The images in this article were generated with artificial intelligence. How we publish
Microsoft has solved a failure that had affected the installation of Windows updates through the independent WUSA installer when .msu files were stored in a network resource and there was more than one in the folder. The problem, detected after updates published since 28 May 2025, caused errors such as ERROR _ BAD _ PATHNAME in teams with Windows 11 24H2 / 25H2 and Windows Server 2025 in business environments where managers usually use shared resources to deploy several updates at a time.
The key symptom for administrators was simple but annoying: the facilities failed only when trying to run WUSA or double-click a .msu from a network location containing multiple .msu; by copying the / the files locally or running a single .msu the problem did not manifest. This particularity points to a failure in route resolution or how WUSA interacts with the Windows Update Agent API in network scenarios, more frequent in managed infrastructure than in domestic equipment.

Microsoft applied mitigating measures before the final correction, including a reversal using Known Issue Rollback (KIR) for unmanaged equipment and some customers, but the complete repair came with the June 2026 cumulatives: see the details of the update for Windows 11 in KB5079391 and for Windows Server 2025 on KB5094125. To understand the mechanism and scope of the known reverse you can review the official documentation of Known Issue Rollbacks in Microsoft documentation.
From the operational point of view, this incident is a reminder that even venerable tools like WUSA can behave unexpectedly when changing platform components. In business environments, the practical consequence was to block manual or small batch deployments, increase in helpdesk work and risk that critical patches did not reach sensitive systems. In addition, Microsoft has shown a pattern of point regressions in different parking cycles (problems with WSUS in April 2025 and errors 0x80240069 in August 2025), which increases the need for caution by deploying production updates without prior evidence.
If your organization was affected and has not yet implemented the June 2026 updates, priority actions are apply the official cumulatives to the affected machines, or, as an immediate rule, copy the .msu locally and run the installation from disk to avoid error. Microsoft also advised to wait at least 15 minutes after a reboot after installing a .msu via WUSA before consulting the update history in Settings, as the interface may take time to reflect the actual status of the installation.

For patch management managers: do not rely solely on a single deployment method. Valid updates in a pilot group, check centralized delivery channels such as WSUS, Intune or third-party solutions, and maintain procedures to remedy failed facilities (record of errors, local reattempts, and use of Known Issue Rollbacks where appropriate). Also document post-installation checks and Microsoft-recommended waiting windows to avoid false positive status reports.
In terms of cybersecurity and continuity, a patch that is not applied on time extends the exposure surface. This is why it is essential to incorporate automated patch status and monitoring tests into its vulnerability management cycle, and consider testing update failure scenarios to reduce the reliance on manual interventions. For more technical information about WUSA and its use in controlled deployments, Microsoft's official guide to Windows Update Standalone Installer is a good starting point: Windows Update Standalone Installer (WUSA).
In short, the June 2026 correction eliminates the known failure that broke facilities from network resources with multiple .msu, but the episode underlines the need for tests, monitoring and alternative routes in patch management to not leave open doors to holdings resulting from delays in the application of updates.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...