Patch Review Recommendations

Flexis July 2026 Patch Recommendation

Patches Microsoft released in July 2026

 

  • KB5099536: 2026-07 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems
  • KB5099540: 2026-07 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5099540)
  • KB5099538: 2026-07 Servicing Stack Update for Windows Server 2016 for x64-based Systems (KB5099542)
  • KB5099535: 2026-07 Cumulative Update for Windows Server 2016 for x64-based Systems

Get Help With Patching, Talk to a Patching Expert.

Microsoft-Windows

Microsoft Windows

Microsoft-Edge

Microsoft Edge

(HTML-based)

Microsoft-Edge

Microsoft Edge

 (Chromium-based)

Internet-Explorer

Internet Explorer

Microsoft-Office

Microsoft Office and Microsoft Office Services and Web Apps

Windows-Defenser

Windows Defender

Visual-Studio

Visual Studio

6

ASP.NET Core

Untitled design (1)

Chakra Core

Microsoft-Dynamics

Microsoft Dynamics

NET-Framework

.NET Framework

NET-Core

.NET Core

Please note the following information regarding the security updates:

Windows 10 Enterprise and Education and Windows 10 Home and Pro Lifecycle pages, Windows 10 was ended on October 14, 2025. The current version, 22H2, will be the final version of Windows 10. The following editions will remain in support with monthly security update releases through that date: 

Home

Pro

Pro Education

Pro for Workstations

Education

Enterprise

Enterprise multi-session

KB5099536: Windows Server 2025, all editions

Improvements 

This security update contains fixes and quality improvements from KB5094125 (released June 9, 2026). The following summary outlines key issues addressed by this update. Also included are available new features. The bold text within the brackets indicates the item or area of the change.  

  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5094125), these apps might fail to launch Office or open documents. 
  • [Containers] This update improves startup performance for Hyper-V–isolated Windows Server containers on Windows Server 2025. The updated Windows Server 2025 container base images (nanoserver, servercore, and windowsservercore) include this improvement and are available through the Microsoft Container Registry (MCR). Pull the latest image tag to get the update. 
  • [Cryptography] 
  • This update adds support for hybrid post-quantum cryptography (PQC) key exchange in Transport Layer Security (TLS) 1.3. This enhancement helps protect secure network connections against emerging threats and improves readiness for future security challenges. 
  • This update adds support for composite cryptographic formats that combine traditional and post-quantum algorithms in a single signature or key. 
  • [Distributed Key Manager (DKM)] This update introduces automatic detection of insecure DKM container ACL configurations in AD FS and provides an opt-in remediation mechanism to help administrators strengthen DKM container permissions. For more information about how to manage this change, see CVE-2026-56155: AD FS Distributed Key Manager container ACL hardening 
  • [Event Log] This update improves the reliability of the Windows Event Log service on event collector servers that forward events to custom log channels configured with a manifest. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode.This issue might occur after installing the June 2026 security update (KB5094125). 
  • [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub. 
  • [Networking] 
  • This update improves how your device connects to shared network resources. Connections used by apps and system features, such as the NetUseAdd function, now work more reliably, including unauthenticated (null session) connections. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. This issue might occur after installing the June 2026 security update (KB5094125). 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption. 
  • [System reliability] 
  • This update improves system reliability by addressing an issue that could cause Windows to stop responding in certain situations. 
  • This update improves performance for virtual machines running graphics-intensive applications by resolving a memory leak in the graphics kernel driver. It also reduces excessive memory usage and helps maintain consistent sign-in access. 

 

 

Known issues in this update 

Windows Server Update Services (WSUS) does not display error details 

  1. After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287. 

KB5099540: Windows Server 2022

Improvements 

This security update contains fixes and quality improvements from KB5094128 (released June 9, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change. 

  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [Apps (Known issue)] Fixed: This update addresses an issue that affects certain third-party apps that use OLE Automation to interact with Microsoft Office. After installing the June 2026 security update (KB5094128), these apps might fail to launch Office or open documents. 
  • [Authentication] This update improves Microsoft Defender for Identity (MDI) unified sensor auditing for NT LAN Manager (NTLM) authentication. It captures more NTLM-based authentication events, helping you better detect identity-related threats. 
  • [Distributed Key Manager (DKM)] This update introduces automatic detection of insecure DKM container ACL configurations in AD FS and provides an opt-in remediation mechanism to help administrators strengthen DKM container permissions. For more information about how to manage this change, see CVE-2026-56155: AD FS Distributed Key Manager container ACL hardening. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode. This issue might occur after installing the June 2026 security update (KB5094128). 
  • [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub. 
  • [Networking] 
  • This update improves reliability in Windows Failover Cluster environments that use cluster virtual IP addresses. It ensures the SkipAsSource setting for cluster IPs is configured correctly, which improves DNS record accuracy and network communication connectivity. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. This issue might occur after installing the June 2026 security update (KB5094128). 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption. 

 

Known issues in this update 

Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key 

 

Symptom 

Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. 

This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. 

  1. BitLocker is enabled on the OS drive.
  2. The Group Policy “Configure TPM platform validation profile for native UEFI firmware configurations” is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually).
  3. System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as “Not Possible”.
  4. The Windows UEFI CA 2023 certificate is present in the device’s Secure Boot Signature Database (DB), making the device eligible for the 2023signed Windows Boot Manager to be made the default.
  5. The device is not already running the 2023-signed Windows Boot Manager.
     

In this scenario, the BitLocker recovery key only needs to be entered once — subsequent restarts will not trigger a BitLocker recovery screen, as long as the group policy configuration remains unchanged. For help finding your BitLocker recovery key, see the article, Find your BitLocker recovery key. 

Enterprises are recommended to audit their BitLocker group policies for explicit PCR7 inclusion and check msinfo32.exe for their PCR7 binding status before installing this update. (See the Workaround below.) 

Workaround 

Remove the Group Policy configuration before installing the update (Recommended)  

  1. Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console.
  2. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives.
  3. Set “Configure TPM platform validation profile for native UEFI firmware configurations” to “Not Configured”.
  4. Run the following command on affected devices to propagate the policy change: gpupdate /force
  5. Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C:
  6. Run the following command to resume BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -enable C:
  7. This updates the BitLocker bindings to use the Windows-selected default PCR profile. 

A permanent resolution for this issue is planned in a future Windows update. More information will be provided when it is available. 

 

Windows Server Update Services (WSUS) does not display error details 

After installing KB5070884 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287. 

KB5099538: Windows Server 2019 Win 10 Ent LTSC 2019

Windows Secure Boot certificate expiration  

Important: Secure Boot certificates used by most Windows devices were set to expire starting in June 2026. Microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months. 

 

Windows Server 2019 

Applies to: Windows Server 2019 

This security update includes fixes and quality improvements that are part of the following update: 

The following is a summary of the issues that this update addresses when you install this update. The bold text within the brackets indicates the item or area of the change we are documenting. 

  • [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub. 
  • [Secure Boot] 
  • This update enables dynamic status reporting for Secure Boot states in Windows Security App. 
  • This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode. 
  • [OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is handled and restores expected application behavior. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. 
  • [Authentication] This update improves auditing for NT LAN Manager (NTLM) authentication by enhancing logging to provide more detailed information for security monitoring and analysis. 
  • [Distributed Key Manager (DKM)] This update introduces automatic detection of insecure DKM container ACL configurations in AD FS and provides an opt-in remediation mechanism to help administrators strengthen DKM container permissions. For more information about how to manage this change, see CVE-2026-56155: AD FS Distributed Key Manager container ACL hardening. 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption. 

 

Windows 10, Version 1809 

 

Applies to: Windows 10 Enterprise LTSC 2019 

This security update includes fixes and quality improvements that are part of the following update: 

The following is a summary of the issues that this update addresses when you install this update. The bold text within the brackets indicates the item or area of the change we are documenting. 

  • [Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub. 
  • [Secure Boot] 
  • This update enables dynamic status reporting for Secure Boot states in Windows Security App. 
  • This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode. 
  • [OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is handled and restores expected application behavior. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption. 

Known issues in this update 

We are currently not aware of any issues with this update. 

KB5099535: Windows Server 2016, all editions Win 10 Ent LTSB 2016 Win 10 IoT Ent LTSB 2016

Windows Secure Boot certificate expiration 

Important Secure Boot certificates used by most Windows devices were set to expire starting in June 2026. Microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that haven’t received the newer certificates will continue to start, and standard Windows updates will continue to be installed. We will continue to install the newer certificates via Windows updates in the coming months. 

 

Summary 

Windows Server 2016 

Applies to: Windows Server 2016 

  • This security update includes fixes and improvements that are a part of the following update: 
  • The following is a summary of the issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting. 
  • [OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. 
  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [Distributed Key Manager (DKM)] This update introduces automatic detection of insecure DKM container ACL configurations in AD FS and provides an opt-in remediation mechanism to help administrators strengthen DKM container permissions. For more information about how to manage this change, see CVE-2026-56155: AD FS Distributed Key Manager container ACL hardening. 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption. 

 

 

Windows 10 Version 1607 

Applies to: Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB 

This security update includes fixes and improvements that are a part of the following update: 

The following is a summary of the issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting. 

  • [OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior. 
  • [File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode. 
  • [Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. 
  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months. 
  • [Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.