July 14 2026 Kb5099539 Os Builds 19045 7548 And 19044 7548
This article lists the security issues and quality improvements included in this cumulative security update.
Applies to: Windows 10 ESU
Use EKB KB5015684 to update to Windows 10, version 22H2.
This security update includes fixes and quality improvements that are part of the following updates:
The following is a summary of the issues that this update addresses when you install this update. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change we are documenting.
[OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior.
[File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode.
[Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file.
[Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub.
[Networking] This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected. For more information, see Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026 .
[Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.
If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device.
For more information security vulnerabilities, please refer to the new Security Update Guide website and the July 2026 Security Updates .
For information Windows update terminology, see the article the types of Windows updates and the monthly quality update types . For an overview of Windows 10, version 22H2, see its update history page .
We are currently not aware of any issues with this update
Applies to: Windows 10 Enterprise LTSC 2021 and Windows 10 IoT Enterprise LTSC 2021
Use EKB KB5003791 to update to Windows 10, version 21H2 on supported editions.
This security update includes fixes and quality improvements that are part of the following updates:
The following is a summary of the issues that this update addresses when you install this update. If there are new features, it lists them as well. The bold text within the brackets indicates the item or area of the change we are documenting.
[OLE Automation (known issue)] Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior.
[File Explorer (known issue)] Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode.
[Recycle Bin (known issue)] Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file.
[Input] This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts. This issue can typically be resolved by restarting the app affected. If the issue is not resolved, report it through the Feedback Hub.
[Networking] This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected. For more information, see Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026 .
[Remote Desktop (RDP) Security] Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal. New guidance is available for managing RDP file security through Group Policy to help organizations reduce phishing risks by controlling which .rdp files users can open. We recommend IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible to avoid disruption.
If you installed earlier updates, only the new updates contained in this package will be downloaded and installed on your device.
For more information security vulnerabilities, please refer to the new Security Update Guide website and the July 2026 Security Updates .
For information Windows update terminology, see the article the types of Windows updates and the monthly quality update types . For an overview of Windows 10, version 22H2, see its update history page .
Note Follow @WindowsUpdate to find out when new content is published to the Windows release health dashboard.
We are currently not aware of any issues with this update.
Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). SSUs improves the reliability of the update process and includes fixes to the servicing stack, the component that installs Windows updates.
Important You must have the latest servicing stack update (SSU) installed. Not installing the latest SSU before applying Windows updates might result in the Windows update not being offered until the latest SSU is installed.
If you deploy this update, choose one of the following based on your installation scenario:
For offline OS image servicing:
If your image does not have the July 25, 2023 ( KB5028244 ) or later LCU, you must install the special standalone October 13, 2023 SSU ( KB5031539 ) before installing this update.
For Windows Server Update Services (WSUS) deployment or when installing the standalone package from Microsoft Update Catalog:
If your devices do not have the May 11, 2021 ( KB5003173 ) or later LCU, you must install the special standalone August 10, 2021, SSU ( KB5005260 ) before installing this update.
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001 .
Note The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
For information how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update .
To get and install this update, use one of the following Windows and Microsoft release channels.
A list of the files that are included in this update are provided in a CSV (Comma delimited) (*.csv) file. The file can be opened in a text editor such as Notepad or in Microsoft Excel.
Note The English (United States) version of this software update might contain files for additional languages.
Download the file information for cumulative update KB5099539 .
Download the file information for the SSU (KB5104021) - version 19041.7546 update.
Windows updates do not install Microsoft Store application updates. If you are an enterprise user, see Microsoft Store apps - Configuration Manager . If you are a consumer user, see Get updates for apps and games in Microsoft Store .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
