1407, ISM-1501, ISM-1621, ISM-1622, ISM-1623, ISM-1654, ISM-1655, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1877, ISM-1889, ISM-1902