The images in this article were generated with artificial intelligence. How we publish
Microsoft has solved a failure that had affected the installation of Windows updates through the independent WUSA installer when .msu files were stored in a network resource and there was more than one in the folder. The problem, detected after updates published since 28 May 2025, caused errors such as ERROR _ BAD _ PATHNAME in teams with Windows 11 24H2 / 25H2 and Windows Server 2025 in business environments where managers usually use shared resources to deploy several updates at a time.
The key symptom for administrators was simple but annoying: the facilities failed only when trying to run WUSA or double-click a .msu from a network location containing multiple .msu; by copying the / the files locally or running a single .msu the problem did not manifest. This particularity points to a failure in route resolution or how WUSA interacts with the Windows Update Agent API in network scenarios, more frequent in managed infrastructure than in domestic equipment.

Microsoft applied mitigating measures before the final correction, including a reversal using Known Issue Rollback (KIR) for unmanaged equipment and some customers, but the complete repair came with the June 2026 cumulatives: see the details of the update for Windows 11 in KB5079391 and for Windows Server 2025 on KB5094125. To understand the mechanism and scope of the known reverse you can review the official documentation of Known Issue Rollbacks in Microsoft documentation.
From the operational point of view, this incident is a reminder that even venerable tools like WUSA can behave unexpectedly when changing platform components. In business environments, the practical consequence was to block manual or small batch deployments, increase in helpdesk work and risk that critical patches did not reach sensitive systems. In addition, Microsoft has shown a pattern of point regressions in different parking cycles (problems with WSUS in April 2025 and errors 0x80240069 in August 2025), which increases the need for caution by deploying production updates without prior evidence.
If your organization was affected and has not yet implemented the June 2026 updates, priority actions are apply the official cumulatives to the affected machines, or, as an immediate rule, copy the .msu locally and run the installation from disk to avoid error. Microsoft also advised to wait at least 15 minutes after a reboot after installing a .msu via WUSA before consulting the update history in Settings, as the interface may take time to reflect the actual status of the installation.

For patch management managers: do not rely solely on a single deployment method. Valid updates in a pilot group, check centralized delivery channels such as WSUS, Intune or third-party solutions, and maintain procedures to remedy failed facilities (record of errors, local reattempts, and use of Known Issue Rollbacks where appropriate). Also document post-installation checks and Microsoft-recommended waiting windows to avoid false positive status reports.
In terms of cybersecurity and continuity, a patch that is not applied on time extends the exposure surface. This is why it is essential to incorporate automated patch status and monitoring tests into its vulnerability management cycle, and consider testing update failure scenarios to reduce the reliance on manual interventions. For more technical information about WUSA and its use in controlled deployments, Microsoft's official guide to Windows Update Standalone Installer is a good starting point: Windows Update Standalone Installer (WUSA).
In short, the June 2026 correction eliminates the known failure that broke facilities from network resources with multiple .msu, but the episode underlines the need for tests, monitoring and alternative routes in patch management to not leave open doors to holdings resulting from delays in the application of updates.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...