Windows August Security Update KB5121003 not being offered through Windows update

LawrenceHeard-8029 0 Reputation points
2026-09-03T17:38:25.8333333+00:00

I have noticed an issue in our estate of roughly 400 Windows 11 laptops, that the monthly security update KB5121003 is not being offered for download. It only exists on around 9 devices that had the update installed directly from the catalogue.

Our fleet of devices is a mix of Microsoft surface 4s /5s and Dell Pro 14's.

We use a managed service for our patching so I queried this observation with them and this was their response:

"When Microsoft releases a new patch, it is distributed through Service channels. If the device is able to detect the update in question during a normal, local update scan, we would be able to detect those patches during the next patch management scan as well. If the device cannot detect the patch, then we will not display it either, as we utilize the results and data from Windows Updater.

In limited cases, there may be a delay between when a security update is released by Microsoft and when that patch is available directly through Windows Update. Microsoft slow rolls patches to all Windows devices over time. This is why you will see it available on one device but not another, even if you run a manual update directly on the devices."

It was my understanding that mandatory monthly security updates were not "slow rolled" out and that they are made available for all devices immediately.
Could anyone clarify my interpterion of security updates is correct and if there is an issue with the availability of this patch for certain devices.

Thank you.

Microsoft Security | Intune | Other
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-09-03T17:38:52.86+00:00

    Monthly security updates are not described as a phased or “slow roll” release in the provided Microsoft documentation. They are published on the second Tuesday of each month, are cumulative, and are made available through Windows Update, WSUS, and the Microsoft Update Catalog. Microsoft states that most organizations consider these monthly security updates mandatory.

    For Windows 11, version 24H2, Microsoft also introduced checkpoint cumulative updates. That changes how some cumulative updates are built, but for devices updating from Windows Update and WSUS, Microsoft states the process is seamless and that no change is needed to the update process.

    For devices that are not being offered a monthly security update, the provided documentation supports these points:

    1. Monthly security updates should be available through the normal servicing channels.
    2. If devices have recurring installation failures caused by servicing stack file or metadata corruption, they might be unable to install monthly security updates and may not become current without remediation.
    3. On affected Windows 10/11 devices, Windows can automatically run a Windows Update troubleshooter that targets the device for an in-place upgrade to resolve the corruption. This troubleshooter cannot be run manually.
    4. On devices with recurring Windows Update problems, there is also a supported recovery path in Settings > System > Recovery using Reinstall now in Fix problems with Windows Updates. The accepted Microsoft Q&A answer states this process does not affect files, settings, or installed apps.

    Based on the provided material, the interpretation that monthly security updates are standard broadly released updates is correct. The supplied documentation does not support the claim that these mandatory monthly security updates are generally withheld from otherwise healthy devices as part of a normal slow-roll process.

    For the estate described, the most evidence-based checks are:

    1. Confirm whether the affected laptops are update-managed through policy, Intune, GPO, CSP, Microsoft Graph, or the managed patching tool, because those controls determine what updates are offered and when.
    2. On a sample affected device, check Start > Settings > Windows Update > Update history to verify whether KB5121003 was installed, superseded, or repeatedly failed.
    3. If devices show repeated quality update failures, check Start > Settings > Update & Security > Troubleshoot > View history for the Windows Update troubleshooter entry indicating the device was automatically targeted for an in-place upgrade due to recurring installation issues.
    4. If recurring update failures are present, use Settings > System > Recovery > Reinstall now under Fix problems with Windows Updates on a test device first. This is a repair action, so validate it on a pilot group before wider use.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.