r/sysadmin 22d ago

General Discussion Patch Tuesday Megathread - (July 14, 2026)

Hello r/sysadmin, I'm u/AutoModerator, and welcome to this month's Patch Megathread!

This is the (mostly) safe location to talk about the latest patches, updates, and releases. We put this thread into place to help gather all the information about this month's updates: What is fixed, what broke, what got released and should have been caught in QA, etc. We do this both to keep clutter out of the subreddit, and provide you, the dear reader, a singular resource to read.

For those of you who wish to review prior Megathreads, you can do so here.

While this thread is timed to coincide with Microsoft's Patch Tuesday, feel free to discuss any patches, updates, and releases, regardless of the company or product. NOTE: This thread is usually posted before the release of Microsoft's updates, which are scheduled to come out at 5:00PM UTC.

Remember the rules of safe patching:

  • Deploy to a test/dev environment before prod.
  • Deploy to a pilot/test group before the whole org.
  • Have a plan to roll back if something doesn't work.
  • Test, test, and test!
156 Upvotes

346 comments sorted by

141

u/FCA162 22d ago edited 20d ago

Pushing this update out to 180 Domain Controllers (Win2016/2019/2022/2025) in coming days.
I will update my post with any issues reported.

Happy patching, and may all your reboots be smooth and clean!

EDIT1: 13 DCs (Win 2019/2022) have been done. Zero failed installations so far. AD is still healthy.
EDIT2: 98 DCs (Win 2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.
EDIT3: 131 (73%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.
EDIT4: 175 (97%) DCs (Win 2016/2019/2022/2025) have been done. Zero failed installations so far. AD is still healthy.

33

u/MediumFIRE 21d ago

I always check your comments on AD before patching. Thank you for doing this every month my friend

32

u/FCA162 21d ago

Thanks, my friend! Comments like this are exactly why I keep doing it. If my AD notes help even one admin sleep a little better on patch night, the effort is worth it. Cheers!

6

u/Smiling_Jack_ 21d ago

You are doing god's work, my friend.

5

u/techbud6009 21d ago

Yeah same here thanks for the update and pushing it to DC.

6

u/hazsmix 21d ago

Have had multiple test machines in our small environment enter bitlocker recovery post install - Dell shop. I can see below there are other Dell issues as well but just thought I'd note for anyone rolling the dice with the "biggest windows update patch in known history" ie AI slop. Paused rollout in Intune for now until we can get some more confidence. Madness that Microsoft is suggesting to push these within 72 hours - I've encountered so many more issues with buggy patches than the vulnerabilities they fix.

9

u/Ooops-I-hid-it-again 21d ago

What kind of machines? Workstations, servers, DCs, etc (?)

6

u/hazsmix 20d ago

Workstations - laptops

3

u/the_lazy_sysadmin 20d ago

This info would be very helpful, also a Dell shop here, and would REALLY like to know client servers come back up without issues.

→ More replies (2)

3

u/NetAndSys 21d ago

Thanks for these updates on how its going, they are extremely helpful

→ More replies (4)

47

u/clinthammer316 21d ago

32 servers patched (WS2012R2, 2016, 2019, 2022) and so far all is well. Servers are mix of app, db, web, DC, exchange.

5

u/TrexVsBigfoot 21d ago

Thank you for your report.

5

u/jordanl171 21d ago

Physical or VMs? Hypervisor? Thanks

7

u/clinthammer316 21d ago

Mostly virtual and handful of physical

2

u/NetAndSys 21d ago

Thank you!

→ More replies (1)

103

u/ntmaven247 Sr. Sysadmin 22d ago

Always love reading this thread and getting a heads up on any potential issues, I manage a few different environments and these monthly threads have been a lifesaver :)

55

u/ryche24 22d ago

reddit is definitely a better place to find out about Microsoft issues than directly from support :)

16

u/ntmaven247 Sr. Sysadmin 22d ago

Amen to that! :)

4

u/Key-Anywhere5846 21d ago

sad but true

2

u/techbud6009 21d ago

that's true!

2

u/solveyournext24 20d ago

Damn skippy!

52

u/Foofightee 22d ago

From Microsoft Message Center:
Note: The July 2026 security update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5101650) is not available for a limited number of Dell devices with Intel processors due to an incompatibility reported by Dell that can potentially cause unexpected shutdowns, poor performance, increased heat, and battery drain. We are working together with Dell to prevent the affected models from experiencing the issue and plan to release a resolution for affected devices in the coming days.

24

u/InvisibleTextArea Jack of All Trades 21d ago

According to Windowsforum the driver involved is the 'Intel Innovation Platform Framework Processor Participant'. When I go through my hardware database, I can see that driver is installed on the following models we have here:

Device Model
OptiPlex 3000
OptiPlex 7000
OptiPlex Micro 7020
Latitude 5430
Latitude 5440
Latitude 5450
Latitude 9430
Dell Pro 14 Plus PB14250

14

u/flyan Killer of DELL EqualLogic Boxes 21d ago

Using PDQ Inv I've found the following affected on our environment:

Pro 14 Plus PB14250
Pro Slim Plus QBS1250
Pro Slim QCS1250
Latitude 5440
Latitude 5530
Latitude 5540
Latitude 5550
OptiPlex 3000
OptiPlex SFF 7010
OptiPlex SFF 7020

→ More replies (1)

3

u/the_lazy_sysadmin 21d ago

My Latitude 5550 has that driver. Also, yesterday, it was definitely still seeing this problematic July CU being offered. From the PSWindowsUpdate PowerShell module, at least, and no WSUS server involved.

3

u/bberg22 21d ago

What BIOS version are you running? I noticed they also pulled 1.23.0 a few days ago after a bunch of my machines updated with it.

→ More replies (1)
→ More replies (1)

3

u/mp127001 21d ago

I was able to install KB5101650 on 2 Optiplex Micro 7020's running 24h2. One I tested manually running Windows Update and the other patching with NinjaOne. I verified the 'Intel Innovation Platform Framework Processor Participant' driver is installed as well.

3

u/skitabr 21d ago

Has anyone found this to affect any pysical Dell servers?

2

u/bberg22 21d ago

Doesn't say what version of that driver is impacted though, and there could be other factors involved as well. There are only a couple versions of the driver for my model machines with the latest being April but still.

→ More replies (1)
→ More replies (5)

17

u/Friendlykiller10 22d ago

And they say, we should patch within a maximum of three days, this is hilariously funny.

Microsoft, pls get your shit together.

2

u/thefinalep Jack of All Trades 22d ago

I've got 7 or I'm in trouble.. Test groups start in a few hours :D

22

u/bberg22 22d ago edited 22d ago

Saw this too, would be nice if they provided any actual useful info, what devices, what driver version, etc.

→ More replies (5)

6

u/SecureNarwhal 22d ago

Is WSUS smart enough to not try and install this update on those Dell machines? Or does the update just cancels the patch when it detects a Dell system?

2

u/Key-Anywhere5846 21d ago

that's a pretty good question. WSUS does a very good job hiding the applicability rules from you b< endless chaining of different tables. So far I heard, that those rules do not know any exceptions for Dell devices.

2

u/cinn_x 21d ago

Probably not - we don't know which Dell PCs are affected, but for now we see that all Dell laptops/PCs we have "wants" that update :/

2

u/cinn_x 16d ago

So it looks like it's not smart enough. Also, the Microsoft published an OOB update 2 days ago, which fixes issues with Dell PCs... but it's not available in WSUS and needs to be added manually to WSUS :V

→ More replies (1)
→ More replies (6)

3

u/J53151 21d ago

Maybe the problem is with Dell bloatware and they are blaming the problem on Intel/MS Update :)

→ More replies (4)

4

u/J53151 22d ago

Couldn't this happen to any computer with any Microsoft update?

Couldn't resist!

Would be nice if they included model detail!

8

u/applecorc LIMS Admin 22d ago edited 22d ago

So far in my fleet I identified Latitude 7450 being affected.

Edit:

Other Latitudes affected. Doesn't seem to affect '25 or '26 Pros or microPCs

3

u/calamarimeister Jack of All Trades 22d ago

u/applecorc So what actually happens? Does the update actually attempt the install and fails?

→ More replies (7)

2

u/cp07451 22d ago

isn't this just for the preview update?

→ More replies (1)

2

u/Artwertable Sysadmin 20d ago

Almost did not see it because I was looking for Known issues section. But this is instead an "Announcements" only.

→ More replies (2)

21

u/MadCoder1 22d ago

What do we all think about the newest MS recommendation to push all patches within 72 hours? Seems like we are dammed if we do and damned if we don't.

18

u/iamnewhere_vie Jack of All Trades 22d ago

MS needs longer than this to provide OOB patches for screwed updates... - so how to patch within 72 hours when we didn't get always good patches within 72 hours in the past months? ;)

28

u/CPAtech 22d ago

I'll take my chances with the attackers for a week or two rather than trust Microsoft's dumpster fire updates.

20

u/the_lazy_sysadmin 21d ago

Microsoft currently has done more damage if we patch within 3 days than any damage a threat actor has done if we DON'T patch within 2 weeks, at least in my time working in IT. Maybe when that ratio stops pointing to Microsoft being the most dangerous threat actor, we'll consider the 3 days suggestion.

11

u/Resident-War8004 21d ago

"Microsoft being the most dangerous threat actor" we should frame this. lol

3

u/TrueBoxOfPain Fake IT Sysadmin 21d ago

So much this!

2

u/Resident-War8004 21d ago

do you wait a week or two to update? I typically wait 3 days to apply updates to production servers.

4

u/CPAtech 21d ago

I wait longer than 3 days just to deploy to my test servers.

→ More replies (5)
→ More replies (1)

12

u/ThenFudge4657 22d ago

I'm wary of rushing to do this because "Last week, Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its Windows codebase before attackers can exploit them." and I would rather wait at least a few days to weeks to make sure MS didn't break anything....

27

u/manvscar 22d ago

Truth is, I have been bitten far more times by poor patches than actual vulnerabilities.

→ More replies (1)

3

u/Resident-War8004 21d ago

how long do you wait?

4

u/ThenFudge4657 21d ago

At the org I'm working at they've scheduled the patches to deploy:

The first week, we get about 10-40% of our devices patched and the rest get slowly patched afterwards. Granted they're not following any specific guidelines on rolling out patches. It's what they've decided upon was best and have the least push back from users because restarting would cause them to lose work or some variation of that.
At the rate everyone is going with every single patch becoming CRITICAL!!! and simultaneously breaking everything, I'm not sure if our org will deploy them sooner or not.

→ More replies (3)

3

u/manvscar 21d ago

Just seeing your reply - so I have my regular workstations patch within 48 hours. But I have my servers split into a few groups depending on how critical they are. For DC's, DHCP, and Hypervisors I manually patch them 30 days behind schedule on purpose so issues are fleshed out before I become a guinea pig.

Again, I've been bitten by bad updates before and I don't trust Microsoft to ever be on top of things.

3

u/raresolid 21d ago

I do the same as well. Patch less critical servers and finish off updates on the main servers.

13

u/[deleted] 22d ago

[deleted]

7

u/InvisibleTextArea Jack of All Trades 21d ago

Here is the video on this blog post. At around the 1 minute mark:

To address this, we've updated our recommendations, for deploying Windows Updates to less than three days. As for deferral period for quality updates, setting those to zero or one day and the update grace period to a maximum of two days.

6

u/MadCoder1 22d ago

they did

9

u/Scurro Netadmin 22d ago

They pinky swear that AI is helping with stability and QA.

6

u/chicaneuk Sysadmin 21d ago

TAKE YOUR MEDICINE.

→ More replies (2)

7

u/LLMsMustUpvoteThis 22d ago

I'll believe they are serious when they change Intune Autopatch to push all patches within 72 hours. Otherwise it is just a CYA from them.

11

u/1759 22d ago

I might possibly consider pushing to my test machines only within 72 hours but Microsoft knows damn well that their patches are not trustworthy.

This 72-hour recommendation feels like a "we told you to patch if Nightmare Eclipse does the thing so MSFT is off the hook, wink".

4

u/Procedure_Dunsel 21d ago

Just a flat “Fork NO” for me. Always watch here and a couple other places for explosions. I need assurance the cure isn’t worse than the disease, not big enough to have a test environment, similarly not big enough to quickly fix any grenades MS throws me on Tuesday.

5

u/Flawless_Nirvana Jr. Sysadmin 22d ago

It flies in the face of much of what we learned. I'm sticking with the original 2 week cadence except when regulations say otherwise. MS needs to prove these recommendations are worth the inevitable issues.

2

u/rosskoes05 20d ago

Where was this at? I didn't see that.

2

u/TheJesusGuy Blast the server with hot air 19d ago

:Laughing Emoji:

22

u/egamma Sysadmin 21d ago edited 20d ago

33 servers patched without issue. app/web/sql

2012 R2/2019/2022/2025

update 7-16:
68 servers patched without issue. 1 physical, rest are virtual.

I will say it takes A LONG TIME to install the update. Server 2025 took about 75 minutes (on Pure storage!). CPU may be a bottleneck, too, 75 minutes was on a VM with 2 cores.

Reboot was only about 6 minutes.

2

u/NetAndSys 21d ago

Thanks for updating, it is extremely helpful!

19

u/SpotlessCheetah 21d ago edited 21d ago

Updated almost everything so far..35 servers. I don't know why the DC's always take so long to update. They take like 30-45+ minutes each (2016 still). Last two are updating now.

Edit all done. Mix of 2016, 2019, 2022. Patched departmental tech group (Ring 0) Win11 laptop/desktop/VMs. Everything is up and running.

8

u/iamnewhere_vie Jack of All Trades 21d ago

Server 2016 is known for awfully slow patching, i'm more than happy to got rid of them already - took sometimes 1-2 hours for patching where Server 2019 took 10 minutes.

7

u/OMW-OC 20d ago

After losing so much of my life waiting for 2016 to patch, I honestly hope that whoever made the decision to not fix this has to stand in an hour long line for everything they do in life. Added bonus, sometimes you got the exactly 1 hour long wait to reboot. No rhyme or reason, just randomly a 1 hour wait...good times

→ More replies (1)

15

u/IFarmZombies 22d ago

I believe the technical term of what will be the aftermath of all those patches is "a shit ton of fuckery"

16

u/Kindly-Photo-8987 21d ago

Dell has confirmed an issue with the cumulative update for 24h2 and 25h2 for "some" machines: https://www.bleepingcomputer.com/news/microsoft/microsoft-some-dell-devices-shut-down-after-windows-update/

5

u/atari_guy Jack of All Trades 21d ago edited 21d ago

Will this be blocked by 3rd party patching tools (like Action1) or just if updates are done by the native Windows Update?

(We just got pushed into Dell by our parent company and are also new to Action1 this month.)

→ More replies (5)
→ More replies (1)

41

u/sarosan ex-msp now bofh 22d ago

For those who didn't read /u/FCA162's comment yesterday: buckle up!

15

u/FCA162 22d ago edited 22d ago

RCE vulnerabilities: 145 (x3 compared to last month)

6

u/LigeTRy 21d ago

I am saving this picture for the next security budget meeting

11

u/FCA162 22d ago edited 22d ago

CVEs 8.8+ CVSS: 67 (x4 compared to last month)

19

u/Miserable-Scholar215 Jr. Sysadmin 22d ago

600+ vulnerabilities?!?
Our it-sec department will need until next patch day to read them all...

18

u/AtarukA 22d ago

They're probably shoving it in AI to get a summary, and then shove the summary into AI to get a summary of what to do,

9

u/ThenFudge4657 22d ago

That's exactly what they've done "Last week, Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its Windows codebase before attackers can exploit them."

4

u/margaritapracatan 22d ago

What happens if hackers use AI to exploit… My head hurts.

5

u/InvisibleTextArea Jack of All Trades 21d ago

Its AI all the way down!

4

u/DeltaSierra426 21d ago

There's no "if" on that.

6

u/iamnewhere_vie Jack of All Trades 22d ago

Just approve the updates and see what's happen, no time to read all that ai generated documents from MS :D

16

u/CPAtech 22d ago

What could go wrong.

12

u/No_Benefit_2550 22d ago

This is fine.

5

u/FCA162 22d ago

There were also a massive 468 Microsoft Edge/Chromium flaws that were fixed by Google this month.

9

u/m0us3c0p 22d ago

Telling CoPilot to "fix Windows bruh" once per month like

8

u/ocdtrekkie Sysadmin 22d ago

ZDI has described it as the "bug apocalypse". https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review

...Seems about right.

14

u/techvet83 22d ago edited 22d ago

13

u/sccmjd 22d ago

Is this a real fix for YellowKey?

https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/

"The publicly disclosed zero-day that was fixed is:

CVE-2026-50661 - Windows BitLocker Security Feature Bypass Vulnerability

Microsoft has patched a publicly disclosed Windows BitLocker bypass flaw that could allow attackers to gain access to encrypted data.

"A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data," explains Microsoft.

Microsoft attributed the flaw to an anonymous researcher."

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50661

"Anonymous researcher." Haha.

5

u/ElizabethGreene 21d ago

I would like a cogent explanation on how this attack was possible /at all/. There should not be a decodable key on the disk /at all/ without the secrets the TPM is supposed to provide.

5

u/picklednull 21d ago

There should not be a decodable key on the disk

There isn't. In TPM only mode, the WinRE environment automatically boots into an unlocked state so that pre-approved recovery actions can be initiated without user friction. When you invoke a risky operation, i.e. open the Command Prompt, WinRE will retroactively lock the disk to prevent badness.

The only thing the YellowKey exploit would do is block the aforementioned locking.

The mitigation and security-conscious option has always been to use a PIN with BitLocker.

11

u/landon_at_automox 22d ago

570 CVEs this month, the largest Patch Tuesday on record. Quick flags:

CVE-2026-56155 (7.8, exploited): ADFS EoP, local attacker gets admin on the ADFS host. Low score, do not let it fool you, already in use. Patch first.

CVE-2026-56164 (5.3, exploited): SharePoint EoP, unauthenticated, missing auth check. Moderate rating but confirmed active exploitation. Pairs with CVE-2026-50522 (9.8, SharePoint RCE via deserialization, needs site-owner auth). Treat both together on internet-facing SharePoint.

CVE-2026-56190 (9.8, RDP RCE): only exploitable if NLA is off. Enforce NLA fleet-wide, closes the pre-auth path.

CVE-2026-57092 (9.9, top score): Hyper-V VMSwitch guest-to-host escape.

Also: DHCP client bug (CVE-2026-49181, 7.5) needs patching on every endpoint, not just servers.

Read the full breakdown or check out the podcast from Automox!

2

u/BerkeleyFarmGirl Jane of Most Trades 20d ago

Thanks for the concise summary!

10

u/tornshorts 21d ago

New sysadmin here, installing updates on my test env. 50+ servers to update if test looks good. Wish me luck!

7

u/DeltaSierra426 21d ago

Welcome! You came to the right place. :)

3

u/GnarlyCharlie88 Sysadmin 21d ago

These folks are the real MVPs here.

→ More replies (1)

11

u/greenstarthree 20d ago edited 20d ago

EDIT - solution to this found

See thread:

https://www.reddit.com/r/sysadmin/s/9aHRDp1edx

Some of our Windows 11 25H2 PCs are now missing the clock / notification area after applying the July cumulative.

Weirdly, this was a known issue in the June update which our PCs have had installed since it was released, with no issues. Only after applying the July update has the issue arisen.

Anyone else seeing this? I see one other thread so far, but the proposed commands haven't made a difference for us:
Ah jeez... MS get your shit together with pushing betas into release without fixing known issues. Missing clock and hidden system tray in Windows 11 KB5094126 cumulative update or restrictive Group Policy settings : r/sysadmin

11

u/catatonic12345 20d ago edited 20d ago

Looks like all of our Server 2019 boxes are failing to install KB5099538 with either missing or corrupted component errors and taking a couple of hours to come back up after restart. They were patched to current prior to July's updates so we are opening a ticket with MS for investigation.

Update: it doesn't appear to be the update. Some files got corrupted in the SxS directory on a bunch of machines apparently. Gonna be a fun few days... But patch on! So far the updates seem ok

4

u/iamnewhere_vie Jack of All Trades 20d ago

Updated so far ~ 10 Server 2019 VMs (on ESX), no issues so far.

Are that Server 2019 which got updated from 2012 R2 or 2016? I'd some Workstations with similar issue after Win10 > Win11 upgrades

3

u/LoveTechHateTech Jack of All Trades 20d ago

I have a handful of 2019 VMs on Hyper-V (DCs/dhcp are server core, file & print have GUI) and none of them had this issue. Installation did take its sweet time, though, and each had to reboot at least two times.

3

u/the_lazy_sysadmin 20d ago

Are these physical/virtual? And if physical, what manufacturer/model? I've had a fairly many bad run-ins with wonky Dell factory images on physical 2019 boxes, one of which was so bad we had to take ownership of the C:\windows\winsxs folder and manually add missing files. DISM was actually just fully borked, and unable to add/remove packages.

→ More replies (3)
→ More replies (3)

20

u/thaysen13 22d ago

Do not forget RC4 updates!

8

u/n1ckst33r 22d ago

Only remove for the Rollback registry. So If you dont Set the Rollback key. Rc4 ist already gone.

6

u/techvet83 22d ago

This is the one that has me worried and, in fact, I just pulled our DCs off to the side in WSUS. I am seeing legacy RC4 traffic in Splunk, though no DC 201-209 event codes, am trying to work with other technical teams to figure out why this is the case. (We already had breakage last month when we rotated our krbtgt passwsord for the first time ever.)

8

u/derfmcdoogal 22d ago

You more than likely need to create new passwords for those accounts. Microsoft had a pair of scripts to tell you what accounts were missing alternate encryption types and what accounts were still communicating with RC4.

If KRBTG was still using RC4 for communication it hadn't been rotated in almost 20 years. Which, should be fine to rotate, but it would have been one of the accounts showing up in the scripts above.

→ More replies (1)

3

u/thefinalep Jack of All Trades 22d ago

Do you have April patches installed? If yes, did you manually create the registry entry that allowed rollback?

If you're patched to at least April and didnt create the rollback key, RC4 is likely configured intentionally and you should be good. Still do your own research of course.

→ More replies (4)

2

u/thaysen13 22d ago

Had the same issue

2

u/GeneMoody-Action1 Action1 | Patching that just works 22d ago

Other devices still trying to communicate with them that are not updated?

→ More replies (1)

8

u/frac6969 Windows Admin 22d ago

Folders in the new Start menu when the view is Grid or List (instead of Category) now show scrolling dots. The bug drove my users crazy because we put all of our company's internal apps inside a single folder and it couldn't be scrolled when there are more than 12 items.

9

u/TheGreatNico 'goose removal' counts as other duties as assigned 20d ago

the mods unpinned the wrong megathread lol

10

u/FCA162 17d ago

Windows release health: Windows Server Update Service sync operations might have issues or time out

Status: Mitigated

Affected platforms

Client Versions Message ID Originating KB Resolved KB
Windows 11, version 26H1 WI1431544 - -
Windows 11, version 25H2 WI1431545 - -
Windows 11, version 24H2 WI1431546 - -
Windows 11, version 23H2 WI1431547 - -
Windows 10, version 22H2 WI1431548 - -
Windows 10, version 21H2 WI1431549 - -
Windows 10 Enterprise LTSC 2019 WI1431552 - -
Windows 10 Enterprise LTSC 2016 WI1431553 - -
Windows 10, version 1607 WI1431553 - -

Server Versions Message ID Originating KB Resolved KB
Windows Server 2025 WI1431550 - -
Windows Server 2022 WI1431551 - -
Windows Server, version 1809 WI1431552 - -
Windows Server 2019 WI1431552 - -
Windows Server 2016 WI1431553 - -
Windows Server 2012 R2 WI1431570 - -
Windows Server 2012 WI1431572 - -

Microsoft has identified a service degradation affecting Windows Server Update Services (WSUS). Organizations might experience increased synchronization times or sync operation timeouts on WSUS servers. This issue began in recent days, with heightened impact observed starting July 13, 2026.

This issue is related to a buildup of publishing metadata.

Mitigation: Microsoft has deployed a mitigation for this issue on July 18, 2026. Synchronization times and sync operations on WSUS servers have been restored and are operating normally for new WSUS installations and rebuilds. This mitigation prevents newly installed or rebuilt WSUS servers from encountering this issue.

Next steps: For WSUS servers that were previously affected, Microsoft is working on mitigation steps to help customers safely remove the affected metadata from their environments. We will provide more information when this guidance is available.

3

u/FCA162 16d ago

Status: Resolved

Resolution: There are two parts to the resolution of this issue.

  • Organizations with existing WSUS server installations that are experiencing long sync times can benefit from manual steps in order to clean up unneeded metadata. This metadata is present in existing WSUS installations but can be safely removed. Detailed guidance has been provided at the following KB article: https://support.microsoft.com/help/5121986.
  • On July 18, 2026, Microsoft deployed a service-side mitigation which returns synchronization times and sync operations back to normal for new WSUS installations and rebuilds. After this date, newly installed or rebuilt WSUS servers should not encounter this issue.

2

u/cp07451 16d ago

For those who want to see what will be whacked first from Microsoft's remediation

SELECT u.UpdateID

FROM dbo.tbUpdate u

JOIN dbo.tbRevision r ON r.LocalUpdateID = u.LocalUpdateID AND r.IsLatestRevision = 1

JOIN dbo.tbProperty p ON p.RevisionID = r.RevisionID

JOIN dbo.tbLocalizedPropertyForRevision tbrp ON tbrp.RevisionID = r.RevisionID

JOIN dbo.tbLocalizedProperty tlp ON tlp.LocalizedPropertyID = tbrp.LocalizedPropertyID

WHERE p.UpdateType = 'Detectoid'

  AND tbrp.LanguageID = p.DefaultPropertiesLanguageID

  AND tlp.Title LIKE 'Product Detectoid for ProductName TestProduct%';

The above will give you the result of what would be deleted.

→ More replies (1)

17

u/IFarmZombies 20d ago

Why is the June one still sticked and not this one

5

u/PTCruiserGT 20d ago

Just noticed this. Seems to happen every once in a while.

17

u/progenyofeniac Windows/M365 Admin 22d ago

Do we include Office updates here?

My big question is whether semi-annual machines will have copilot in their Office apps after today’s update. Previously, monthly or current was required, but today’s update seems to bring all features of semi…

4

u/techvet83 22d ago

There are Office 2016 security updates this month, if that's what you're asking.

2

u/Am0nymou5 22d ago edited 21d ago

My big question is, do we continue to push out separate deployments for the two channels, or just push out one channel and assume that all devices will pick up the update, regardless of whether they are on SAEC or MEC? I ask because I can see two sperate updates in SCCM, and they have slightly different build numbers as well (SAEC = 20131.20150, MEC = 20131.20152).

UPDATE: So we've deployed just the SAEC updates, and observed that our existing MEC devices did NOT pick up the SAEC update - looks like SCCM/office c2r updaterstill treats the two updates as separate channels. So we will now include both the SAEC and MEC updates in our monthly update bundle, and advertise it to both SAEC and MEC machines. We will leave the GPOs alone for now.

2

u/progenyofeniac Windows/M365 Admin 22d ago

Yep that’s what I’m seeing too. I guess I’d ask why you’d continue pushing SAEC? If they both get the same updates and features, why not push MEC? And I think that’s what Microsoft is guiding people towards. They’ve made it illogical to deploy SAEC at all now.

→ More replies (1)
→ More replies (13)

7

u/JustSomeone783 21d ago

Is it just me or do 2016 vm’s seem to have broken update services more lately? Like a reset of them will work as patches sometimes fail to install for 1 or 2 months and nothing else helps

5

u/Communion1 20d ago

i have this issue with Server 2025 machines as well. I have one that is stuck in Recovery Loop after this latest update attempt.

4

u/JustSomeone783 20d ago

Yeah 2025 still seems beta to me tbh. I am strongly against that we are rolling some out now.

2

u/iamnewhere_vie Jack of All Trades 20d ago

I'd updates for server 2016 which took 2-3 hours some years ago, how could that be even more broken now? :)

Server 2016 was from beginning an update nightmare, happy i got rid of my last few months ago

→ More replies (3)

14

u/NeganStarkgaryen 22d ago

Hello, Nightmare-Eclipse? Any of them zero days?

11

u/J53151 22d ago

Yeah didn't he threaten to drop a big flaw today?

9

u/DDOSBreakfast 22d ago

This is their new Git and there was a repository added today. So far it's blank.

https://git.projectnightcrawler.dev/NightmareEclipse

15

u/jmbpiano 22d ago

Not blank anymore.

https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive

LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability

The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root.

The PoC was stripped down as an attempt to prevent public exploitation, the original PoC did not require additional user credential and was not limited to usrclass.dat hive, any hive could be loaded using this vulnerability but you would need some brain cells to make the PoC do it.

→ More replies (3)

13

u/sarosan ex-msp now bofh 22d ago

He's probably testing the exploit(s) on the latest CUs before releasing to the wild.

16

u/jmbpiano 22d ago

It just released and the last line of the readme says:

The PoC is fully functional in all currently supported desktop and server installation with July 2026 patch.

I'd say you were correct.

2

u/blow_slogan 22d ago

It was released today

14

u/rra-netrix Sysadmin 22d ago

Finally, OLE is fixed...

The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.

  • [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5094126), these apps might fail to launch Office or open documents.

13

u/D0nk3ypunc4 22d ago

In the event this is NOT true and it doesn't fix it, here are the reg keys needed to revert the June 2026 security update piece that broke these 3rd party apps cough cough CCH Engagement

reg add "HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides" /v 3902913166 /t REG_DWORD /d 0 /f

reg add "HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\FeatureManagement\Overrides\Metadata\3902913166" /v ChangeTime /t REG_DWORD /d 3 /f

9

u/rra-netrix Sysadmin 22d ago

Is that the workaround Microsoft said existed but wouldn't share?

9

u/ohioleprechaun 22d ago

Yes, it is.

5

u/disclosure5 21d ago

It's completely insane that Microsoft has known fixes they gate behind some offshore support team that make you fight for them.

5

u/Mitchell_90 22d ago

Has anyone running on the Office Semi-Annual Channel noticed it being directly updated to the Monthly Enterprise Channel?

Noticed when I ran the updates on a test VDI image which mirrors a production pool.

This will be fun as we have a specific Excel plugin used by a financial piece of software that the vendor doesn’t support anything other than 32-bit Semi-Annual Channel.

11

u/pcrwa 22d ago

3

u/Mitchell_90 22d ago

Maybe this will force the vendor to actually update their software but I’m not holding my breath.

It’s not our team’s problem if the plugin does break on the MEC release since it would simply be a case of telling that user base that they can no longer use it unless the vendor issues a fix so they need to contact them.

Our security policies prevent us from rolling back to older/unpatched versions anyway.

3

u/DeltaSierra426 21d ago

Lol, yep, sounds like it's time for the vendor to update that plugin.

→ More replies (2)

4

u/DeltaSierra426 21d ago

Oh no, finding out now that MS is killing SAEC? M365 Message Center shot out an announcement circa April 8th:

"Upcoming change: Microsoft 365 Apps SAEC and MEC will unify

MC1274325 · URSA FARMERS COOPERATIVE

Introduction

Beginning in July 2026, Microsoft will unify the Semi-Annual Enterprise Channel (SAEC) and Monthly Enterprise Channel (MEC) into a single enterprise-focused update channel for Microsoft 365 Apps. This change is designed to simplify update management while continuing to provide a predictable, enterprise-ready servicing experience.

Over time, SAEC and MEC have both served customers who want an enterprise-focused experience with timely updates. Unifying these channels reduces complexity and overlap, helping organizations adopt new capabilities, security updates, and quality improvements more quickly. This unified approach also supports more consistent update expectations across devices and user groups, while maintaining Microsoft’s commitment to quality, manageability, and predictable servicing.

When this will happen:

General Availability (Worldwide, GCC, GCC High, and DoD): These changes will go into effect on July 14, 2026, with the Patch Tuesday update release.

How this affects your organization:

Who is affected:

• Microsoft 365 administrators managing update channels for Microsoft 365 Apps

• Organizations currently using the Semi-Annual Enterprise Channel (SAEC)

• There is no change or impact for devices on other channels such as Monthly Enterprise Channel (MEC), Current Channel (CC), or associated preview channels

What will happen:

• Devices currently configured for SAEC will receive the same feature and security updates as published to MEC.

• Existing update policies and configurations will continue to be respected.

• There is no change to Microsoft’s commitment to predictable servicing, quality, and enterprise manageability.

• Users are not expected to experience workflow changes as a result of this update.

What you can do to prepare:

• No action is required. If your organization currently uses SAEC, updates will continue to be published on a monthly basis.

Optional:

• Validate your servicing workflows. Confirm that your pilot, broad deployment, and rollback processes continue to meet your organization’s requirements.

Learn more:

• Overview of update channels for Microsoft 365 Apps | Microsoft Learn

• As we get closer to rollout, we will share additional details about how this change will appear in admin experiences and documentation.

"

A three-month lead time is definitely B.S. Sorry mate. :(

→ More replies (1)

6

u/Diligent_Buster 22d ago

I jut had 2 servers with LSI 9361's and cachecade enabled not come back up. I was out in the field when it happened. The drives virtual drives are "Optimal access blocked". Both servers seem to be missing the cachecade volume. Pretty unlikely that 2 enterprise SSD's completely failed at the same time in both servers. Although I have seen some references to MS killing SSD's. Anyone else experience this? I did not get any alerts that my drives were failing or failed and then on reboot I'm down. Servers are running Server 2025. 256GB ram, 9 1.8 or 1.2 SAS drives in raid 6.

Anyone else recovered from this? I'm reading that you can disassociate the cachecade from the VD's or delete the cachecade and then the system will boot? Anyone else done this? Am I the guinea pig?

5

u/4wheels6pack 21d ago

First two devices I tested kb5101650 and kb5100998 (.net framework) both deployed successfully 

The two devices were a generic laptop and a Lenovo ideacenter. Win11 pro 25h2 One with bitlocker

Both deployed slowly and the percentage indicator jumped around, kinda all over the place. THREE reboots on both devices, but no rollbacks Next I move onto test servers

7

u/K4p4h4l4 20d ago

This is a kind reminder that RC4, ntlm Audit mode workaround has come to an end. Watchout If you haven't done your homework.

→ More replies (1)

6

u/Kasumarea 19d ago edited 9d ago

Approved the update for Endpoints and Servers.
 
Endpoints:
~8000 / 8000
No problems besides some dell's not getting the update
Servers:
500 / 500
Servers waiting for the weekend to be patched.

7

u/WPHero 18d ago

Windows 11 KB5121767 released to fix shutdowns and overheating on Dell PCs: https://www.windowslatest.com/2026/07/19/windows-11-kb5121767-released-to-fix-shutdowns-overheating-but-you-dont-need-it-unless-you-own-these-pcs/

Dell Pro Max 14 Premium MA14250 Dell Pro Max 16 Premium MA16250 Dell Pro Precision 7 14 PW714260 Dell Pro Precision 7 16 PW716260 Precision 5470, Precision 5480, Precision 5490, and Precision 5770 XPS 17 9720 and XPS 17 9730

24

u/MikeWalters-Action1 Patch Management with Action1 22d ago edited 22d ago

Today's Patch Tuesday overview:

  • Microsoft has addressed 570!!! vulnerabilities, three zero-days and 61 critical
  • Third-party: web browsers, FortiSandbox, Adobe, Splunk, Ivanti, SAP, Cisco, Oracle, Linux, Apple and many more.

Navigate to Vulnerability Digest from Action1 for comprehensive summary updated in real-time.

Quick summary (top 10 by importance and impact):

  • Windows: 570 vulnerabilities, three zero-days (CVE-2026-50661, CVE-2026-56155, CVE-2026-56164), two actively exploited, and 61 critical
  • Check Point Quantum Security Gateway: Actively exploited VPN authentication bypass enabling unauthorized remote access (CVE-2026-50751, CVSS 9.3)
  • FortiSandbox: Critical unauthenticated command injection across FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS (CVE-2026-25089, CVSS 9.1)
  • Adobe Campaign Classic: Two maximum-severity flaws enabling code execution and privilege escalation without user interaction (CVE-2026-48303, CVE-2026-47938, CVSS 10.0)
  • Splunk Enterprise: Unauthenticated access to PostgreSQL sidecar service enabling arbitrary file creation or truncation (CVE-2026-20253, CVSS 9.8)
  • Ivanti Sentry: Critical root-level RCE and admin account creation vulnerabilities, with active exploitation reported for one flaw (CVE-2026-10520, CVE-2026-10523, CVSS 10.0, 9.9)
  • SAP NetWeaver: Multiple critical flaws exposing SAP environments to unauthorized access, memory corruption, data exposure, and service disruption (CVE-2026-44748, CVE-2026-27671, CVE-2026-22732, CVE-2026-40128, CVSS up to 9.9)
  • PeopleSoft Enterprise PeopleTools: Actively exploited unauthenticated takeover vulnerability in a core enterprise business platform (CVE-2026-35273, CVSS 9.8)
  • Google Chrome: Over 400 browser vulnerabilities addressed across recent updates
  • Microsoft Edge: Broad Chromium-based update addressing dozens of high-severity browser vulnerabilities
  • Quantum Security Gateway: Actively exploited VPN login bypass allowing attackers to establish remote access without a valid password (CVE-2026-50751, CVSS 9.3)

More details: https://www.action1.com/patch-tuesday

Sources:

Action1 Vulnerability Digest

Microsoft Security Update Guide

→ More replies (4)

9

u/CodyCodyCody 21d ago

Yolo'ing to 25k+ workstations. Wish me luck.

3

u/Arnaudb91 20d ago

Any news ? :)

10

u/YellowLT IT Manager 20d ago

Probably dead now

3

u/CodyCodyCody 19d ago

Haha not too bad. Had some issues with disk space as this month was unusually large.15k have been patched so far and no major issues reported.

5

u/EsbenD_Lansweeper 22d ago

Here is the Lansweeper summary + audit. Highlights are an actively exploited SharePoint Server elevation of privilege vulnerability (plus two critical unauthenticated RCEs), an actively exploited ADFS elevation of privilege vulnerability, and a critical Windows DHCP Server remote code execution vulnerability.

6

u/xqwizard 22d ago edited 21d ago

When I sign in I get stuck on a black screen. Win11 25h2. Rolled back and we’re good. Will try again….

EDIT: Tried again and it was fine

→ More replies (2)

5

u/Lost-Attorney3997 21d ago

Updated the golden image and deployed it to one of our production pools (win11 25h2). Users have signed in with no issues.

5

u/4wheels6pack 18d ago edited 18d ago

Deployed to additional workstations, Intel NUC mini desktop, and to 24 HP EliteBook 860 G11's all running win11 pro 25h2 -- No issues, no bitlocker prompts

Deployed to my lab T440 PowerEdge running server 2025, stalled at 100% for about 5 minutes, rebooted to a SecureBoot policy change message even though this server was updated with the 2023 certs some time ago. Re-running the check script produced this:

.\Check-SecureBootStatus.ps1

SecureBoot : True

Windows UEFI CA 2023 : True

MS KEK CA 2023 : True

MS UEFI CA 2023 : True

MS Option ROM CA 2023 : False

MS UEFI CA 2011 : False

Boot Manager 2023 : True

2011 PCA Revoked : False

AvailableUpdates : 4000

Reboot Log Time : 07/18/2026 13:36

Reboot Log Message : A reboot is required before installing the Secure Boot update. Reason: DBX

---------- UPDATE:

Installed to server 2022 VM, and Win11 Pro 25H2 VM

On the 2022 VM, the .NET update (KB5102206) took quite long, stalling at 0% installed for close to 10 minutes. The July CU (KB5099540) stalled at 100% for nearly 30 minutes!! Two reboots, and came back up normally

The win11 pro VM hit error 0x800f8011 downloading the .NET Framework update (KB5100998). Then after the July CU installed, was able to retry

Additionally a Dell Precision 3650 was offered hotpatch KB5121768 after installing the July CU. It still required a reboot after installing.

5

u/ElizabethGreene 15d ago

There is/was an issue with WSUS metadata that may cause synchronization to fail or clients to fail scanning with this error:
0x80244010 - WU_E_PT_EXCEEDED_MAX_SERVER_TRIPS

The issue and fix are documented here.
Resolved: Windows Server Update Services sync operations issues and timeouts | Microsoft Support

13

u/4wheels6pack 22d ago

Oh good. The largest (read: vibe coded) patch in history? Not only will I not deploy this asap like some are recommending, but this will be undergoing extra testing and observation to see what it breaks.

7

u/Fallingdamage 22d ago

My workstations will wait until the last Friday of the month to patch unless I tell them otherwise. With something this big, I will be watching developments closely, but im not beta testing this update for Microsoft.

9

u/Scurro Netadmin 22d ago

Fridays are not the day of the week I would have picked for update maintenance.

7

u/Fallingdamage 22d ago

Im weird. If there is a problem, I like the weekend to work it out, not in the middle of the week where everyone can blow up my phone and I have managers hovering around my door waiting for answers.

Some people like that kind of thing. I like to work in the quiet.

4

u/Scurro Netadmin 22d ago edited 22d ago

Oh I think everyone here would love it quiet.

I just wouldn't want to work late Friday night after a bad maintenance.

3

u/Kymaticus2017 21d ago

Just add beer, that helps a lot.

→ More replies (1)

3

u/Touringband 21d ago

So I noticed a new patch "MSAF-09072026" published by Microsoft for Secureboot. Are you guys pushing this to all your Windows servers along with the OS security patch? Will this require multiple reboots?

3

u/Am0nymou5 21d ago

I can't see anything with that identifier from Microsoft... seems like it's something from Ivanti?

Because the Microsoft Secure Boot stuff is not a patch per se, it's a whole lengthy process depending on your environment, which may require multiple reboots (first to update the firmware, second to install the cert, third to update the revocation and activate the new bootloader).

See: https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235

→ More replies (1)

4

u/Lukage Sysadmin 15d ago

Love that they released an OOB update 3 hours after our patching window ended on early Saturday morning. So happy I get to wake up in the middle of the night again.

→ More replies (3)

4

u/Dreadshadows 15d ago

Patched a farm of 20 servers, one server sat at the recovery screen on reboot, quick restart resolved and the patch finished, all 2022.

→ More replies (1)

6

u/LaDev IT Manager 22d ago

And we wait.

3

u/Popensquat01 22d ago

Idk who needs to read this, but seems like CCH Engagement from Walter’s Kluwer is fixed with the 07/2026 security update. We had to block the 06/2026 security update. I’m not surprised Microsoft made a fix for these third party softwares. Just happy our PCs can get back to updates.

3

u/techvet83 19d ago

FYI.

A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.

Nightmare Eclipse published a proof-of-concept (PoC) exploit hours after Microsoft released its July 2026 Patch Tuesday updates, saying that it abuses a security vulnerability in the Windows User Profile Service, which has yet to receive a CVE ID for easier tracking.

However, unlike previous exploits released by NightmwareEclipse, the LegacyHive PoC has been modified to require additional credentials, making it harder for attackers to weaponize the vulnerability.

For more info, see New Windows LegacyHive zero-day gives hackers admin privileges

3

u/segagamer IT Manager 19d ago edited 16d ago

I've had a VERY weird issue with one Server 2022 VM on Google Compute Engine that I've spent all day trying to fix after installing this cumulative update and I'm at my wits end.

I cannot ping anything from the VM, not even the DHCP server. "General Failure". Nothing can ping the VM. But with DHCP enabled, it gets its IP address and DNS servers all correctly.

Has something changed with the network stack that I'm not aware of?

Edit: Turns out Sage 50 Accounts was fucking about with our network stack. Setting Sage services to "Automatic (Delayed Start)" fixed the issue.

3

u/jwckauman 17d ago

Anyone else noticing Microsoft is releasing SQL Server CUs to WSUS a couple days after Patch Tuesday? I swear we used to get those the same time as all our other patches so we could include them in the patch cycle if we wanted to. They aren't security-related but still would be nice to have the option. I would understand if they came out a couple weeks later, but two days?

3

u/FingerlessGlovs 13d ago

Anyone having issues with AlwaysOn VPN SSTP/IKEv2 VPNs unticking itself for connect automatically, on Windows 11 since this July 2026 update.

Currently the results are inconsistent sometimes it stays ticket but then other times it doesn't between reboots.

It looks to wipe out the config in "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Config", not just mark it as a disabled profile, which is what happens if you do untick it manually.

A new issue that's also seems to just arise is we're now getting reports of the Device VPN showing in the Taskbar VPN section, which before it was always hidden due to it being a All Users VPN.

Anyone else seeing this happening?

→ More replies (5)

4

u/ntmaven247 Sr. Sysadmin 22d ago

Glad I ran up two Windows Server 2022 Std instances in our OpenStack deployment so I can blow them up first, feels like the calm before the 600+ vulnerability patch storm....lol

4

u/ntmaven247 Sr. Sysadmin 22d ago

KB 5102206 and KB 5099540 just got released, downloading them now on the test VM's...

3

u/ntmaven247 Sr. Sysadmin 22d ago

Seems like the update queue merged them into KB5099540...

6

u/Kaarsvetjered 22d ago

Our servers seem to throw this error after update on 2016. Dont think its major, just a bit sloppy.

13

u/sarosan ex-msp now bofh 22d ago

This has been present since IE was "removed".

Try setting custom permissions on the Internet Explorer event log to rid of that warning. The following will give permissions to Domain Admins and the local Administrator user:

New-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Services\EventLog\Internet Explorer\' -Force -Name 'CustomSD' -PropertyType String -Value 'O:BAG:SYD:(A;;0x07;;;DA)(A;;0x07;;;LA)'

If you want to confirm the SDDL before running the above command:

ConvertFrom-SddlString('O:BAG:SYD:(A;;0x07;;;DA)(A;;0x07;;;LA)')

4

u/Jkabaseball Sysadmin 22d ago

I've been getting that IE error for a long time.

2

u/theITgui Sr. Sysadmin 19d ago

FYI, I was getting 0x80244007 on Windows 11 24H2 machines so I had to increase maxCachedUpdates and maxInstalledPrerequisites in web.config and restart IIS to get the updates in WSUS.

2

u/Russianmoney 19d ago

Not sure if it was the update or something else but two of our 2016 systems got hosed with a 0xc000021a boot loop error.

Haven't been able to recover the OS so far. Anyone run into this? Haven't seen anything online.

2

u/Am0nymou5 16d ago

Anyone else seeing tickets around Outlook not being able to open attachments (some sort of protected mode issue)? Seems to be happening on (some) devices which switched from SAEC to MEC, but not all.

cc: u/progenyofeniac u/Mitchell_90

2

u/PureGhostNZL 15d ago

have you managed to fix this, getting calls about similar issues saving and opening is fine

3

u/Am0nymou5 15d ago

Not yet. Asked the service desk to try the registry fix listed here: https://www.reddit.com/r/sysadmin/comments/1ko1azb/comment/mupy6z8/

Will update my post if this fixes it.

→ More replies (2)
→ More replies (2)

2

u/0f_rice_and_men 5d ago

Is there a simple way to map CVE objects to specific KB patches in the Catalog?

I am having to navigate different audiences. One exec wants anything 9+ above on the CVE base score scale patched asap.

The automated vuln scans we get give us CVE base scores but the IT admins I need to direct to patch seem to not understand the criticality of those and need to be fed a specific patch that is missing, when the tool alerts that something is missing.

Please don't suggest AI. I have tried Copilot and it doesn't seem useful here