Fix it now
ESET’s own wording for this is “Undocumented serious error (0x1106)”, and that is literal: ESET publishes no meaning for the number. What it does publish is an ordered troubleshooting sequence for a failed module update, and the first step is to upgrade to the current version of the product.
- Open Help and support, then About, note the version, and install the current build of your ESET product over the top if you are behind.
- Check free space. ESET asks for at least 1 GB free on the drive the product is installed on.
- Confirm the subscription is valid and not expired. An update will fail if the product is not activated by an activation key.
- Clear the update cache: press F5 for Advanced setup, open Updates, choose Clear, then OK, and restart the computer.
- Remove any previously installed antivirus, and exclude ESET from any third-party firewall that is running.
- Turn the proxy off for updates: Advanced setup, Updates, Profiles, Updates, Connection options, then Do not use proxy server.
- Test the path with
ping update.eset.comin a Command Prompt, then run Update from the main window and read what it returns.
ESET’s sequence expects you to re-check for a successful update after each step rather than doing all of them and hoping. Stop at the first one that works.
If modules download and the detection engine date moves, you are done. If not, the next section explains what an update actually consists of and where it can stall.
Why it happens
An ESET module update is not one file. The product fetches signed components – the detection engine, scanner modules, the cleaner – and applies them to what is already on disk. The interface reports the outcome as a single line, which is why a transport problem, a disk problem and an expired subscription all arrive looking identical.
0x1106 and 0x101a are the two numbers people see most often against that line, and ESET’s message for both literally says “Undocumented serious error”. That is not a translation quirk. ESET’s published troubleshooting for the modules-update failure does not name either number, so any page that tells you 0x1106 specifically means an end-of-life build, a broken certificate chain or a retired endpoint is inventing a meaning. Work the documented sequence instead, which is short and gets there.
The one companion code with a published meaning is 12038, and it is worth recognising because it changes what you do. Microsoft publishes it as ERROR_INTERNET_SEC_CERT_CN_INVALID: the SSL certificate’s common name does not match the host that was asked for. On a filtered corporate network that is the fingerprint of an appliance re-signing traffic in the middle, and no amount of cache clearing on the client will move it.
The build is behind
You have this one if Help and support, then About shows a version several releases old, and the update has failed since a date on which nothing on the machine changed.
- Download the current installer for your ESET product from ESET’s own site rather than reusing an old copy.
- Run it and let it upgrade in place; the existing subscription and settings are carried over.
- Reboot, then run Update and confirm the modules download.
- Check Help and support, then About afterwards to confirm the version actually changed.
This is step one of ESET’s own sequence, not a last resort. It is also the step people skip because it feels like a bigger change than clearing a cache.
There is not enough room to apply the update
You have this one if The system drive is nearly full, or the machine has been warning about space, and the failure repeats instantly on every retry.
- Free space until there is at least 1 GB available on the drive ESET is installed on.
- Clear the update cache from Advanced setup, Updates, Clear, then OK.
- Restart and run Update again.
The subscription is not actually active
You have this one if Updates started failing around the time a subscription anniversary passed, and the main window has an activation or subscription notice you have been ignoring.
- Read the subscription state in Help and support and confirm the validity date is in the future.
- Renew or re-enter the key if it has lapsed, then run Update.
- Remember that ESET states updates fail where the product is not activated by an activation key, so this is a genuine cause rather than a coincidence.
A proxy or another security product is in the way
You have this one if Updates fail on one network and work on another, or a second antivirus or third-party firewall is installed.
- Remove any previously installed antivirus rather than just disabling it.
- In a third-party firewall, exclude ESET from detection. Skip this if you are using ESET’s own firewall.
- Set Advanced setup, Updates, Profiles, Updates, Connection options to Do not use proxy server and retry.
- Where the network genuinely requires a proxy, put the correct proxy in rather than leaving the default.
If you see 12038 alongside the ESET code, the certificate presented did not match the host requested. That is a TLS-inspecting appliance, and the fix belongs to whoever runs it.
The installation itself is damaged
You have this one if Every documented step has been worked through and the failure survives a cache clear, an upgrade and a reboot.
- Uninstall and reinstall the ESET application following ESET’s own procedure for home or business products.
- Activate with your existing key and let the first update run to completion without interruption.
- Scan the machine for malware afterwards, which is the last step in ESET’s published sequence.
Full reference
ESET’s documented order of checks
This is the sequence ESET publishes for the modules-update failure, in its order. The order matters: several of the steps are quick and rule out the expensive ones.
| # | Step | Why it is where it is |
|---|---|---|
| 1 | Upgrade to the latest version of the ESET application | Costs nothing with an active subscription and clears a whole class of failure |
| 2 | Confirm at least 1 GB free on the drive ESET is installed on | An update that cannot write has nowhere to go |
| 3 | Verify the subscription is valid and not expired | Updates fail where the product is not activated by a key |
| 4 | Clear the update cache | Removes a half-applied download that every retry then trips over |
| 5 | Remove previously installed antivirus software | A second product’s driver blocks the update path |
| 6 | Exclude ESET from a third-party firewall | Not needed where you are using ESET’s own firewall |
| 7 | Disable the proxy for updates | Advanced setup, Updates, Profiles, Updates, Connection options |
| 8 | Ping update.eset.com | Confirms the machine can reach ESET’s update servers at all |
| 9 | Uninstall and reinstall the application | Separate procedures for home and small office and for business |
| 10 | Clean the computer of malware | Last, because it is the least likely and the most disruptive |
Clearing the update cache without guessing
- Press F5 in the ESET main window to open Advanced setup.
- Open Updates.
- Choose Clear, then OK.
- Restart the computer.
- Run a manual update check from the main window and read the result.
ESET publishes the same cache-clear sequence for the General Compiler Error message that can appear after a version upgrade. If you have both messages, you have one cause.
Reading the companion codes
| Code | Where it comes from | What it tells you |
|---|---|---|
0x1106 |
ESET | Nothing published. The message text is literally “Undocumented serious error” |
0x101a |
ESET | Same family, same wording, no published meaning |
20005 |
ESET | No published meaning; treat as another form of the update failure |
12038 |
Windows internet layer | The SSL certificate common name did not match the host requested |
The asymmetry there is the useful part. Three of the four numbers tell you nothing you can act on, and the fourth tells you exactly where to look. If 12038 appears, stop working on ESET and start working on the network path, because the client is being handed a certificate for a host it did not ask for.
What an out-of-date detection engine actually costs you
The product keeps working with the modules it already has, so the interface can look healthy while the engine ages. That is worth being precise about rather than dramatic: existing detections still fire, and anything relying on cloud lookups still works while the machine is online. What stops is the arrival of new local detection. The gap widens every day the update fails, which makes this a job for this week rather than this hour, but it is a job.
A custom update server that no longer exists
Machines set up in an office that once ran a local mirror can still be pointed at it. Check Advanced setup, Updates for a custom update server, and set it back to the automatic choice unless you know the mirror is still running. This is not in ESET’s published sequence because it is not common, but it produces a permanent, repeating failure that survives every other step, and it takes ten seconds to rule out.
Ruling out the cheap causes first
- Confirm the failure survives a reboot. A single failed update after a sleep or a dropped connection is not a fault.
- Confirm it survives a cache clear, because that is the cheapest real fix.
- Try the machine on a different network before blaming the build. Hotel, guest and heavily filtered networks produce this reliably.
- Check the clock and time zone. Certificate validation depends on the time being roughly right, and a machine that has been off for a year will fail every secure connection it attempts.
- Read the subscription date. An expired subscription is the most common cause that looks like a technical fault.
When a licence is the actual fix
Upgrading to the current build is included with an active subscription, so if that is what fixes it you owe nothing. The case where money is genuinely involved is narrower: the build is old because the subscription lapsed some time ago and the product has been coasting on the modules it had. There the upgrade will install and then refuse to activate, and you need a current ESET Internet Security subscription before updates resume. Arco can check what your existing subscription covers and price a renewal against it rather than selling you a new one, and we would rather tell you the upgrade is free than take an order you do not need to place.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x1106 |
Shown by ESET against a failed module update. ESET’s own message text describes it as an undocumented serious error and no ESET page publishes a meaning for the number | not published by the vendor |
0x101a |
The same undocumented serious error wording against the same update failure; no published meaning | not published by the vendor |
20005 |
Another identifier seen against a failed ESET update. No ESET knowledgebase page publishes a meaning for it | not published by the vendor |
12038 |
ERROR_INTERNET_SEC_CERT_CN_INVALID: the SSL certificate common name is incorrect for the host that was requested, which is what an intercepting proxy looks like from the client | Microsoft Learn |
Confirm the fix worked
- Update from the ESET main window reports the modules as updated rather than failing.
- Help and support, then About shows a current detection engine version and date.
- The product version shown matches the build you installed.
ping update.eset.comreturns replies from the machine that was failing.- Reboot and run Update once more, so you know it works unattended rather than only after a cache clear.
Questions people ask about this
What does 0x1106 actually mean?
Nothing that ESET publishes. The message ESET shows alongside it says “Undocumented serious error”, and neither ESET’s modules-update troubleshooting article nor its update-errors article gives the number a meaning. Anyone who tells you it specifically means an end-of-life build is filling in a blank.
Is the machine unprotected while updates fail?
Not unprotected, but increasingly out of date. The engine keeps working with the modules it already has. What stops is the arrival of new local detection, and that gap grows every day.
Does upgrading ESET cost anything?
Not with an active subscription. Version upgrades within your entitlement are included and the installer carries the subscription and settings across. You only pay if the subscription itself has expired.
Will I lose my exclusions if I upgrade in place?
An in-place upgrade normally keeps them. Note them anyway before you start, because the reinstall further down ESET’s list will not, and you may end up doing that instead.
I only see 12038, not the ESET code. Is that different?
Yes, and it is more useful. 12038 is a Windows internet-layer error meaning the certificate presented did not match the host requested. That points at TLS inspection on the network rather than at anything on the machine, and the fix belongs to whoever runs the gateway.
