KB5099536: Overview with user sentiment and feedback

Last Updated August 14, 2026

Probability of successful installation and continued operation of the machine

0%
20%
40%
60%
80%
100%
60%
Known Issues

Overview

KB5099536 is a cumulative security update for Windows Server 2025 released on July 14, 2026 (OS Build 26100.33158). This update delivers the latest security patches and quality improvements, incorporating fixes from the June 2026 preview release. It addresses critical infrastructure concerns including Secure Boot certificate expiration management and includes a servicing stack update (KB5101372) to ensure reliable update installation.

General Purpose

  • Secure Boot Certificate Management: Expands device targeting for automatic deployment of updated Secure Boot certificates to address June 2026 expiration timeline
  • Security Hardening: Introduces post-quantum cryptography support in TLS 1.3, strengthens RDP certificate validation with SHA-2 migration, and hardens AD FS Distributed Key Manager container permissions
  • Container Performance: Improves Hyper-V-isolated Windows Server container startup performance with updated base images
  • System Reliability: Resolves graphics kernel memory leaks affecting virtual machines and addresses potential system unresponsiveness issues
  • Network Connectivity: Enhances reliability of network resource connections and implements TDI transport registration enforcement
  • Application Compatibility: Fixes OLE Automation issues affecting third-party Office integration and File Explorer OneDrive shortcut functionality

General Sentiment

This update addresses significant infrastructure concerns, particularly the impending Secure Boot certificate expiration. The inclusion of post-quantum cryptography support and enhanced security hardening demonstrates Microsoft's forward-looking security posture. However, the update introduces behavioral changes that may impact compatibility: third-party applications using unregistered TDI transports will require remediation, and input hotkey handling changes could temporarily affect keyboard shortcuts in some applications. The WSUS error reporting limitation is a notable trade-off for addressing a critical vulnerability.

Known Issues

  • Windows Server Update Services (WSUS) does not display synchronization error details after installing this update (temporary removal to address CVE-2025-59287 Remote Code Execution vulnerability)
  • Applications using unregistered third-party TDI transports may stop working due to new TDI transport registration enforcement
  • Some built-in Windows experiences may temporarily stop responding to certain keyboard shortcuts due to hotkey lifecycle behavior changes; restarting affected applications typically resolves the issue
  • Third-party applications using OLE Automation with Microsoft Office may fail after June 2026 security update (KB5094125) - this update includes a fix for this issue

Disclaimer: We take measures to ensure that AI-generated content is of the highest possible quality, but we cannot guarantee its accuracy and recommend that users do their own independent research. Generated on 2026-08-14 01:16 PM

Back to Knowledge Base Catalog