Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Windows Update says a patch installed fine, but one server in the DMZ never got it. Or a cumulative update fails on three laptops and you need the exact package to try again by hand. Here's how to use the Microsoft Update Catalog to find the right update, install it with wusa or DISM, handle the new checkpoint updates, and prove it landed.

What the Microsoft Update Catalog Is

The Microsoft Update Catalog is Microsoft's public index of update packages. It lists cumulative updates, security updates, servicing stack updates, drivers and hotfixes, each as a downloadable file. Microsoft describes it as a listing of updates "that can be distributed over a corporate network."

It doesn't install anything. Windows Update, WSUS and Intune decide what a device needs and deliver it. The catalog hands you the same packages as files, so you decide where and when they go.

When to Use the Catalog Instead of Windows Update

For day-to-day patching, let your normal channel do the work. The catalog is the tool for the exceptions:

  • Offline or restricted machines. DMZ servers, lab networks and air-gapped systems that can't reach Windows Update.
  • A failing update. When a cumulative update keeps failing through Windows Update, installing the package by hand often shows a clearer error.
  • One KB for a test ring. You want a single update on five pilot machines before it reaches everyone.
  • Out-of-band fixes. Emergency updates that Microsoft publishes to the catalog but doesn't push to every channel.
  • Image servicing. Adding the latest cumulative update to install.wim before you deploy it.

That first case is common enough that the catalog going down gets its own r/sysadmin thread. One admin patching DMZ servers by hand found search returning nothing for almost two hours:

If the catalog is part of your emergency plan, keep a local copy of the last few cumulative updates for the systems that depend on it.

How to Find the Right Update

Search by KB number. Type KB5048667 into the search box and you get every variant of that update: each Windows version, each architecture, sometimes each language. You can also search by product name, classification or, for drivers, the four-part hardware ID. Wrap a phrase in double quotes to match it exactly.

Read four columns before you click Download:

  • Title. It names the Windows version and the architecture. "x64-based Systems" and "arm64-based Systems" are different files, and the wrong one fails with a "not applicable" error.
  • Products. Windows 11 version 24H2 and 25H2 can share a package. Windows Server has its own.
  • Classification. Security Updates, Updates, Critical Updates or Drivers.
  • Last Updated. Microsoft sometimes re-releases a package. Take the newest.

Click the title to open the details page. It shows the package's supersedence, so you can see which older updates it replaces, plus the UpdateID you'll need for a WSUS import.

.msu vs .cab

The Download button gives you one or more .msu files. An .msu is a wrapper around one or more .cab files, plus the Windows Update metadata and an XML file describing the package.

.msu.cab
What it isWindows Update standalone packageThe update payload itself
Install withDouble-click, wusa or DISMDISM only
Remove withDISM, by package nameDISM, by package name or path
WSUS importNo, use the UpdateID insteadNo

Keep the .msu unless a tool asks for a .cab. wusa.exe <file>.msu /extract:C:\cabs unpacks it when you need the inside.

How to Install an Update From the Catalog

On a single machine, double-clicking the .msu runs the Windows Update Standalone Installer. For anything scripted, use the command line.

With wusa:

code
wusa.exe C:\updates\windows11.0-kb5048667-x64.msu /quiet /norestart

With DISM, which Microsoft's KB articles now use in their own install steps:

code
DISM /Online /Add-Package /PackagePath:C:\updates\windows11.0-kb5048667-x64.msu

DISM can add an .msu to a running system on Windows 11 version 21H2 and later. On older versions, it only takes an .msu for offline images. For a mounted image, swap /Online for /Image:C:\mount. The PowerShell equivalent is Add-WindowsPackage -Online -PackagePath.

Either way, plan a reboot. Our guide to DISM RestoreHealth covers what to run first if DISM reports component store corruption.

BrenTech's walkthrough shows the manual download and install from start to finish:

Checkpoint Cumulative Updates on Windows 11 24H2

Starting with Windows 11 version 24H2, Microsoft ships some cumulative updates as checkpoints. Later updates only contain the changes since the last checkpoint. That makes them smaller, but it adds a rule for catalog users: a device needs every earlier checkpoint before it can take the target update.

That's why the catalog's download window sometimes shows two .msu files for one KB. Microsoft's own example is the December 2024 update, KB5048667, which needs the September 2024 checkpoint, KB5043080, first. Windows Update and WSUS handle this for you. Manual installs don't.

You have two options. Install each .msu in order, oldest first. Or put the target .msu and its checkpoints in one folder, with nothing else in it, and point DISM at the target:

code
DISM /Online /Add-Package /PackagePath:C:\updates\windows11.0-kb5048667-x64.msu

DISM finds the checkpoints in that folder and applies the ones the device is missing, in the right order. Microsoft's page on checkpoint cumulative updates covers the image servicing cases, including when Features on Demand or language packs need every checkpoint regardless.

Importing Catalog Updates Into WSUS and Configuration Manager

WSUS can't import an .msu. The old Import Updates button in the WSUS console relied on ActiveX, and Microsoft replaced it with a PowerShell script. Copy the UpdateID from the catalog's details page, then run Microsoft's ImportUpdateToWSUS.ps1 against your WSUS server. The script calls ImportUpdateFromCatalogSite for each ID, and it accepts a text file with one UpdateID per line for bulk imports. Microsoft's WSUS import guide has the full script.

Configuration Manager uses the same route. Import into the WSUS server behind your top-level software update point, then run Synchronize Software Updates in the console. Child sites pick it up from there.

This matters when Microsoft ships out-of-band fixes. In September 2026, an r/SCCM admin found that some OOB updates arrived through WSUS sync while others had to be imported by hand:

Verifying and Rolling Back a Catalog Install

Check the install from the servicing stack's view first:

code
DISM /Online /Get-Packages /Format:Table

The package list shows each installed update with its state. Get-HotFix -Id KB5048667 is quicker to type, and it works against remote machines with -ComputerName. Microsoft notes it only returns updates from Component Based Servicing, so an empty result isn't always proof the update is missing.

Rolling back works differently than you might expect. Cumulative updates now ship combined with the servicing stack update, and Microsoft's KB articles state that wusa.exe /uninstall "will not work" on the combined package. Use DISM instead. Find the package name with /Get-Packages, then remove it:

code
DISM /Online /Remove-Package /PackageName:<package name from Get-Packages>

The servicing stack part stays behind. Microsoft doesn't allow removing it.

Checking five machines by hand is fine. For a whole client, OpenFrame can run the same DISM or Get-HotFix check as a script across a client's devices and collect the output in one place.

The Short Version

The Microsoft Update Catalog is where you get an update as a file when the normal channel can't or won't deliver it. Search by KB, match the Windows version and architecture, install with DISM, and on Windows 11 24H2 keep the checkpoints in the same folder. Import into WSUS by UpdateID, verify with DISM, and roll back with DISM too.

For the bigger picture, see how the tools compare in our guide to patch management software.

When you need to hold a patch back instead, here's how to stop Windows Update safely.

"Fae" Grace Meadows

"Fae" Grace Meadows

Lead AI Fairy

Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Microsoft Update Catalog

It is Microsoft's public index of update packages: cumulative updates, security updates, servicing stack updates, drivers and hotfixes, each available as a downloadable file. It does not install anything by itself. You download the package and install it with wusa, DISM or your update tooling, or import it into WSUS.
Search the catalog by KB number, download the .msu that matches the device's Windows version and architecture, then run DISM /Online /Add-Package /PackagePath: with the path to the .msu, or wusa.exe with /quiet /norestart. Restart the device, then confirm the install with DISM /Online /Get-Packages.
Starting with Windows 11 version 24H2, some cumulative updates are checkpoints. A later update needs every earlier checkpoint first, so the catalog lists the checkpoint .msu next to the target. Install them in order, or put them in one folder and point DISM /Add-Package at the target file.
Find the package name with DISM /Online /Get-Packages, then run DISM /Online /Remove-Package /PackageName: with that name. Microsoft states that wusa.exe /uninstall does not work on the combined servicing stack and cumulative update package, and the servicing stack part cannot be removed.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.