Windows 11’s Rocky July: Patch Tuesday, an Emergency Fix, and a New Preview Build
July has been an unusually eventful month for Windows 11 updates. What started as a routine Patch Tuesday release on July 14 turned into a multi-week saga involving a record-breaking security update, an emergency out-of-band fix for a subset of Dell machines, and — just this week — a fresh optional preview build previewing what’s coming next. Here’s how it all unfolded, and what Windows 11 users actually need to do about it.
It started with the biggest Patch Tuesday in Windows history
Microsoft’s July 2026 Patch Tuesday, released as KB5101650, quietly set a record: more than 570 vulnerabilities addressed directly by Microsoft, with the fuller count — including related CVE entries and Chromium-based Edge fixes tracked separately — pushing past 620. That makes it the largest single monthly security release Microsoft has ever shipped, roughly triple the vulnerability count from June and nearly five times May’s total.
Buried in the numbers were two zero-day vulnerabilities that were already being actively exploited before the patch shipped, plus a third that had been publicly disclosed. Among the standouts: a critical authentication bypass in SharePoint Server that, when chained with a second, still-embargoed vulnerability, can lead to fully unauthenticated remote code execution — a flaw serious enough that Microsoft is expected to ship the second half of the fix in August’s Patch Tuesday. Other high-priority items included an access-control flaw in Active Directory Federation Services that could let an authenticated attacker escalate to administrator, and a BitLocker protection-bypass issue exploitable through physical access to a device.
On the non-security side, KB5101650 also delivered a broader rollout of Point-in-time restore — a full-system rollback feature that had spent months hiding in Windows Insider builds — along with Secure Boot certificate rollout improvements, Bluetooth stability fixes, faster File Explorer performance, and a fix for a Recycle Bin bug from the June update that had been showing internal file names (like “$R4ABC12.docx”) instead of the original file name in delete confirmation dialogs.
Then came the storage bug — and a very overdue fix
KB5101650 also quietly resolved a problem that had been frustrating users since the spring: a bug in the Capability Access Manager service that could cause a hidden database file to balloon in size, in extreme cases consuming hundreds of gigabytes of drive space without any clear explanation in Settings. Independent tracking across thousands of affected devices found that well over half showed the problematic file exceeding a gigabyte in size, with some machines seeing the file grow by tens of gigabytes in a single week. Microsoft had privately acknowledged the issue as early as mid-May, offering a manual Safe Mode workaround to affected users who opened support tickets, but the fix didn’t ship broadly until this month’s cumulative update — and the issue was never listed on Windows’ public release-health dashboard, leaving most affected users to discover the workaround only through word of mouth or tech press coverage.
Then the emergency fix: KB5121767
Just days after Patch Tuesday, reports began surfacing of a specific, serious problem: certain Dell PCs receiving the July update experienced unexpected shutdowns, overheating, poor performance and rapid battery drain. Microsoft traced the issue to a conflict with Intel’s Innovation Platform Framework driver, used in thermal management on many newer systems, and responded by temporarily blocking KB5101650 from installing on the affected Dell models while it prepared a fix.
That fix arrived on July 19 as KB5121767, an out-of-band cumulative update built specifically to replace the July security update on the affected machines. Microsoft was clear that the update is intended only for PCs that were actually hit by the issue — if your device wasn’t affected, no action was required — though some users reported the update automatically downloading on unaffected machines when certain Windows Update settings were enabled. This kind of targeted, out-of-band patch is relatively rare and typically reserved for problems serious enough that Microsoft can’t wait for the next scheduled Patch Tuesday to fix them.
And now: a preview of what’s coming in August
This week, Microsoft published its July non-security preview update — KB5101684 for Windows 11 versions 25H2 and 24H2, and the parallel KB5101681 for version 26H1. Preview updates like these are optional releases that give Microsoft a chance to ship quality-of-life fixes and feature refinements ahead of the following month’s mandatory security update, and they give more cautious users and IT departments an early look at what will eventually become part of the standard rollout.
For home users, the practical takeaway is simple: this is an optional update that shows up under “Optional updates” in Windows Update, not something that installs automatically. Businesses running managed device fleets generally only see preview updates if an administrator specifically deploys them, which keeps unpredictable early-stage fixes away from production machines until they’ve been folded into a mandatory release.
How to check where you stand
With three separate updates in play this month, it’s worth taking a moment to confirm exactly what’s installed on your machine:
- Go to Settings > Windows Update and check your update history to see whether KB5101650 (the July security update) has installed successfully.
- If you own an affected Dell PC and experienced shutdowns, overheating or battery issues after installing the July update, check Windows Update for KB5121767 specifically, or consult Dell’s support documentation for your model.
- Go to Settings > System > About and check the build number under Windows specifications — builds 26200.8875 or 26100.8875 confirm the July security update has applied.
- If you want early access to August’s quality fixes, look for KB5101684 (or KB5101681 on 26H1) under Optional updates.
Why one Patch Tuesday keeps spawning follow-up updates
To someone who doesn’t follow Windows servicing closely, having three distinct update packages in play within a single month can look chaotic. In practice, it reflects how Microsoft has restructured its update strategy over the past several years to balance two competing goals: shipping security fixes to hundreds of millions of devices on a predictable monthly schedule, while still being able to react quickly when something in that release causes real-world problems on specific hardware.
The mandatory Patch Tuesday release is deliberately conservative — Microsoft tests broadly before it ships, but with a install base spanning an enormous range of hardware configurations, driver versions, and third-party software combinations, some percentage of real-world problems only surface after a release reaches full scale. That’s exactly what happened with the Dell/Intel thermal management conflict this month: an interaction serious enough to justify pulling the update from affected devices and shipping a dedicated out-of-band fix, but narrow enough that it didn’t require re-issuing the entire monthly security package for every Windows 11 user.
The optional preview update that follows a few weeks later serves a different purpose entirely: giving Microsoft a low-stakes proving ground for quality-of-life fixes and smaller feature refinements before they become part of next month’s mandatory release. Because preview updates are opt-in, Microsoft can ship more experimental changes into them without the same blast-radius risk a mandatory update carries.
The record-breaking vulnerability count, in context
It’s worth dwelling for a moment on just how large July’s Patch Tuesday was. Security researchers tracking Microsoft’s monthly disclosures noted that the roughly 570 vulnerabilities Microsoft directly enumerated — not even counting the nearly 400 additional Chromium-based Edge vulnerabilities patched separately by Google earlier in the month — represented close to triple June’s total and nearly five times May’s. Some of that growth is almost certainly a byproduct of the same trend affecting other major vendors this year: AI-assisted vulnerability discovery tools are helping both internal security teams and outside researchers find bugs at a pace that simply wasn’t possible with manual auditing alone.
That has real implications for how organizations should think about patch management. A monthly cadence built around manageable, predictable release sizes starts to strain when a single month’s disclosures can exceed 600 individual issues. Several security vendors covering this release specifically urged enterprises to treat the sheer scale as a signal to revisit patch deployment processes — prioritizing critical and actively exploited vulnerabilities for immediate deployment while building more systematic, tested rollout procedures for the long tail of lower-severity fixes rather than attempting to deploy all 570-plus changes with equal urgency.
Tips for navigating a month like this one
- Prioritize by exploitation status, not just severity. The two actively exploited zero-days and the SharePoint authentication bypass deserve faster action than the hundreds of lower-severity “Important” fixes bundled into the same release.
- If you’re on affected Dell hardware, don’t assume you’re covered automatically. Check Windows Update history specifically for KB5121767 if you experienced shutdowns, overheating, or battery problems after mid-July.
- Treat storage issues seriously even without an error message. The Capability Access Manager bug fixed this month is a good example of a problem that never surfaced through normal Windows notifications — periodically checking free disk space is still worthwhile even on a “healthy-looking” system.
- Business users should distinguish preview updates from mandatory ones. KB5101684 and KB5101681 are optional previews; there’s no need to seek them out unless you specifically want early access to next month’s non-security fixes.
The bigger pattern
This month is a useful case study in how modern Windows servicing actually works: a single mandatory security release, followed by a targeted emergency patch when something goes wrong for a specific subset of hardware, followed by an optional preview that starts the cycle over again for next month. It isn’t glamorous, but it’s a far cry from the days of infrequent, monolithic service packs — and for most users, the right move remains the simplest one: keep automatic updates enabled, and only dig into the KB numbers if something actually goes wrong.
