Microsoft released KB5099540 on July 14, 2026 — the July Patch Tuesday cumulative security update for Windows Server 2022. It moves affected systems to OS build 20348.5386.
KB5099540 is a cumulative security update for Windows Server 2022 released on July 14, 2026. This combined package includes both the Servicing Stack Update (KB5120210) and the Latest Cumulative Update, delivering security fixes, quality improvements, and non-security updates from the previous month’s optional preview release.
The scale of the July 2026 security content is significant: KB5099540 patches 326 CVEs, with the worst rated Critical at CVSS 9.9 and at least one CVE already listed in the CISA Known Exploited Vulnerabilities catalog. The CISA KEV listing is the detail that demands immediate attention — it means active exploitation in the wild has been confirmed by CISA, not just predicted.
Beyond the CVE count, KB5099540 carries three changes every Windows Server 2022 administrator needs to understand before deploying: a TDI transport security hardening change that may break applications using unregistered TDI transports, a fix for the OLE Automation failure introduced in June 2026, and a known BitLocker recovery issue on systems with non-default Group Policy configurations.
Here is everything.
What Is KB5099540?
KB5099540 addresses multiple system components including Secure Boot certificate management, authentication protocols, and networking reliability.
It is the July 2026 mandatory cumulative security update for Windows Server 2022, applying to all editions. The update is cumulative — it contains all security content from KB5094128 (June 9, 2026) and every previous monthly update, plus the new July 2026 fixes.
Unlike the Windows Server 2016 update chain — where KB5099542 must be installed separately as a prerequisite before KB5099535 — KB5099540 bundles both components together. This combined package includes both the Servicing Stack Update (KB5120210) and the Latest Cumulative Update.
This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates.
No separate SSU prerequisite installation is required for Windows Server 2022 — the bundled delivery model handles the ordering automatically.
326 CVEs — Including One Actively Exploited
KB5099540 is a large July 2026 rollup fixing 326 CVEs, with the worst rated Critical at CVSS 9.9 and at least one CVE already listed in the CISA Known Exploited Vulnerabilities catalog. The confirmed exploitation matters more than the modest 11% top EPSS here, since KEV listing means attacks are observed in the wild rather than merely predicted.
The CISA KEV designation is the critical prioritization signal for enterprise administrators. The Known Exploited Vulnerabilities catalog is CISA’s authoritative list of security vulnerabilities that have been confirmed as actively exploited by threat actors in real attacks. A CVE on this list is not a theoretical risk — it is an active operational threat.
Organizations using any risk-based patching framework should treat the CISA KEV-listed CVE in KB5099540 as the highest priority driver for deployment. Delaying this update on exposed Windows Server 2022 systems means leaving a confirmed exploitation vector open.
The July 2026 Patch Tuesday cycle — the same cycle that delivered KB5101650 to Windows 11 with a record 570 vulnerability fixes — addressed security issues across every supported Windows platform simultaneously. The 326 CVEs in KB5099540 for Windows Server 2022 represent the server platform’s portion of that same July security content.
The worst-rated vulnerability at CVSS 9.9 is in the Critical severity band. CVSS 9.9 is near-maximum severity on the 0-10 scale — it typically indicates a remotely exploitable vulnerability requiring no authentication and no user interaction.
Every Fix and Change in KB5099540
OLE Automation Fix — Restoring Enterprise Workflows
Microsoft has received reports of an issue in which certain third-party applications might be unable to launch Microsoft Office applications or open documents after installing the Windows updates released on or after June 9, 2026. This issue affects certain third-party applications that use OLE automation to interact with Microsoft Office applications. In some cases, the Office application or document might fail to open without displaying an error message. Affected Microsoft Office applications might include Word, Excel, PowerPoint, Access, and other Microsoft Office applications when launched from within the affected third-party application.
This issue is resolved in Windows updates released on and after July 14, 2026 such as KB5099540.
This is the fix that matters most to enterprise environments running line-of-business applications on Windows Server 2022. The June 2026 security update KB5094128 introduced a regression in OLE Automation (oleaut32.dll) that broke the IDispatch::Invoke mechanism used by applications to control Microsoft Office programmatically.
Any server running applications that generate Office documents, populate spreadsheets, trigger email workflows, or perform any COM-based Office integration was affected. KB5099540 corrects parameter ownership management in oleaut32.dll and restores expected application behavior across all affected Office applications.
TDI Transport Registration Enforcement — May Break Applications
This is the change that requires the most careful pre-deployment testing for Windows Server 2022 environments.
This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update. Registered TDI transports are not affected.
TDI — Transport Driver Interface — is a Windows networking API that some legacy applications and network drivers use to send and receive network traffic. The security hardening in KB5099540 enforces a requirement that TDI transports must be properly registered before applications can use them.
Applications and drivers that use registered TDI transports — the correct, documented approach — are not affected. Applications that use TDI transports without proper registration — a pattern more common in older or legacy network software — will stop working after KB5099540 installs.
Who is most at risk:
Environments running older network monitoring tools, VPN clients, security software, or custom-developed network applications that use TDI. Also at risk are organizations running legacy third-party firewall or network filtering software that hooks into the TDI layer.
How to identify affected applications:
After installing KB5099540 in a test environment, monitor for application failures in network-dependent software. The Windows Event Log will record TDI-related errors that help identify which applications are affected. Microsoft has published additional guidance in the support documentation titled “Third-party TDI transports might stop working after installing Windows security updates released on or after July 14, 2026.”
What to do:
Contact vendors of any affected network software for updated drivers or application versions that use registered TDI transports. If no updates are immediately available and the affected application is business-critical, test whether excluding specific traffic paths resolves the issue while awaiting vendor updates.
Recycle Bin Filename Fix
This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. This issue might occur after installing the June 2026 security update KB5094128.
When permanently deleting a file from the Recycle Bin after the June 2026 update, the confirmation dialog showed the internal Recycle Bin file identifier format — similar to $R4ABC12.docx — instead of the original human-readable filename. This made permanent deletion genuinely confusing and created a risk of accidentally confirming deletion of the wrong file.
KB5099540 restores the original filename display in the Recycle Bin confirmation dialog on Windows Server 2022. This fix is the same one that shipped to Windows 11 users in KB5101650 and to Windows 10 22H2 ESU users in KB5099539 — the same June regression affected all Windows platforms.
RDP Security — SHA-2 Certificate Thumbprints
Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal.
Remote Desktop Protocol connections now support SHA-2 certificate thumbprints for trusted publisher authentication. This is a security hardening change specifically aimed at reducing the risk of RDP phishing attacks — where malicious actors present fraudulent certificates during remote desktop connection setup to intercept credentials.
SHA-2 is the current cryptographic standard. SHA-1 support is retained only for backward compatibility and is flagged as planned for future removal. Organizations managing RDP connections to Windows Server 2022 instances should verify that their trusted publisher certificate infrastructure supports SHA-2 now, before SHA-1 support is removed in a future update.
Secure Boot Certificate Rollout Continues
This update includes additional high-confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.
The Secure Boot certificate renewal — responding to the expiration of certificates that have been in use since the early Secure Boot era — continues through KB5099540 for Windows Server 2022 systems. Servers that qualify based on update history receive the renewed certificates. Servers that have missed several months of updates should have their Secure Boot certificate status specifically verified.
The BitLocker Known Issue
Devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update.
This is the same BitLocker known issue that appeared in the April 2026 Windows 11 update KB5083769 — it has now surfaced in the July Windows Server 2022 update.
The issue affects systems where BitLocker is configured through Group Policy with settings that deviate from Microsoft’s recommended defaults. On these systems, the first restart after KB5099540 installation may trigger BitLocker recovery mode — requiring the recovery key before Windows Server 2022 boots.
Who is affected:
Windows Server 2022 instances where BitLocker is enabled with custom Group Policy configurations. This is most commonly an enterprise scenario — BitLocker on Windows Server is typically managed through Group Policy rather than local settings.
How to prepare before deploying:
Verify that BitLocker recovery keys are accessible for all Windows Server 2022 instances before deploying KB5099540. In managed environments, ensure recovery keys are escrowed in Active Directory or Azure Active Directory before the update reaches affected systems. Test KB5099540 on a representative sample of your Server 2022 fleet — including servers with non-default BitLocker policy — before broad deployment.
Recovery if a server enters BitLocker recovery:
Enter the recovery key when prompted. The server will boot normally after the key is accepted. The BitLocker issue is a one-time occurrence — subsequent restarts on the same server will not trigger recovery mode again.
Full Fix Summary Table
| Fix / Change | Type | Details |
|---|---|---|
| OLE Automation | Fixed | oleaut32.dll BYREF parameter ownership restored |
| TDI transport hardening | Security change | May break unregistered TDI transport apps |
| Recycle Bin filename | Fixed | Original filename shown in deletion dialog |
| RDP SHA-2 thumbprints | Security improved | SHA-1 retained for backward compat only |
| Secure Boot certificates | Ongoing | Phased rollout continues |
| Servicing stack (KB5120210) | Bundled | SSU included — no separate prerequisite |
| 326 CVEs including KEV | Security | One actively exploited, worst CVSS 9.9 |
| BitLocker recovery | Known issue | Non-default GPO configs may require key entry |
Windows Server 2022 Support Timeline — Context for KB5099540
Unlike Windows Server 2016 — which reaches end of support in January 2027 as we covered in the KB5099535 article — Windows Server 2022 has a significantly longer support window.
Windows Server 2022 mainstream support ends October 13, 2026. However, extended support continues until October 13, 2031 — giving organizations five more years of security patches after mainstream support concludes. This means KB5099540 is well within the active support lifecycle, and administrators can plan patching without the urgency of an approaching end-of-life deadline.
The transition from mainstream to extended support in October 2026 does not eliminate security updates — it means that new features and non-security improvements shift to paid extended support contracts, while security patches continue under standard support terms.
How to Install KB5099540
Method 1 — Windows Update
KB5099540 installs automatically through Windows Update on eligible Windows Server 2022 systems. On server systems where Windows Update is enabled, the update will be offered and installed during the next maintenance window.
For servers managed through Windows Update for Business policies, KB5099540 appears in the July 2026 update ring on the standard deferral schedule.
Method 2 — WSUS or Configuration Manager
In WSUS, synchronize the July 2026 Patch Tuesday content and approve KB5099540 for your Windows Server 2022 product group. Unlike the Windows Server 2016 deployment — where KB5099542 must be approved and deployed separately before KB5099535 — KB5099540 includes the SSU (KB5120210) bundled within the combined package. A single approval is sufficient.
Deploy to a test group first. Given the TDI transport hardening change and the BitLocker known issue, validating in a test environment before broad deployment is particularly important this month.
Method 3 — Microsoft Update Catalog
Go to catalog.update.microsoft.com. Search for KB5099540. Download the x64 package for Windows Server 2022. Run the .MSU file and restart when prompted.
If you encounter error 0x80244022 during download or WSUS synchronization, our complete error fix guide covers every enterprise and consumer resolution path.
Verifying KB5099540 Installed Successfully
After installation and restart, verify the build number via Command Prompt:
winver
Or via PowerShell:
powershell
Get-HotFix -Id KB5099540
Or via WMI for remote verification across multiple servers:
powershell
Get-WmiObject -Class Win32_QuickFixEngineering | Where-Object {$_.HotFixID -eq "KB5099540"}
Successful installation shows OS build 20348.5386 on Windows Server 2022.
KB5099540 and the July 2026 Server Update Landscape
The July 2026 Patch Tuesday delivered simultaneous security content across all supported Windows Server versions. KB5099540 is the Windows Server 2022 piece of a coordinated cross-platform security response.
For administrators managing mixed server environments, understanding which KB delivers July’s security content to each platform prevents confusion when tracking patch compliance:
Windows Server 2016 — KB5099535 — Build 14393.9339 — requires separate KB5099542 SSU first.
Windows Server 2022 — KB5099540 — Build 20348.5386 — SSU bundled as KB5120210.
Windows Server 2025 — KB5099536 — Build 26100.33158 — SSU bundled.
Windows 11 25H2/24H2 — KB5101650 — Build 26200.8875/26100.8875.
Windows 10 22H2 ESU — KB5099539 — Build 19045.7548.
The OLE Automation fix, TDI hardening change, Recycle Bin fix, and RDP SHA-2 support appear across all these updates — they are cross-platform fixes applied consistently.
Frequently Asked Questions
What is KB5099540?
KB5099540 is the July 14, 2026 Patch Tuesday cumulative security update for Windows Server 2022. It moves systems to OS build 20348.5386, patches 326 CVEs including one in the CISA Known Exploited Vulnerabilities catalog, and includes the SSU KB5120210 bundled within the combined package.
Does KB5099540 require a separate SSU installation?
No. Unlike the Windows Server 2016 update chain where KB5099542 must be installed separately before KB5099535, KB5099540 bundles the Servicing Stack Update KB5120210 within the combined package. A single installation handles both components automatically.
What is the TDI transport change in KB5099540?
KB5099540 enforces a security hardening requirement that TDI (Transport Driver Interface) transports must be properly registered before applications can use them. Applications using unregistered TDI transports will stop working after the update. Registered TDI transports are not affected. Test network-dependent applications in a pre-production environment before broad deployment.
What is the BitLocker issue with KB5099540?
Devices with non-default BitLocker Group Policy configurations may be required to enter their BitLocker recovery key on the first restart after installing KB5099540. This is a one-time occurrence. Ensure BitLocker recovery keys are accessible for all affected servers before deploying the update.
How many CVEs does KB5099540 fix?
KB5099540 fixes 326 CVEs. The worst-rated vulnerability is Critical at CVSS 9.9. At least one CVE is listed in the CISA Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild has been confirmed.
What OS build does KB5099540 install?
KB5099540 installs OS build 20348.5386 on Windows Server 2022.
Does KB5099540 fix the OLE Automation issue?
Yes. KB5099540 resolves the OLE Automation (oleaut32.dll) compatibility regression introduced by the June 2026 security update KB5094128. Third-party applications that were unable to launch Office applications or open documents through OLE Automation will resume normal operation after KB5099540 installs.
When does Windows Server 2022 reach end of support?
Windows Server 2022 mainstream support ends October 13, 2026. Extended support continues until October 13, 2031. Security patches continue through the extended support period, so KB5099540 is well within the active support lifecycle.