Updated: October 2026
Windows Update says a patch installed fine, but one server in the DMZ never got it. Or a cumulative update fails on three laptops and you need the exact package to try again by hand. Here's how to use the Microsoft Update Catalog to find the right update, install it with wusa or DISM, handle the new checkpoint updates, and prove it landed.
What the Microsoft Update Catalog Is
The Microsoft Update Catalog is Microsoft's public index of update packages. It lists cumulative updates, security updates, servicing stack updates, drivers and hotfixes, each as a downloadable file. Microsoft describes it as a listing of updates "that can be distributed over a corporate network."
It doesn't install anything. Windows Update, WSUS and Intune decide what a device needs and deliver it. The catalog hands you the same packages as files, so you decide where and when they go.
When to Use the Catalog Instead of Windows Update
For day-to-day patching, let your normal channel do the work. The catalog is the tool for the exceptions:
- Offline or restricted machines. DMZ servers, lab networks and air-gapped systems that can't reach Windows Update.
- A failing update. When a cumulative update keeps failing through Windows Update, installing the package by hand often shows a clearer error.
- One KB for a test ring. You want a single update on five pilot machines before it reaches everyone.
- Out-of-band fixes. Emergency updates that Microsoft publishes to the catalog but doesn't push to every channel.
- Image servicing. Adding the latest cumulative update to install.wim before you deploy it.
That first case is common enough that the catalog going down gets its own r/sysadmin thread. One admin patching DMZ servers by hand found search returning nothing for almost two hours:
If the catalog is part of your emergency plan, keep a local copy of the last few cumulative updates for the systems that depend on it.
How to Find the Right Update
Search by KB number. Type KB5048667 into the search box and you get every variant of that update: each Windows version, each architecture, sometimes each language. You can also search by product name, classification or, for drivers, the four-part hardware ID. Wrap a phrase in double quotes to match it exactly.
Read four columns before you click Download:
- Title. It names the Windows version and the architecture. "x64-based Systems" and "arm64-based Systems" are different files, and the wrong one fails with a "not applicable" error.
- Products. Windows 11 version 24H2 and 25H2 can share a package. Windows Server has its own.
- Classification. Security Updates, Updates, Critical Updates or Drivers.
- Last Updated. Microsoft sometimes re-releases a package. Take the newest.
Click the title to open the details page. It shows the package's supersedence, so you can see which older updates it replaces, plus the UpdateID you'll need for a WSUS import.
.msu vs .cab
The Download button gives you one or more .msu files. An .msu is a wrapper around one or more .cab files, plus the Windows Update metadata and an XML file describing the package.
| .msu | .cab | |
|---|---|---|
| What it is | Windows Update standalone package | The update payload itself |
| Install with | Double-click, wusa or DISM | DISM only |
| Remove with | DISM, by package name | DISM, by package name or path |
| WSUS import | No, use the UpdateID instead | No |
Keep the .msu unless a tool asks for a .cab. wusa.exe <file>.msu /extract:C:\cabs unpacks it when you need the inside.
How to Install an Update From the Catalog
On a single machine, double-clicking the .msu runs the Windows Update Standalone Installer. For anything scripted, use the command line.
With wusa:
codewusa.exe C:\updates\windows11.0-kb5048667-x64.msu /quiet /norestart
With DISM, which Microsoft's KB articles now use in their own install steps:
codeDISM /Online /Add-Package /PackagePath:C:\updates\windows11.0-kb5048667-x64.msu
DISM can add an .msu to a running system on Windows 11 version 21H2 and later. On older versions, it only takes an .msu for offline images. For a mounted image, swap /Online for /Image:C:\mount. The PowerShell equivalent is Add-WindowsPackage -Online -PackagePath.
Either way, plan a reboot. Our guide to DISM RestoreHealth covers what to run first if DISM reports component store corruption.
BrenTech's walkthrough shows the manual download and install from start to finish:
Checkpoint Cumulative Updates on Windows 11 24H2
Starting with Windows 11 version 24H2, Microsoft ships some cumulative updates as checkpoints. Later updates only contain the changes since the last checkpoint. That makes them smaller, but it adds a rule for catalog users: a device needs every earlier checkpoint before it can take the target update.
That's why the catalog's download window sometimes shows two .msu files for one KB. Microsoft's own example is the December 2024 update, KB5048667, which needs the September 2024 checkpoint, KB5043080, first. Windows Update and WSUS handle this for you. Manual installs don't.
You have two options. Install each .msu in order, oldest first. Or put the target .msu and its checkpoints in one folder, with nothing else in it, and point DISM at the target:
codeDISM /Online /Add-Package /PackagePath:C:\updates\windows11.0-kb5048667-x64.msu
DISM finds the checkpoints in that folder and applies the ones the device is missing, in the right order. Microsoft's page on checkpoint cumulative updates covers the image servicing cases, including when Features on Demand or language packs need every checkpoint regardless.
Importing Catalog Updates Into WSUS and Configuration Manager
WSUS can't import an .msu. The old Import Updates button in the WSUS console relied on ActiveX, and Microsoft replaced it with a PowerShell script. Copy the UpdateID from the catalog's details page, then run Microsoft's ImportUpdateToWSUS.ps1 against your WSUS server. The script calls ImportUpdateFromCatalogSite for each ID, and it accepts a text file with one UpdateID per line for bulk imports. Microsoft's WSUS import guide has the full script.
Configuration Manager uses the same route. Import into the WSUS server behind your top-level software update point, then run Synchronize Software Updates in the console. Child sites pick it up from there.
This matters when Microsoft ships out-of-band fixes. In September 2026, an r/SCCM admin found that some OOB updates arrived through WSUS sync while others had to be imported by hand:
Verifying and Rolling Back a Catalog Install
Check the install from the servicing stack's view first:
codeDISM /Online /Get-Packages /Format:Table
The package list shows each installed update with its state. Get-HotFix -Id KB5048667 is quicker to type, and it works against remote machines with -ComputerName. Microsoft notes it only returns updates from Component Based Servicing, so an empty result isn't always proof the update is missing.
Rolling back works differently than you might expect. Cumulative updates now ship combined with the servicing stack update, and Microsoft's KB articles state that wusa.exe /uninstall "will not work" on the combined package. Use DISM instead. Find the package name with /Get-Packages, then remove it:
codeDISM /Online /Remove-Package /PackageName:<package name from Get-Packages>
The servicing stack part stays behind. Microsoft doesn't allow removing it.
Checking five machines by hand is fine. For a whole client, OpenFrame can run the same DISM or Get-HotFix check as a script across a client's devices and collect the output in one place.
The Short Version
The Microsoft Update Catalog is where you get an update as a file when the normal channel can't or won't deliver it. Search by KB, match the Windows version and architecture, install with DISM, and on Windows 11 24H2 keep the checkpoints in the same folder. Import into WSUS by UpdateID, verify with DISM, and roll back with DISM too.
For the bigger picture, see how the tools compare in our guide to patch management software.
When you need to hold a patch back instead, here's how to stop Windows Update safely.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
