KB5099540: Overview with user sentiment and feedback
Last Updated August 6, 2026
Probability of successful installation and continued operation of the machine
Overview
KB5099540 is the July 14, 2026 cumulative security update for Windows Server 2022 (OS Build 20348.5386). This combined Servicing Stack Update (SSU) and Latest Cumulative Update (LCU) package incorporates the latest security fixes and quality improvements from the June 2026 preview release. The update addresses multiple security vulnerabilities and introduces enhancements across authentication, networking, Remote Desktop security, and system hardening.
General Purpose
- Secure Boot Certificate Management: Expands device targeting for automatic Secure Boot certificate deployment, addressing expiration concerns beginning June 2026
- Security Hardening: Enforces TDI transport registration requirements and strengthens AD FS Distributed Key Manager (DKM) container ACL configurations
- Authentication & Identity: Enhances Microsoft Defender for Identity (MDI) unified sensor auditing for NTLM authentication with improved threat detection capabilities
- Remote Desktop Security: Adds SHA-2 certificate thumbprint support for trusted RDP publishers while maintaining SHA-1 backward compatibility
- Networking & Clustering: Improves reliability in Windows Failover Cluster environments and ensures proper SkipAsSource configuration for cluster virtual IP addresses
- Bug Fixes: Resolves issues affecting third-party Office automation apps, File Explorer OneDrive shortcuts, Recycle Bin file naming, and hotkey lifecycle behavior
General Sentiment
The update addresses critical security concerns, particularly the Secure Boot certificate expiration issue affecting most Windows devices. Community feedback indicates appreciation for the comprehensive security improvements and bug fixes from the previous June release. However, some users report confusion regarding combined SSU/LCU package installation behavior, where only the SSU appears in the installed updates list despite successful LCU application. The update introduces a breaking change for third-party TDI transports, which may affect legacy applications, though registered transports remain unaffected. Overall, the patch is viewed as necessary for security compliance, though administrators should review compatibility with custom networking solutions.
Known Issues
- Devices with unrecommended BitLocker Group Policy configurations (specifically PCR7 inclusion in TPM validation profiles) may require BitLocker recovery key entry on first restart; recovery key needed only once if group policy remains unchanged
- Windows Server Update Services (WSUS) does not display synchronization error details after installing KB5070884 or later updates; functionality temporarily removed to address CVE-2025-59287
- Applications using unregistered third-party TDI transports will stop working due to enforced TDI transport registration requirements; registered transports are unaffected
- In rare cases, built-in Windows experiences relying on previous hotkey lifecycle behavior may temporarily stop responding to certain keyboard shortcuts; typically resolved by restarting the affected application
- Combined SSU+LCU package may only display SSU (KB5120210) in installed updates list while LCU (KB5099540) remains hidden; this is a WMI display limitation and does not indicate installation failure; OS Build Revision (UBR) remains the authoritative verification method
Disclaimer: We take measures to ensure that AI-generated content is of the highest possible quality, but we cannot guarantee its accuracy and recommend that users do their own independent research. Generated on 2026-08-06 01:14 PM