Microsoft released KB5099535 on July 14, 2026 — the July Patch Tuesday cumulative security update for Windows Server 2016 and Windows 10 version 1607. It moves affected systems to OS build 14393.9339.
This update carries two pieces of information that every administrator managing Windows Server 2016 needs to know.
The first is practical and immediate: KB5099535 fixes the OLE Automation compatibility failure introduced by June 2026’s security update — the same break that stopped third-party applications from launching Office, opening documents, and triggering COM-based workflows across every supported Windows version.
The second is strategic: support for Windows Server 2016 will end in January 2027. KB5099535 is one of approximately six monthly updates remaining before Microsoft stops providing security patches for this platform entirely.
Here is everything administrators need to know.
What Is KB5099535?
KB5099535 is the July 14, 2026 mandatory cumulative security update for Windows Server 2016, all editions, and Windows 10 version 1607 Enterprise LTSB. It is part of the same July 2026 Patch Tuesday cycle that delivered KB5101650 to Windows 11 users and KB5099539 to Windows 10 22H2 ESU users.
This security update includes fixes and improvements that are a part of the June 9, 2026 update KB5094122 for OS Build 14393.9230. KB5099535 is cumulative — it includes all security content from KB5094122 and every previous monthly update, plus the new July 2026 fixes.
Critical prerequisite: For Windows Server 2016, the release includes the MAJOR Servicing Stack Update KB5099542 and the Cumulative Update KB5099535. These form the core of the July 2026 patch set for this version. The servicing stack update prepares the system for subsequent installations, while the cumulative update delivers the security fixes.
KB5099542 must be installed before KB5099535 will install successfully. Attempting to install KB5099535 without KB5099542 in place will fail.
The OLE Automation Fix — Most Important for Enterprise
OLE Automation known issue fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update.
This fix is the most operationally significant content in KB5099535 for enterprise environments.
OLE Automation is the Windows mechanism that allows one application to programmatically control another. It is the foundation of countless enterprise workflows — a CRM that generates Word documents, an ERP system that populates Excel reports, an accounting application that triggers Outlook emails, a business process tool that creates PowerPoint presentations.
Some applications that use the IDispatch::Invoke method to call COM methods with BYREF parameters that share the same underlying storage might fail. These failures can include parameter marshaling errors or automation call failures. This update corrects how parameter ownership is managed and restores expected application behavior.
The June 2026 security update for Windows Server 2016 introduced this regression. Any server running line-of-business applications that integrate with Microsoft Office through OLE Automation was affected — workflows would fail silently or with cryptic COM errors, and the root cause was not immediately obvious.
KB5099535 permanently resolves the underlying parameter ownership management issue. After installation, OLE Automation-dependent applications should resume normal operation without any additional configuration changes.
CVEs Fixed — 260+ Vulnerabilities
KB5099535 addresses an extensive list of security vulnerabilities for Windows Server 2016 as part of the July 2026 Patch Tuesday cycle.
The CVE list for KB5099535 is substantial — over 260 documented vulnerabilities addressed across Windows components. A partial list of specific CVEs includes:
CVE-2026-32202, CVE-2026-33842, CVE-2026-34346, CVE-2026-40378, CVE-2026-40400, CVE-2026-40422, CVE-2026-41087, CVE-2026-42900, CVE-2026-42975, CVE-2026-42982, CVE-2026-42990, CVE-2026-44806, CVE-2026-47302, CVE-2026-47304, CVE-2026-48564, CVE-2026-49164, CVE-2026-49165, CVE-2026-49168, CVE-2026-49171, CVE-2026-49172, CVE-2026-49176, CVE-2026-49177, CVE-2026-49178, CVE-2026-49180, CVE-2026-49181 — plus 236 additional CVEs.
The security priorities for Windows Server 2016 in July 2026 mirror the same categories that drove KB5101650 for Windows 11 — remote code execution vulnerabilities, elevation of privilege exploits, and information disclosure vulnerabilities across Windows networking, authentication, and graphics components.
CVE-2026-47302 and CVE-2026-47304 appear in both KB5099535 and in KB5100998 — the July 2026 .NET Framework update — because those vulnerabilities affect code shared between the Windows platform and the .NET runtime. Both updates are needed to fully close those shared CVEs if .NET Framework components are installed on the server.
Secure Boot Certificate Renewal
Important: Secure Boot certificates used by most Windows devices were set to expire starting in June 2026. Microsoft has been updating these certificates on PCs and non-managed business devices for the past months. Devices that have not received the newer certificates will continue to start, and standard Windows updates will continue to install. We will continue to install the newer certificates via Windows updates in the coming months.
KB5099535 continues the phased Secure Boot certificate renewal for Windows Server 2016 systems. Servers that have been receiving monthly updates are likely already in the certificate renewal queue. Servers that have missed several monthly updates — particularly those managed through WSUS with inconsistent approval workflows — should be specifically checked for Secure Boot certificate status.
Secure Boot certificate expiration on a server is a recoverable but disruptive situation. Verifying certificate status before it becomes an issue is preferable to dealing with boot failures after the fact.
The January 2027 End of Support Deadline
This is the strategic context that should accompany every Windows Server 2016 update conversation in the second half of 2026.
Support for Windows Server 2016 will end in January 2027.
Specifically, Windows Server 2016 reaches end of extended support on January 12, 2027. After that date, Microsoft will no longer provide security fixes, software updates, or technical assistance for the platform under standard support agreements.
KB5099535, released July 14, 2026, means approximately six monthly Patch Tuesday updates remain for Windows Server 2016 — August, September, October, November, December 2026, and the final January 2027 update before the deadline.
What end of support means in practice:
Security vulnerabilities discovered after January 2027 will not be patched on Windows Server 2016. Each month after the deadline, the unpatched vulnerability count grows — and attackers specifically target end-of-life systems because they know patches will not be forthcoming.
Extended Security Updates (ESU):
Microsoft offers Extended Security Updates for Windows Server 2016 beyond the January 2027 deadline, similar to the ESU program for Windows 10. ESU for Windows Server 2016 can be purchased from Microsoft or accessed through Azure Arc. Organizations that cannot migrate servers by January 2027 should evaluate ESU as a bridge option.
Migration path:
The recommended upgrade path from Windows Server 2016 is to Windows Server 2025, which has a mainstream support end date of October 2029 and extended support through October 2034. Organizations with sufficient lead time should be planning server migrations now — a migration from Windows Server 2016 to 2025 typically requires application compatibility testing, infrastructure planning, and staged rollout work that takes months to complete properly.
How KB5099535 Fits in the July 2026 Server Update Landscape
The July 2026 Patch Tuesday delivered parallel updates across all supported Windows Server versions. Understanding how KB5099535 relates to the broader release helps administrators prioritize across mixed server environments.
| Platform | Update | Build |
|---|---|---|
| Windows Server 2016 | KB5099535 | 14393.9339 |
| Windows Server 2019 | KB5099538 | 17763.9020 |
| Windows Server 2022 | KB5099536 | 20348.x |
| Windows Server 2025 | KB5101649 | 26100.x |
| Windows 11 25H2/24H2 | KB5101650 | 26200.8875 / 26100.8875 |
| Windows 10 22H2 ESU | KB5099539 | 19045.7548 |
The OLE Automation fix present in KB5099535 also appears in KB5099539 for Windows 10 22H2 ESU users, in KB5101650 for Windows 11 users, and in the equivalent updates for Windows Server 2019, 2022, and 2025. The same June 2026 regression affected all Windows platforms — the July 2026 Patch Tuesday fixed it everywhere simultaneously.
Installation Order — Critical
The installation order for KB5099535 is non-negotiable:
Step 1: Install KB5099542 — the July 2026 Servicing Stack Update for Windows Server 2016.
Step 2: Install KB5099535 — this cumulative security update.
Proper sequencing ensures that all fixes are integrated successfully.
Attempting to install KB5099535 before KB5099542 will fail. Patch management tools that deploy both updates in the same deployment cycle should be configured to enforce this prerequisite order.
How to Install KB5099535
Method 1 — Windows Update
On managed Windows Server 2016 systems that receive updates through Windows Update, KB5099542 and KB5099535 will be offered in the correct order. Navigate to Settings, Windows Update, Check for updates. Allow KB5099542 to install first. Then install KB5099535. Restart when prompted.
Method 2 — WSUS or Configuration Manager
Approve KB5099542 first in WSUS with a dependency rule ensuring it deploys before KB5099535 is approved. BigFix released the corresponding content on July 14, 2026, to facilitate automated deployment in enterprise settings.
Configure deployment sequencing in your patch management tooling so KB5099542 completes across your server fleet before KB5099535 deployment begins.
Method 3 — Microsoft Update Catalog
Go to catalog.update.microsoft.com. Search for KB5099535. Download the x64 package for Windows Server 2016. Run it after KB5099542 is confirmed installed.
If you encounter error 0x80244022 during catalog access or WSUS communication, our complete error fix guide covers every enterprise and consumer resolution path.
Verifying KB5099535 Installed Successfully
After installation and restart, confirm the update applied correctly.
Open a Command Prompt and run:
winver
Or go to Control Panel, System. The build number should show 14393.9339 after successful KB5099535 installation.
Via PowerShell:
powershell
Get-HotFix -Id KB5099535
If installation details are returned, the update is present. If nothing is returned, the update did not install correctly — verify that KB5099542 is installed first and retry.
No Reported Known Issues
With no reported known issues and minimal community discussion volume, KB5099535 appears to be a straightforward maintenance update focused on restoring functionality rather than introducing new features.
NinjaOne’s monitoring rates KB5099535 at approximately 75% stability — appears stable with no widespread failure reports. The update is well-received in enterprise deployment environments, reflecting its targeted scope — security patches and the OLE Automation fix without new features that might introduce regressions.
Frequently Asked Questions
What is KB5099535?
KB5099535 is the July 14, 2026 Patch Tuesday cumulative security update for Windows Server 2016 and Windows 10 version 1607. It moves systems to OS build 14393.9339, fixes 260+ security vulnerabilities, and resolves the OLE Automation compatibility issue introduced by the June 2026 security update.
What does KB5099535 fix?
The primary fix in KB5099535 is the OLE Automation compatibility issue in oleaut32.dll introduced by the June 2026 security update. Applications using IDispatch::Invoke with BYREF parameters were failing with parameter marshaling errors. KB5099535 corrects parameter ownership management and restores normal application behavior. It also patches 260+ security CVEs.
Must I install KB5099542 before KB5099535?
Yes. KB5099542 — the July 2026 Servicing Stack Update for Windows Server 2016 — must be installed before KB5099535. Installing KB5099535 without KB5099542 in place will fail. Configure your patch management tools to enforce this sequence.
When does Windows Server 2016 reach end of support?
Windows Server 2016 reaches end of extended support on January 12, 2027. After that date, Microsoft will no longer provide security patches. Approximately six monthly updates remain before the deadline. Organizations should evaluate migration to Windows Server 2025 or enroll in the Extended Security Updates program for continued coverage.
What is the OLE Automation fix in KB5099535?
OLE Automation allows applications to programmatically control other applications — for example, a CRM launching Word to generate a document. The June 2026 security update broke this mechanism by incorrectly managing BYREF parameter ownership in the IDispatch::Invoke COM interface. KB5099535 corrects how parameter ownership is managed, restoring all OLE Automation-dependent workflows.
What OS build does KB5099535 install?
KB5099535 installs OS build 14393.9339 on Windows Server 2016 and Windows 10 version 1607 Enterprise LTSB.
Does KB5099535 have any known issues?
No. KB5099535 launched with no documented known issues. NinjaOne stability monitoring rates it at approximately 75% — appears stable with no widespread failure reports across enterprise deployments.
How does KB5099535 relate to KB5099539?
Both are July 14, 2026 Patch Tuesday updates addressing the same OLE Automation fix. KB5099535 applies to Windows Server 2016 and Windows 10 version 1607 LTSB. KB5099539 applies to Windows 10 version 22H2 through the Extended Security Updates program. Both contain the same core security content targeted at their respective platforms.
I do not even know how I ended up here, but I thought this post was good. I don’t know who you are but definitely you are going to a famous blogger if you are not already 😉 Cheers!