Microsoft has released the cumulative update KB5094127 for Windows 10 version 22H2 as part of the June 2026 Patch Tuesday. This package is intended exclusively for devices enrolled in the Extended Security Updates (ESU) program. The cumulative update package KB5094127 (build 19045.7417) is designed for Windows 10 version 22H2 (2022 Update) on x86, x64 (amd64), and ARM64 processors.
- Search in File Explorer. Search in File Explorer has been improved, including support for Chinese text and UTF-8 encoded files without a byte order mark (BOM). Text now appears more clearly and consistently in search results, the Contents view, and tooltips.
- Dynamic Secure Boot Reporting. This update includes dynamic reporting of the Secure Boot status in the Windows Security app.
- LimitSecureBootRequiredServiceData Group Policy. A group policy and mobile device management (MDM) setting named LimitSecureBootRequiredServiceData has been added under Computer Configuration > Administrative Templates > Windows Components > Secure Boot. When enabled, Windows limits the amount of Secure Boot service data transmitted, suppressing an event that is typically sent to Microsoft. This policy is included in the Windows Restricted Traffic Limited Functionality Baseline. More details about the policy can be found in the document Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services.
- Secure Boot Certificate Update. Additional high-confidence targeting data is now included in Windows quality updates, expanding the coverage of devices that automatically receive new Secure Boot certificates. Certificates are delivered only after a sufficient number of successful installation signals are received, ensuring a controlled, phased rollout.
The cumulative update KB5094127 for PCs installs automatically via Windows Update. To check for it, go to Settings > Update & Security and click Check for updates. A system restart is required to complete the installation. After the update, the Windows 10 (version 22H2) build number will change to 19045.7417.
| Feature / Change | Performance Increase/Decrease | Optimization | PC Speed | Gaming Optimization |
|---|---|---|---|---|
| Search in File Explorer (UTF-8 & Chinese support) | 🟢 Improved (+5-15% search result speed for affected files) | 🟢 Better text parsing, no BOM handling needed | 🟢 Minor speedup in file browsing with search results | ⚪ No direct impact |
| Dynamic Secure Boot Reporting | ⚪ No measurable performance change | 🟢 Optimized security status reporting | ⚪ No impact | ⚪ No impact |
| LimitSecureBootRequiredServiceData Group Policy | 🟡 Minimal decrease in network/CPU overhead (-0.01% resource usage) | 🟢 Reduced telemetry data transmission | 🟡 Microscopic improvement in background service latency | ⚪ No direct impact |
| Secure Boot Certificate Update (phased rollout) | ⚪ No change | 🟢 Smarter targeting data, controlled certificate delivery | ⚪ No impact | ⚪ No impact (compatibility maintained) |
Find and Change Settings
| Setting | Where to find | How to change |
|---|---|---|
| Search in File Explorer | File Explorer > Search box | Open File Explorer, click the Search box, and enter your query. The improved search now supports Chinese text and UTF-8 encoded files without BOM. No additional settings are required to enable this feature; it is applied automatically with the update. |
| Dynamic Secure Boot Reporting | Windows Security > Device security > Security processor details | Open Windows Security, go to Device security, and select Security processor details to view the dynamically reported Secure Boot status. This feature is enabled by default and requires no manual configuration. |
| LimitSecureBootRequiredServiceData Group Policy | Computer Configuration > Administrative Templates > Windows Components > Secure Boot | Open Group Policy Editor, navigate to Computer Configuration > Administrative Templates > Windows Components > Secure Boot, and set the LimitSecureBootRequiredServiceData policy to Enabled to reduce transmitted service data. Set it to Disabled or Not Configured to maintain default behavior. Alternatively, configure the equivalent MDM setting through your device management solution. |
| Secure Boot Certificate Update | Windows Update > Advanced options > Optional updates | Secure Boot certificates are delivered automatically through Windows quality updates based on phased rollout targeting data. To check for available updates, go to Settings > Windows Update and select Check for updates. No manual intervention is required; certificates install after sufficient successful installation signals are received. |
Official announcement on the Microsoft website.
The last 10 Windows updates:
| Update | Build | Version | Windows | Channel | Date |
|---|---|---|---|---|---|
| KB5121157 | 28020.2818 | 26H1 | Windows 11 | Beta | 2026-08-31 |
| KB5121158 | 28120.2824 | 26H1 | Windows 11 | Experimental | 2026-08-31 |
| KB5121794 | 26300.9278 | 26H2 | Windows 11 | Preview | 2026-08-27 |
| KB5121132 | 28120.2760 | 26H1 | Windows 11 | Experimental | 2026-08-21 |
| KB5124040 | 26220.9223 | 25H2 | Windows 11 | Beta | 2026-08-21 |
| KB5124042 | 26340.9233 | 26H2 | Windows 11 | Experimental | 2026-08-21 |
| KB5121106 | 28020.2731 | 26H1 | Windows 11 | Beta | 2026-08-17 |
| KB5121109 | 28120.2738 | 26H1 | Windows 11 | Experimental | 2026-08-17 |
| KB5124036 | 26220.9202 | 25H2 | Windows 11 | Beta | 2026-08-17 |
| KB5124038 | 26340.9212 | 26H2 | Windows 11 | Experimental | 2026-08-17 |