The images in this article were generated with artificial intelligence. How we publish
Microsoft has confirmed a new problem that prevents a small subset of equipment from installing the cumulative updates of June 2026 after they have been updated to Windows 11 24H2 or 25H2. According to the company's alert, the devices affected show the errors 0x80073712 or 0x800f0993 when trying to apply the patches, messages that in the records are described as ERROR _ SXS _ COMPONENT _ STORE _ CORRUPT and PSFX _ E _ REBASE _ HYDRATION _ CANDIDATES _ MISSING, respectively. These codes indicate corruption or inconsistencies in the Windows component store, a critical piece for the correct execution of the upgrade facilities.
The good news for domestic users and unmanaged business devices is that Microsoft is deploying a correction that is activated after restart the equipment: no new devices should arrive affected from 19 May 2026, 18: 30 PT, and a reboot can accelerate the application of the solution. For already up-to-date environments and equipment that continue to fail, Microsoft offers two clear steps: remove the problem package with DISM or, if that doesn't work, make an in-place update of Windows 11. The command indicated by Microsoft to remove the package is as follows (run it in a system symbol with privileges elevation): dec / online / remove -package / packagename: Package _ for _ RollupFix ~ 31bf38ad364e35 ~ amd64 ~ ~ 26100.1742.1.10.

Before running that order or trying to repair, it should be remembered that handling system packages can produce unwanted effects if the environment has complex integrations or third party software that depends on specific versions. Make a complete backup or at least a restoration point before proceeding and, in corporate environments, test disposal in laboratory equipment. If you are not comfortable, the safest and most likely to succeed alternative is the in-place update, which reinstates Windows by preserving applications and data.
For managers, the operational involvement is double: on the one hand, avoid installing equipment that lack the prior corrections during the jump to 24H2 / 25H2; on the other, monitor the update telemetry and Windows Update reports to detect massive failures. Microsoft publishes mitigation updates as part of the Patch Tuesday cycle; for example, several KB related to this problem family are available to install before the upgrade (see details of each KB and its id in Microsoft documentation). You can access the history and state of the incidents on the official Windows Release Health page: Windows Release Health and read the technical note on one of the incidents recently resolved in KB5089549.
The risks are real: a team that cannot apply cumulative patches is exposed to corrected vulnerabilities in these packages, increasing the attack window. For corporate equipment, in addition to technical risk, there are policy compliance and vulnerability management implications that may affect audits and insurance. Therefore, do not delay the status check on critical machines nor intervention in those which report the above codes.

If you detect the problem in your organization, document first the scope: how many equipment, what source and destination versions, and if the previous installation (e.g. migration from Windows 10 21H2 / 22H2 or Windows 11 23H2) was managed by tools such as Windows Update for Business, WSUS or Configuration Manager. This information will help to decide whether centralized mitigation (deploying the KB resolved before the upgrade) or specific actions in isolated equipment (forced reboot, DISM, in-place upgrade) are the right option.
For domestic users with a single machine, the steps are simple: check Settings > Windows Update > History of updates if errors appear with 0x80073712 or 0x800f0993; restart the computer to wait for automatic application of the correction; if the error persists, consider running the indicated DISM command (with prior backup) or the inplace update - following the official Microsoft guide. If you prefer direct documentation on related updates, you can check the Microsoft support input on the latest packages, for example KB5094126.
This episode is not isolated: in recent months Microsoft has had to publish off-schedule patches and specific recommendations for update scenarios, which highlights the increasing complexity of the maintenance cycle of modern operating systems. The practical lesson It is clear: test layer upgrades (firmware, drivers, critical applications, and update mechanisms) before deploying to production reduces incidences; keep backup and recovery plans speed up remediation; and have processes to monitor update failures allows to detect problems in advance and reduce exposure to vulnerabilities.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...