KB5120709: Overview with user sentiment and feedback

Last Updated September 23, 2026

Probability of successful installation and continued operation of the machine

0%
20%
40%
60%
80%
100%
60%
Known Issues

Overview

KB5120709 is a cumulative security and reliability update for .NET Framework 3.5 and 4.8.1 released on August 11, 2026, targeting Windows 10 Version 21H2 and Version 22H2. This patch addresses multiple critical vulnerabilities including elevation of privilege and remote code execution flaws within the .NET Framework components. The update is recommended as part of regular maintenance routines to maintain system security and stability.

General Purpose

  • Addresses six critical security vulnerabilities including CVE-2026-65810 and CVE-2026-62872 (elevation of privilege), CVE-2026-62886, CVE-2026-62897, and CVE-2026-70354 (remote code execution), and CVE-2026-62902 (information disclosure)
  • Provides cumulative reliability improvements for .NET Framework 3.5 and 4.8.1
  • Introduces enhanced security protections for font handling and XPS package boundary restrictions in WPF applications
  • Requires system restart and closure of .NET Framework-based applications prior to installation

General Sentiment

This patch addresses significant security vulnerabilities and is officially recommended by Microsoft for regular deployment. However, the update introduces two documented compatibility issues affecting WPF applications that handle fonts and XPS documents, requiring workarounds or configuration changes for affected users. Microsoft has confirmed one issue is resolved in subsequent updates, indicating active remediation efforts.

Known Issues

  • WPF applications may fail with System.IO.FileFormatException when printing or generating PDF/XPS content using certain fonts including Calibri; workaround available via AppContext switch (resolved in September 2026 update)
  • WPF applications printing or displaying print preview from in-memory XPS documents registered with System.IO.Packaging.PackageStore may fail with System.IO.FileFormatException when using pack scheme URIs; workaround available via AppContext switch or package identity modification (status: investigating)

Disclaimer: We take measures to ensure that AI-generated content is of the highest possible quality, but we cannot guarantee its accuracy and recommend that users do their own independent research. Generated on 2026-09-23 01:47 PM

Back to Knowledge Base Catalog