KB5099539: Windows 10’s July 2026 ESU Update — 570 Security Fixes, OLE Automation Restored, and Free Updates Extended to 2027

Windows 10 officially reached end of support in October 2025. Most users know this. What far fewer people know is that Microsoft has quietly extended its free Extended Security Updates program by an additional year — meaning enrolled devices can now receive monthly security patches until October 12, 2027.

KB5099539 is the first major update to reflect that extended timeline. Released July 14, 2026 as part of Microsoft’s record-breaking July Patch Tuesday cycle, it delivers 570 security fixes, patches three zero-days, and closes several bugs that the June 2026 update introduced — including the OLE Automation break that stopped third-party apps from opening Office applications.

This guide explains everything: what KB5099539 contains, who can actually install it, what the ESU extension means, and whether Windows 10 users still on the operating system need to act.

What Is KB5099539?

KB5099539 is the July 2026 cumulative update for Windows 10 versions 22H2 and 21H2, released as part of Microsoft’s July 2026 Patch Tuesday cycle on July 14, 2026. It updates Windows 10 version 22H2 to OS build 19045.7548 and Windows 10 Enterprise LTSC 2021 (version 21H2) to build 19044.7548.

Although Windows 10 reached end of support in October 2025, Microsoft continues to deliver monthly security updates and quality improvements through the ESU program.

KB5099539 is not available to all Windows 10 users — only those enrolled in the Extended Security Updates program or running Windows 10 Enterprise LTSC 2021 can install it. Standard Windows 10 users not enrolled in ESU will not see it offered through Windows Update.

The ESU Extension — The News Most People Missed

Before getting into what KB5099539 fixes, the broader ESU context matters significantly for anyone still running Windows 10.

Initially, Microsoft only offered consumers one year of extended security updates. However, last month, Microsoft quietly extended its free Windows 10 Extended Security Updates program for consumers by an additional year, allowing enrolled devices to receive security updates until October 12, 2027.

This means Windows 10 users who enrolled in the free consumer ESU program — which was already extended once from the original October 2025 end-of-support date — now have security patches available until October 2027. That is two full years of continued protection beyond Windows 10’s end-of-support date.

This is a significant and underreported change. Many Windows 10 users who assumed they were out of options after October 2025 may not realize free security updates are still available to them through ESU enrollment.

For enterprise customers, Windows 10 Enterprise LTSC 2021 continues to receive updates as part of its license terms. KB5099539 applies to those deployments as well.

The 570 Vulnerabilities and Three Zero-Days

As part of July 2026 Patch Tuesday, KB5099539 includes Microsoft’s latest security updates, addressing 570 vulnerabilities across Windows, Microsoft Office, SharePoint, .NET, Visual Studio, and other Microsoft products.

The July 2026 Patch Tuesday is the largest ever released by Microsoft: 570 vulnerabilities fixed, including 57 critical issues and 3 zero-day flaws — two already exploited in active attacks, one publicly disclosed before the patch was ready.

The same security content that shipped to Windows 11 users through KB5101650 is delivered to Windows 10 ESU users through KB5099539. The vulnerability count, zero-day fixes, and priority patch areas are the same across both updates — the difference is the delivery vehicle and the Windows version they target.

The two actively exploited zero-days are the highest priority. Zero-days being exploited in active attacks means attackers were using these vulnerabilities against real targets before Microsoft’s patch was ready. On unpatched systems, those attacks remain viable until this update is installed.

That volume of flaws is no accident — Microsoft warned a few days earlier that AI would make Patch Tuesday updates bigger. The ESU update is therefore the practical outcome of those statements.

Every Fix in KB5099539

While this update does not introduce new features, it delivers several important reliability improvements, security enhancements, and fixes for known issues affecting Windows 10 devices.

Windows 10 is in maintenance mode — Microsoft is not adding features, only maintaining security and stability for enrolled devices. Here is every fix KB5099539 delivers.

OLE Automation Fix — The Most Important Fix

The most anticipated fix is the one related to OLE automation — the decades-old mechanism that lets one piece of software control another in the background. For example, your line-of-business app that generates a letter in Word or fills in an Excel workbook without the user opening Office directly. The June 2026 security update broke the mechanism, to the point that Microsoft admitted on June 16 that “some third-party applications might be unable to start Microsoft Office applications or open documents,” sometimes without any error message at all. KB5099539 resolves this issue.

This update addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update. Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior.

For enterprise environments where line-of-business applications integrate with Microsoft Office — generating Word documents, populating Excel spreadsheets, sending Outlook emails — the June 2026 break was a serious operational disruption. KB5099539 restores the OLE Automation behavior that existed before the June update.

File Explorer Fix — OneDrive Shortcut Restored

File Explorer fix restoring the OneDrive shortcut when running as Administrator.

A previous update removed the OneDrive shortcut from the File Explorer navigation panel when Windows was running in an elevated Administrator context. This was an unintended regression that affected users and IT administrators who frequently work in elevated sessions. KB5099539 restores the OneDrive shortcut to the File Explorer navigation panel regardless of whether you are running as a standard user or Administrator.

Recycle Bin Fix — Correct Filename Now Shows

Recycle Bin confirmation dialog now displays the correct file name.

This is the same bug that Windows 11 users experienced after the June 2026 KB5094126 update — when permanently deleting a file from the Recycle Bin, the confirmation dialog showed the internal Recycle Bin filename format ($R4ABC12.docx) rather than the original human-readable file name (Report.docx). This made permanent deletion genuinely confusing and created risk of accidentally deleting the wrong file.

KB5099539 fixes the Recycle Bin confirmation dialog on Windows 10 to show the correct original filename.

Remote Desktop Security — SHA-2 Certificate Thumbprints

The biggest change in Windows 10 KB5099539 is on the Remote Desktop side. Microsoft has added support for SHA-2 certificate thumbprints for trusted RDP publishers.

Remote Desktop connections now support SHA-2 certificate thumbprints for authentication verification when connecting to trusted RDP publishers. This is a security hardening change that protects against phishing attacks targeting RDP connections through fraudulent certificates.

For organizations using Remote Desktop Protocol for remote access — which remains common in enterprise Windows 10 environments — this change strengthens the authentication chain for trusted publisher validation. SHA-2 is the current cryptographic standard; the previous reliance on older certificate methods represented a security gap that KB5099539 closes.

Network Security Hardening — TDI Transport Registration

This update introduces a security hardening change that enforces TDI transport registration requirements.

The Transport Driver Interface is a Windows networking component that some applications use to send and receive network traffic. KB5099539 introduces stricter enforcement of TDI transport registration requirements — applications and drivers that use TDI must now properly register their transport before using it. This prevents a class of network-level manipulation that could be used to bypass security controls.

This change primarily affects enterprise network security posture rather than individual user experience. Most users will not notice any visible change from this hardening.

Secure Boot Certificate Deployment Continues

This update includes additional high-confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.

The phased rollout of updated Secure Boot certificates — which began in earlier 2026 updates in response to older certificate expiration — continues through KB5099539. Windows 10 devices that qualify based on their update history receive the updated certificates automatically. Devices that have not yet received them continue to operate normally.

Keyboard Hotkey Cleanup Behavior Update

Updated keyboard hotkey cleanup behavior to improve system reliability.

KB5099539 updates how Windows cleans up keyboard hotkey registrations when applications close or crash. The previous behavior could leave orphaned hotkey registrations that interfered with keyboard shortcuts in subsequently opened applications. The updated cleanup behavior prevents this interference and improves overall system reliability when running multiple applications that use keyboard shortcuts.

What KB5099539 Does NOT Include

This is important for managing expectations.

No new features. Windows 10 is in maintenance-only mode. Microsoft is not adding Shared Audio, Point-in-Time Restore, NPU monitoring, or any of the new capabilities that shipped to Windows 11 users through KB5101650 and KB5094126.

No Dell-specific fix. The Intel IPF driver conflict that affected certain Dell PCs with the July 2026 updates was specific to the Windows 11 update delivery path. KB5099539 does not carry equivalent Dell-specific content.

No AI component updates. The Windows AI component updates (Image Search, Content Extraction, Semantic Analysis) that shipped to Copilot+ PCs through Windows 11 updates are not part of KB5099539.

Who Can Install KB5099539?

This is the most critical practical question about KB5099539.

Can install:

Windows 10 version 22H2 devices enrolled in the Extended Security Updates program. Since Microsoft extended the free consumer ESU by another year, more devices are now eligible than many users realize. Enrollment is managed through Windows Update settings.

Windows 10 Enterprise LTSC 2021 (version 21H2) devices. Enterprise LTSC licenses include continued security updates as part of their licensing terms.

Cannot install:

Standard Windows 10 devices not enrolled in ESU. These devices reached end of support in October 2025 and are no longer receiving updates through Windows Update.

Like every ESU-era Windows 10 patch, the offline installers from the Microsoft Update Catalog will not work unless your device already has ESU active. This means even manually downloading the .msu file from the catalog and running it will fail if ESU is not activated on the device.

How to Check If You Are Enrolled in ESU

If you are unsure whether your Windows 10 device is enrolled in the Extended Security Updates program:

Go to Settings, Update and Security, Windows Update and click Check for updates. If KB5099539 is offered, your device is enrolled in ESU and eligible for July’s security patches.

If no updates are offered and your device is on Windows 10 version 22H2, your device is likely not enrolled in ESU. Contact Microsoft or check the Windows 10 ESU enrollment documentation for enrollment options.

How to Install KB5099539

Method 1 — Windows Update

Go to Settings, Update and Security, Windows Update. Click Check for updates. If your device is enrolled in ESU, KB5099539 will appear labeled as “2026-07 Cumulative Update for Windows 10 Version 22H2 (KB5099539).” Click Download and install. Restart when prompted.

In testing, Windows 10 KB5099539 takes just a few minutes to download and install.

Method 2 — Microsoft Update Catalog

The offline .msu installer is available at catalog.update.microsoft.com. Search for KB5099539, download the package matching your architecture — x64 for 64-bit or ARM-64 for ARM devices — and run it. Remember that the offline installer requires ESU to be active on the device. Running it on a non-ESU device will fail.

If you encounter error 0x80244022 during the update process, check our full error fix guide for step-by-step solutions.

Verification after install:

Go to Settings, System, About and check the OS build number. A successful KB5099539 installation shows build 19045.7548 on Windows 10 22H2 and 19044.7548 on Windows 10 Enterprise LTSC 2021.

No Known Issues

Unlike several recent Windows updates — notably KB5094126 which shipped with three confirmed bugs — KB5099539 launched with no documented known issues. Microsoft’s release notes do not list any active investigation items for this update.

This is unusual given the scale of the July 2026 Patch Tuesday and reflects the fact that Windows 10 ESU updates are more conservative in scope — they patch security vulnerabilities and fix confirmed bugs rather than introducing new features that might create new instability.

Should You Install KB5099539?

Yes — immediately if you are eligible.

The two zero-days that were actively exploited before July 14 are the clearest reason. These are vulnerabilities that attackers were already using against real targets. On any Windows 10 ESU device that has not installed KB5099539, those attacks remain viable.

The OLE Automation fix is the second compelling reason for enterprise environments. If your organization’s line-of-business applications were broken by the June 2026 update — unable to open Word, Excel, or Outlook programmatically — KB5099539 restores that functionality.

If you are not enrolled in ESU:

The practical question is whether to enroll. With Microsoft extending the free consumer ESU program through October 2027, enrollment is worth considering for any Windows 10 device that cannot realistically be upgraded to Windows 11 in the near term. Monthly security patches — even without new features — are significantly better than no patches on a device connected to the internet.

KB5099539 vs KB5101650 — Windows 10 vs Windows 11

Both updates shipped on July 14, 2026 as part of the same Patch Tuesday cycle. Understanding how they relate helps Windows environments running mixed OS versions.

The security content is the same — 570 vulnerabilities, three zero-days, the same RDP SHA-2 certificate improvement, the same TDI transport hardening, the same OLE Automation fix. Both deliver the full scope of Microsoft’s July 2026 security response.

The differences are in features and delivery. KB5101650 for Windows 11 added Point-in-Time Restore, Bluetooth improvements, File Explorer upgrades, and other new capabilities alongside the security fixes. KB5099539 for Windows 10 contains only security and bug fixes — no new features, reflecting Windows 10’s maintenance-only status.

Frequently Asked Questions

What is KB5099539?

KB5099539 is the July 14, 2026 Patch Tuesday cumulative security update for Windows 10 versions 22H2 and 21H2 delivered through the Extended Security Updates program. It updates Windows 10 22H2 to OS build 19045.7548 and Windows 10 Enterprise LTSC 2021 to build 19044.7548. It fixes 570 vulnerabilities including three zero-days and resolves the OLE Automation bug introduced in June 2026.

Does KB5099539 work on all Windows 10 PCs?

No. KB5099539 is only available to Windows 10 devices enrolled in Microsoft’s Extended Security Updates program and Windows 10 Enterprise LTSC 2021 devices. Standard Windows 10 installations not enrolled in ESU will not receive this update. Even the offline installer from the Microsoft Update Catalog requires ESU to be active on the device.

What is the Windows 10 Extended Security Updates program?

The ESU program allows Windows 10 devices that have passed the October 2025 end-of-support date to continue receiving monthly security patches. Microsoft recently extended the free consumer ESU program by an additional year, allowing enrolled devices to receive updates until October 12, 2027.

What does KB5099539 fix?

KB5099539 fixes the OLE Automation (oleaut32.dll) compatibility issue from June 2026 that prevented third-party apps from opening Office applications, restores the OneDrive shortcut in File Explorer for Administrator users, fixes the Recycle Bin confirmation dialog to show correct filenames, adds SHA-2 RDP certificate thumbprint support, introduces TDI network security hardening, and continues Secure Boot certificate deployment.

Does KB5099539 add any new features?

No. Windows 10 is in maintenance-only mode. KB5099539 contains only security fixes and bug corrections — no new features. New features like Point-in-Time Restore and Shared Audio shipped only to Windows 11 users through KB5101650.

What OS build does KB5099539 install?

KB5099539 installs OS build 19045.7548 on Windows 10 version 22H2 and 19044.7548 on Windows 10 Enterprise LTSC 2021 (version 21H2).

Are there any known issues with KB5099539?

No. Unlike several recent Windows updates, KB5099539 launched with no documented known issues. Microsoft’s release notes do not list any active investigations for this update.

How is KB5099539 different from KB5101650?

Both are July 14, 2026 Patch Tuesday updates with the same security content — 570 vulnerabilities and three zero-days. KB5101650 is the Windows 11 update and includes new features like Point-in-Time Restore and Bluetooth improvements. KB5099539 is the Windows 10 ESU update and contains only security fixes and bug corrections with no new features.

Leave a Reply

Your email address will not be published. Required fields are marked *