Patch Review Recommendations

Flexis February 2026 Patch Recommendation

Patches Microsoft released in February 2026

 

  • KB5075899: – 2026-02 Cumulative Update for Microsoft server operating system 24H2 for x64-based System 
  • KB5075906: – 2026-02 Cumulative Update for Microsoft server operating system 21H2 for x64-based Systems 
  • KB50759042026-02 Cumulative Update for Windows Server 2019 for x64-based Systems 
  • KB5075999: – 2026-02 Cumulative Update for Windows Server 2016 for x64-based Systems 

Get Help With Patching, Talk to a Patching Expert.

Impacted Products:

Microsoft-Windows

Microsoft Windows

Microsoft-Edge

Microsoft Edge

(HTML-based)

Microsoft-Edge

Microsoft Edge

 (Chromium-based)

Internet-Explorer

Internet Explorer

Microsoft-Office

Microsoft Office and Microsoft Office Services and Web Apps

Windows-Defenser

Windows Defender

Visual-Studio

Visual Studio

6

ASP.NET Core

Untitled design (1)

Chakra Core

Microsoft-Dynamics

Microsoft Dynamics

NET-Framework

.NET Framework

NET-Core

.NET Core

Please note the following information regarding the security updates:

Windows 10 Enterprise and Education and Windows 10 Home and Pro Lifecycle pages, Windows 10 was ended on October 14, 2025. The current version, 22H2, will be the final version of Windows 10. The following editions will remain in support with monthly security update releases through that date: 

Home

Pro

Pro Education

Pro for Workstations

Education

Enterprise

Enterprise multi-session

KB5075899: Windows Server 2025, all editions

Improvements

This security update contains fixes and quality improvements from KB5073379 (released January 13, 2026), KB5077793 (released January 17, 2026), and KB5078135 (released January 24, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change. ​​​​ 

  • [File Explorer] Fixed: This update addresses an issue where folder renaming with desktop.ini files in File Explorer isn’t work correctly. The LocalizedResourceName setting is ignored, so custom folder names don’t appear. 
  • [Fonts & Display] Updates the Chinese fonts to support the GB180302022A standard for character coverage and display. 
  • [Graphics] Fixed: This update addresses an issue where certain GPU configurations might recently have experienced a system error related to dxgmms2.sys, resulting in the KERNEL_SECURITY_CHECK_FAILURE error. 
  • [Performance & Reliability] Fixed: This update disables the forwarded I/O feature in the NVMe stack by default. 
  • [Networking] 
  • ​​​New!DNS over HTTPS (DoH) support for Windows DNS Server is now available in public preview. This preview enables evaluation of DoH for traffic between the server and its clients. This is intended for feedback only. It isn’t supported for production use, and it might contain issues. Functionality might also change, including potential breaking changes, before General Availability (GA).  You can read more about this preview in the DoH on Windows DNS Server blog. 
  • New! Windows Server now supports random shuffling of resource records in DNS Server responses. This helps reduce scenarios where a single resource record becomes overloaded because it appears first in the returned list. 

 

To enable, create a DWORD registry key named “RandomShuffle” at: 

Registry Key: Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters 

Data to be set: 1 
 

To disable or erase the key: 

Date to be set to: 0​​​​​​​  

 

Known issues in this update  

After installing  KB5070881  or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.  

KB5075906: Windows Server 2022

This security update contains fixes and quality improvements from KB5073457 (released January13, 2026), KB5077800 (released January 17, 2026), and KB5078136 (released January 24, 2026). The following summary outlines key issues addressed by this update. Also, included are available new features. The bold text within the brackets indicates the item or area of the change. 

  • [File Explorer] Fixed: This update addresses an issue where folder renaming with desktop.ini files in File Explorer isn’t work correctly. The LocalizedResourceName setting is ignored, so custom folder names don’t appear. 
  • [Fonts & Display] Updates the Chinese fonts to support the GB180302022A standard for character coverage and display.  ​​​​​​​ 
  • [Graphics] Fixed: This update addresses an issue where certain GPU configurations might recently have experienced a system error related to dxgmms2.sys, resulting in the KERNEL_SECURITY_CHECK_FAILURE error. 
  • [OS Security (known issue)] Fixed: After installing the Windows security update released on or after January 13, 2026, some PCs which run Virtual Secure Mode (VSM) are unable to shut down or enter hibernation. Instead, the device restarts. 
  • [Networking]New! Windows Server now supports random shuffling of resource records in DNS Server responses. This helps reduce scenarios where a single resource record becomes overloaded because it appears first in the returned list. 

To enable, create a DWORD registry key named “RandomShuffle” at: 

Registry Key: Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters 

Data to be set: 1 
 

To disable or erase the key: 

Data to be set to: 0​​​​​​​ 

 

Known issues in this update  

After installing KB5070884 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting. This functionality is temporarily removed to address the Remote Code Execution Vulnerability, CVE-2025-59287.  

KB5075904 - Windows Server 2016, all editions Win 10 Ent LTSB 2016

Windows Secure Boot certificate expiration  

Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates. 

Known issues in this update 

 

Symptoms 

After installing this update released on or after January 13, 2026, Japanese language installations of Windows Server 2019 might not correctly display Japanese characters in the PowerShell console. 

This issue is caused by an unintended change to PowerShell encoding settings, which are incorrectly set to UTF-8 following the installation of the update. English language text can appear correctly, and commands can be entered as usual. However, Japanese output text appears garbled, or with the appearance of question marks where Japanese text is intended to be shown. Japanese text which is entered into PowerShell will also be affected in the same way. 

 

Workaround 

There are two methods to address this issue: 

 

Method 1: Start PowerShell from a Command Prompt 

  • Open the Command Prompt (cmd.exe) console. To do this, you can click Start, type “cmd” in the Search box, and then select cmd from the results. 
  • In the Command Prompt window, type powershell.exe and then press Enter. This opens a PowerShell console where this issue does not occur. 

Method 2: Change the font in the PowerShell console 

  • Start PowerShell as usual. To do this, you can click Start, type “PowerShell” in the Search box, and then select PowerShell from the results. 
  • Right-click the top bar of the PowerShell console, select Properties, and then select the Font tab. Here, select MS Gothic, and then click OK. 

 

Next steps 

We are working on releasing a resolution for this issue in a future Windows update. We will provide an update when more information is available.

KB5075999 - Windows Server 2016, all editions Win 10 Ent LTSB 2016

Windows Secure Boot certificate expiration  

Important: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate expiration and CA updates. 

 

 

Windows Server 2016 

Applies to: Windows Server 2016 

  • This security update includes fixes and improvements that are a part of the following update: 
  • The following is a summary of the issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting. 
  • [Graphics] Fixed: A stability issue affecting certain graphics processing units (GPUs) configurations. 
  • If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device. 

 

Windows 10, version 1607 

Applies to: Win 10 Ent LTSB 2016 

This security update includes fixes and improvements that are a part of the following update: 

The following is a summary of the issues that this update addresses. The bold text within the brackets indicates the item or area of the change we are documenting. 

  • [Graphics] Fixed: A stability issue affecting certain graphics processing units (GPUs) configurations. 

If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device. 

For more information about security vulnerabilities, please refer to the new Security Update Guide website and the February 2026 Security Updates.