Connect with us

NEWS

KB5089573 Unblocks Windows 11 Updates on Packed EFI Partitions

KB5089573 unblocks Windows 11 Patch Tuesday on PCs whose EFI partitions had 10 MB free, while OEM files and Secure Boot certs still share that slice.

Published

on

Microsoft’s May 26, 2026 preview KB5089573 moves Windows 11 24H2 and 25H2 to builds 26100.8524 and 26200.8524. It exists because the May 12 security update, KB5089549, rolled back with error 0x800f0922 on PCs that had 10 MB or less free on the EFI System Partition.

The optional package also refreshes on-device AI modules, ships servicing stack update KB5092734, and adds targeting data for new Secure Boot certificates. The occupant that decided whether Patch Tuesday could finish is that small FAT32 boot slice, already holding OEM files Microsoft’s installer did not put there.

May’s Security Update Died at 35 Percent

KB5089549, the May 12, 2026 cumulative for Windows 11 24H2 and 25H2, took those branches to builds 26100.8457 and 26200.8457 and then failed on a subset of devices. Microsoft documented the known issue on May 15, three days after the security drop, and pointed at free space on the EFI System Partition.

On those PCs the download and staging steps looked fine. The break came after reboot, when Windows tried to service boot files and ran out of room.

WHAT FAILED ON AFFECTED PCS

  • Early stages: The May 12 package installed through its first phases without an obvious error.
  • Reboot stall: Setup died during the restart pass at 35 to 36 percent complete.
  • Rollback copy: Windows undid the change and showed “Something didn’t go as planned. Undoing changes.”
  • Error code: Windows Update then reported 0x800f0922.
  • Who hit it: Devices with very little free space on the EFI System Partition, especially at that 10 MB free-space floor.

That on-screen line is the whole incident in one sentence. The security patches never landed, so the PC sat on the previous cumulative until a later package could write boot files again.

Something didn’t go as planned. Undoing changes.

Windows 11 rollback screen after KB5089549

Microsoft later said the May 26 preview addresses that install failure, and on May 29 it moved the fix into the normal-rollout column of the preview notes. Until that package, or a later security update that carries the same change, the May Patch Tuesday hole stayed open on those machines.

What KB5089573 Puts on 24H2 and 25H2

KB5089573 is an optional, production-quality preview for Windows 11 version 24H2 and version 25H2, all editions, and Microsoft says it is not currently aware of any issues with it. Home PCs pick it up under Settings, Windows Update, Advanced options, Optional updates. Windows Update for Business was told the same changes would appear in the next security update rather than as a separate optional click.

The notes describe production-quality improvements in KB5089573 delivered in two phases, a gradual rollout that spreads features across devices and a normal rollout that hits every eligible PC at once. Personalization tweaks entered the gradual column on May 28. The install fix was listed as a normal rollout the next day.

Inside the same combined package is Windows 11 servicing stack update KB5092734, build 26100.8519. That stack is the installer for later Windows updates. Microsoft now wraps the latest servicing stack with the latest cumulative so administrators are not left staging two packages in order, which is how an old stack used to block a new security drop.

The preview also bumps four on-device AI modules that only apply to Copilot+ PCs. They do not install on a regular Windows PC or on Windows Server, even though the files ride along in the cumulative.

AI MODULE VERSIONS IN THE MAY PACKAGES

AI component KB5089549 (May 12) KB5089573 (May 26)
Image Search 1.2604.515.0 1.2605.856.0
Content Extraction 1.2604.515.0 1.2605.856.0
Semantic Analysis 1.2604.515.0 1.2605.856.0
Settings Model 1.2604.515.0 1.2605.856.0

Microsoft’s AI component release history for Copilot+ records both version rows against KB5089573 on 2026-05-26, because the preview package can carry the prior module build as well as the new one. Later optional cumulatives have already moved those four modules on again, so a PC that kept updating past May is not frozen on 1.2605.856.0.

OEM Files Already Occupied the Boot Partition

The EFI System Partition is the FAT32 slice a UEFI PC actually boots from. Microsoft’s current GPT layout rules set a 200 MB EFI system partition minimum on 512-byte and 512e disks, and 300 MB on 4K native disks. The same page says the partition is managed by the operating system and should not hold other files, including Windows Recovery Environment tools.

May’s failure was not a 200 MB versus 300 MB debate. It was free space measured in the low tens of megabytes, on partitions that still had to accept a boot-file servicing pass. CBS logs on broken installs called out insufficient free space, ServicingBootFiles, and space used by third-party or OEM files outside Microsoft boot directories.

That last line is the stakeholder. HP now tells business-PC imaging teams to follow HP’s 512 MB ESP recommendation and to stop shipping a 100 MB layout. A smaller ESP, HP says, may not leave enough room for Windows boot servicing, Secure Boot updates, HP BIOS recovery content, HP UEFI diagnostics, and firmware update files. Those OEM payloads are exactly the “other files” the GPT guide says should not live there, and they are what the May CBS logs flagged.

EFI PARTITION SIZE RULES IN PLAY

Rule Figure Where it applies
Microsoft GPT minimum, 512e disks 200 MB Current Windows hardware spec for the system partition
Microsoft GPT minimum, 4K native disks 300 MB Current Windows hardware spec for 4K media
HP business-PC imaging floor 512 MB Room for BIOS recovery, diagnostics, firmware, and boot servicing
Layout HP tells customers to avoid 100 MB Legacy imaging scripts and older factory defaults
May 2026 install failure 10 MB or less free Quality update cannot finish writing boot files

A GPT disk can hold up to 128 partitions, and Microsoft reserved partitions are 16 MB, so the squeeze is not a lack of partition slots. It is a FAT32 boot volume that OEMs treated as a firmware stash, then a monthly Windows quality update that needed a few more megabytes than were left.

Secure Boot Certificates Share That Same Slice

The May 26 notes open with the same banner both May quality updates carried. Secure Boot certificates expiring in 2026 were originally issued in 2011. Devices that miss the 2023 replacements still start, and ordinary Windows updates still install, but they stop receiving new boot-manager protections, database updates, revocation lists, and fixes for fresh boot-level bugs.

Secure Boot certificates used by most Windows devices have started expiring in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install.

Microsoft, KB5089573 support note

KB5089573 does not swap the certificates by itself. It adds more high-confidence device targeting data so a larger set of PCs becomes eligible for automatic delivery, and only after those devices show enough successful update signals. It also adds the LimitSecureBootRequiredServiceData group policy and MDM setting, which stops Windows sending the usual Secure Boot service event to Microsoft when a Restricted Traffic Limited Functionality baseline is in force.

THE 2026 CERTIFICATE CLOCK

  1. May 12, 2026: KB5089549 ships, adds a SecureBoot folder under C:\Windows on eligible devices, and then fails to finish on packed EFI partitions.
  2. May 26, 2026: KB5089573 ships as an optional preview, restores that install path, and widens certificate targeting data.
  3. June 24, 2026: Microsoft Corporation KEK CA 2011 expires. The 2023 replacement, Microsoft Corporation KEK 2K CA 2023, is what signs later DB and DBX updates.
  4. June 27, 2026: Microsoft UEFI CA 2011 expires and splits into Microsoft UEFI CA 2023 for third-party boot loaders and Microsoft Option ROM UEFI CA 2023 for option ROMs.
  5. October 19, 2026: Microsoft Windows Production PCA 2011 expires. Windows UEFI CA 2023 is the replacement that signs the Windows boot loader.

June 24 and June 27 are already behind the calendar. The Production PCA date is still ahead. Certificate payloads, boot-file servicing, and OEM firmware extras all compete for the same FAT32 volume that ran out of space in May, which is why Secure Boot fixes still failing on HP and Dell fleets sit on the same hardware path as this preview.

The Snappiness Pitch Missed the Boot Files

Most of the public argument around KB5089573 never mentioned the EFI partition. The optional preview was framed as a feel-faster drop: quicker Start, Search, and Action Center, less wait when apps launch, steadier File Explorer, cleaner touch and clipboard history, and quieter Microsoft Store transfers.

Those items are in the official highlights. Shared Audio is new, using Bluetooth LE Audio broadcast so two supported, paired, connected devices can listen from Quick settings. Task Manager gains optional NPU and NPU Engine columns, plus NPU dedicated and shared memory on Details, and an Isolation column for AppContainer. Magnifier talks more clearly to screen readers and can magnify permitted protected content. Multi-app camera lets more than one app share the stream, with a Basic Camera mode for troubleshooting. Search starts ranking files from two characters. Dev Drive creation accepts size in GB. USB4 dock displays light up more reliably out of standby.

Windows Hello face or fingerprint becomes the default sign-in method when it is set up, until you use a PIN three times in a row. Setup can take a custom user-folder name on the Device Name page. Store changes include the same Microsoft Store download speed work the notes describe as underlying download and bandwidth fixes, plus clearer errors when a Windows Update group policy blocks a Store transfer.

Replies under the most-circulated roundup treated a responsive File Explorer as if it were a breakthrough, and asked when the baseline shell would stop being a patch-note event. That is a fair read of the feature list. It is a poor read of why the package had to exist in the third week of May. The servicing fix is the load-bearing change. Shared Audio and NPU columns rode in the same optional bucket because Microsoft dumps production-quality work into the late-month preview, not because Bluetooth LE Audio unblocked Patch Tuesday.

The Same Error Still Shows Up After May

Microsoft’s position on the May 12 known issue is blunt: updates released May 26, 2026 (KB5089573) and later address it, and PCs that install those packages do not need a separate workaround. The preview itself listed no known issues. For anyone who skipped the optional click, later monthly security updates were the path that was supposed to carry the same install change.

The error code did not retire with that May known-issue note. Device-management write-ups in August 2026 were still tracing Windows 11 25H2 feature-upgrade failures to a short EFI partition and the same 0x800f0922 code, which is a different servicing path than a monthly quality update. A packed ESP can break a feature upgrade even after the May quality-update hole is closed.

One technician report on September 9, 2026 tied 0x800f0922 to Windows Sandbox when a cumulative tried to delta-patch the guest OS. That is a single environment, not a new Microsoft known issue, and it is useful only as a reminder that the code still means “this servicing pass could not commit,” often because a system partition ran out of room.

The practical check on a UEFI PC is free space on the EFI slice, not the size of C:. If that volume is stuffed with OEM firmware extras, the next boot-file pass, including leftover Secure Boot certificate delivery ahead of October 19, 2026, is the change that still has to fit.

Frequently Asked Questions

Which Windows 11 versions does KB5089573 support?

The support note applies to Windows 11 version 24H2 and version 25H2, all editions. It does not list Windows Server, and the May 12 install failure was documented on those client branches only, so a server SKU was never in the Applies To line for either package.

What does error 0x800f0922 mean for this update?

On the May 12 failure, CBS.log under C:\Windows\Logs\CBS\ showed “SpaceCheck: Insufficient free space,” “ServicingBootFiles failed. Error = 0x70,” and space used by third-party or OEM files outside Microsoft boot directories, which is how Microsoft tied the code to a packed EFI System Partition rather than to a generic Windows Update glitch.

Do the AI components in KB5089573 install on every PC?

No. Image Search, Content Extraction, Semantic Analysis, and the Settings Model in this package are for Copilot+ PCs only, and Microsoft’s own catalog note says those AI components will not install on a regular Windows PC or on Windows Server even though the cumulative contains them.

What servicing stack update ships with KB5089573?

The combined package includes servicing stack update KB5092734 at build 26100.8519. The May 12 security update had shipped stack KB5092762 at 26100.8456, so the preview both raised the installer layer and wrapped it with the latest cumulative so the stack no longer has to be staged as a separate prerequisite.

How do you install KB5089573 if Windows Update hides it?

On unmanaged PCs it is an optional preview under Advanced options, Optional updates. Windows Update for Business was told the same changes would appear in the next security update, and the standalone MSU files are listed on the Microsoft Update Catalog for x64 and arm64 if you need to DISM the package by hand.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending