KB5099536: Overview with user sentiment and feedback
Last Updated August 18, 2026
Probability of successful installation and continued operation of the machine
Overview
KB5099536 is a cumulative security update for Windows Server 2025 released on July 14, 2026 (OS Build 26100.33158). This update incorporates the latest security fixes and quality improvements from the June 2026 preview release, along with addressing critical infrastructure issues including Secure Boot certificate expiration concerns. The update applies to all editions of Windows Server 2025.
General Purpose
- Secure Boot Certificate Management: Expands device targeting for automatic delivery of updated Secure Boot certificates to prevent startup issues when current certificates expire in June 2026
- Security Hardening: Introduces post-quantum cryptography support in TLS 1.3, strengthens AD FS Distributed Key Manager (DKM) container ACL configurations, and enhances RDP security with SHA-2 certificate thumbprint support
- Performance Improvements: Resolves graphics kernel driver memory leak affecting virtual machines, improves container startup performance for Hyper-V-isolated Windows Server containers, and enhances Event Log reliability
- Application Compatibility: Fixes OLE Automation issues affecting third-party Office integration, resolves File Explorer OneDrive shortcut failures, and corrects Recycle Bin file name display problems
- Network Reliability: Improves shared network resource connections and null session connectivity while enforcing TDI transport registration requirements
General Sentiment
The update addresses critical infrastructure concerns, particularly the imminent Secure Boot certificate expiration, which demonstrates proactive maintenance planning. The inclusion of post-quantum cryptography and security hardening improvements reflects Microsoft's commitment to forward-looking security. However, the update introduces behavioral changes that may require administrator attention, particularly regarding third-party TDI transport compatibility and hotkey handling. The networking security hardening change and input system modifications could potentially impact legacy applications and user experience in specific scenarios.
Known Issues
- Windows Server Update Services (WSUS) does not display synchronization error details after installing KB5070881 or later updates (temporarily removed to address CVE-2025-59287)
- Third-party applications using unregistered TDI transports may stop working due to enforced transport registration requirements
- Built-in Windows experiences relying on previous hotkey lifecycle behavior may temporarily stop responding to certain keyboard shortcuts in rare cases
- Input handling changes may require application restarts to resolve keyboard shortcut responsiveness issues
Disclaimer: We take measures to ensure that AI-generated content is of the highest possible quality, but we cannot guarantee its accuracy and recommend that users do their own independent research. Generated on 2026-08-18 07:26 PM