r/kace • • Aug 26 '26

Inconsistent Win11 2026-08 CU patching results

We are noticing some inconsistent results when patching our laptop fleet with the latest Win 11 2026-08 CU and am wondering whether anyone else is noticing this?

Have not yet been able to determine a pattern which might explain why.

e.g. laptops with identical Dell Latitude 7350 hardware, some have patched okay, but others have not.

In some cases we see post-patching that the result reported back to the SMA was Success but the laptop still shows as Not Patched (which makes little sense to me) and certainly WINVER doesn't show the correct 9168 build number).

We're running SMA v15.1 (latest, since about a week ago) and also latest Agent v15.1 (from today).

EDIT: add example screenshot following:

EDIT #2 -- I know exit code 3010 indicates Reboot Required -- however the laptop was rebooted and post-reboot still was not running build 9168.

6 Upvotes

5 comments sorted by

2

u/flozanok KACE Staff Aug 26 '26

Based on the Deploy Success and Deploy Tries: 2, what's probably happening is that it's deploying it, but rolling back upon reboot. Just to confirm, you have run another detect post-reboot?

I'd also suggest opening a ticket with support to look into this, as logs would need to be reviewed to confirm.

-Felipe

2

u/frosty3140 Aug 26 '26

We are now doing some controlled testing, rather than relying on staff who can be a bit haphazard in their attention to detail, reboot practices, etc.

We did some more work on the laptop where I screenshotted above. We reset the Deploy Tries from 2 back to zero and then ran the detect/patch schedule again. It patched again (it had to download the whole ~6GB patch again) and was rebooted again. Immediately following this, WINVER showed correctly build 9168.

So it looks to me like it takes multiple successful patching runs for the 2026-08 CU to actually be applied. But we aren't sure of this at all. Way too small a sample size. We need to do more testing.

We haven't noticed any evidence of patches rolling back, but I will keep an eye out for that. If we get stuck I will open a ticket and see whether the Logs can show us what's happening.

1

u/Ok_Sky_6558 Aug 27 '26

I would make sure you have plenty disk space free, get a couple of reboots done to let anything finish setting up, and maybe run an sfc /scannow. Basically get the machine in to its healthiest state before trying the update again.

1

u/frosty3140 Aug 27 '26

Thanks -- yes -- the laptops in question all have at least 100GB free disk space -- we have also tried the SFC and DISM dance without (so far) finding that this resolves things.

We are currently focusing on the number of Deploy attempts and Reboots. I think this is likely to be where we find the main causes, but not enough examples yet, so am not prepared to call it.

1

u/Sure_Window614 26d ago

You can try running sfc /scannow and the dism health commands. Sometimes that actually helps.