Welcome to Microsoft Q&A!
Thank you for the detailed information about your environment and the troubleshooting you have already performed.
Based on your description, since the updates remain Pending download on multiple PCs even after restarting the Windows Update and BITS services, rebuilding the SoftwareDistribution folder, and successfully completing DISM and SFC, I would recommend looking beyond the local Windows Update cache.
Since multiple devices are affected, it would be helpful to check whether they share the same Windows Update source, policy, or network configuration.
1. Check whether the PCs are managed by WSUS, Group Policy, or MDM/Intune
If these are organization-managed devices, verify which update source they are configured to use. Windows Update policies can affect update behavior or direct devices to an internal WSUS server.
On an affected PC, you can review:
Settings > Windows Update > Advanced options > Configured update policies
If possible, compare the configured policies with a Windows 11 device that is downloading updates normally.
If WSUS is being used, also verify that the affected updates are approved and available on the WSUS server and that the clients can communicate with the server successfully.
2. Review the Windows Update log
Since Windows detects the updates but does not begin downloading them, reviewing the Windows Update log may provide more useful information than resetting the SoftwareDistribution folder again.
Open an elevated PowerShell window and run:
Get-WindowsUpdateLog
Then review the generated WindowsUpdate.log for errors around the time the download was attempted. This may help identify whether the problem is related to connectivity, DNS, proxy, firewall, or another Windows Update component.
3. Check the proxy, firewall, VPN, and network configuration
Because the same behavior is occurring on several PCs, check whether the affected devices share the same corporate network, VPN, proxy, firewall, or security configuration.
If permitted by your organization's security policies, one useful isolation test is to connect one affected device through a different network path without the corporate VPN or proxy and check Windows Update again.
If the updates begin downloading normally, this will indicate that the shared network path or configuration should be investigated further.
4. Check for a Windows Update error code
In addition to WindowsUpdate.log, I recommend checking:
Event Viewer > Applications and Services Logs > Microsoft > Windows > WindowsUpdateClient > Operational
Look for warnings or errors generated when you check for updates or when Windows attempts to start the download.
If an error code is recorded, it can help narrow down the cause of the issue considerably.
At this stage, I would not assume that a particular recent KB is responsible unless all affected devices are failing to download the same KB and there is a documented known issue associated with that update.
References:
Deploy updates using Windows Server Update Services | Microsoft Learn
Configure Windows Update client policies via Group Policy | Microsoft Learn
Configure Windows Update client policies | Microsoft Learn
If you find it useful, please click Accept Answer.
Thank you for choosing Microsoft Q&A.