Views
8

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

Update Summary

KB5099540 for Windows Server 2022 (OS Build 20348.5386) includes July 2026 security fixes, quality improvements from KB5094128, and servicing stack update KB5120210. It also adds Secure Boot certificate targeting, NTLM auditing improvements, RDP SHA-2 thumbprint support, and AD FS DKM ACL hardening. Reference IDs: CVE-2026-56155, CVE-2025-59287.

Update Details

Security

  • Adds additional high-confidence device targeting data to expand automatic delivery of new Secure Boot certificates.
  • Improves Microsoft Defender for Identity unified sensor auditing for NTLM authentication to better detect identity-related threats.
  • Introduces automatic detection of insecure AD FS Distributed Key Manager (DKM) container ACL configurations with opt-in remediation.
  • Adds security hardening that enforces TDI transport registration requirements; apps using sockets over unregistered third-party TDI transports might stop working.
  • Remote Desktop (RDP) trusted publisher support now prefers SHA-2 certificate thumbprints; SHA-1 remains only for backward compatibility and is planned for removal.
  • Includes security fixes referenced by the July 2026 Security Updates.

Bug Fixes

  • Fixes third-party apps using OLE Automation with Microsoft Office that might fail to launch Office or open documents after KB5094128.
  • Fixes File Explorer OneDrive shortcut failures when File Explorer is run in administrative mode after KB5094128.
  • Fixes Recycle Bin confirmation dialogs that might show an internal file name instead of the original file name when permanently deleting a file.
  • Improves reliability in Windows Failover Cluster environments using cluster virtual IP addresses by correcting SkipAsSource configuration for better DNS accuracy and connectivity.
  • Updates hotkey unregister and cleanup behavior for built-in Windows experiences that rely on previous hotkey lifecycle behavior.

New Features

  • Introduces automatic detection of insecure AD FS DKM container ACL configurations with opt-in remediation.
  • Adds support for SHA-2 certificate thumbprints for trusted RDP publishers and provides new Group Policy guidance for controlling which .rdp files users can open.

Known Issues

  • Some devices with an unrecommended BitLocker Group Policy configuration might prompt for the BitLocker recovery key on the first restart after installing this update.
  • WSUS does not display synchronization error details after installing KB5070884 or later updates because the functionality was temporarily removed.

Hints

  • This cumulative update includes the latest security fixes and non-security updates from the previous month's optional preview release.
  • Administrators should review BitLocker Group Policy settings before installing if PCR7 is explicitly included in the validation profile.
  • Recommended BitLocker workaround: set the TPM platform validation profile policy to Not Configured, run gpupdate /force, then suspend and resume BitLocker protectors on the OS drive.
  • For RDP security, Microsoft recommends migrating trusted publisher thumbprints to SHA-256 or a stronger algorithm as soon as possible.
  • The servicing stack update KB5120210 improves the component that installs Windows updates.

Links

Product Information

Vendor: Microsoft

Product: Windows Server 2022

Product type: Other

Application category: Utilities

Platform: Windows

Version: OS Build 20348.5386

Vendor release date: Jul 14, 2026

Published on updatealert.io: Jul 16, 2026

Description: Server operating system for on-premises and hybrid workloads.