Microsoft Releases Windows 10 KB5099539 Extended Security Update
Microsoft has released the Windows 10 KB5099539 extended security update, which includes this month's record-breaking July 2026 Patch Tuesday fixes, along with additional security improvements.
Initially, Microsoft only offered consumers one year of extended security updates. However, last month, Microsoft quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to receive security updates until October 12, 2027.
Installing the Update
If you are running Windows 10 Enterprise LTSC or are enrolled in the ESU program, you can install this update like normal by going into Settings, clicking on Windows Update, and manually performing a 'Check for Updates.'
After installing this update, Windows 10 will be updated to build 19045.7548, and Windows 10 Enterprise LTSC 2021 will be updated to build 19044.7548.
What's New in Windows 10 KB5099539
Microsoft is no longer releasing new features for Windows 10, and the KB5099539 update primarily contains security updates and bug fixes. The update also includes fixes released as part of today's record-breaking July 2026 Patch Tuesday, which fixed a massive 570 vulnerabilities across Microsoft's products, including two exploited and one publicly disclosed zero-day flaws.
Approximately 300 of the 570 vulnerabilities addressed this month affect Windows 10 Version 22H2.
Complete List of Fixes in KB5099539
- OLE Automation (known issue): Fixed: Addresses a compatibility issue in OLE Automation (oleaut32.dll) that was introduced by the June 2026 security update.
- File Explorer (known issue): Fixed: An issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run with administrative mode.
- Recycle Bin (known issue): Fixed: This update addresses an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file.
- Input: This update changes hotkey unregister and cleanup behavior. In rare cases, some built-in Windows experiences that rely on previous hotkey lifecycle behavior might temporarily stop responding to certain keyboard shortcuts.
- Secure Boot: This update enables dynamic status reporting for Secure Boot states in Windows Security App. This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates.
- Networking: This update introduces a security hardening change that enforces TDI transport registration requirements. As a result, applications that use sockets over unregistered third-party TDI transports might stop working after installing this update.
- Remote Desktop (RDP) Security: Support for SHA-2 certificate thumbprints has been added for trusted RDP publishers, with SHA-1 support retained only for backward compatibility and planned for future removal.
Microsoft also warns that an intentional security hardening change that enforces TDI transport registration requirements may impact legacy applications that rely on unregistered third-party TDI transports.
Windows users can determine whether they are affected by checking the Windows System event log in Event Viewer for AFD Event ID 16003 entries.
To determine if you have a TDI transport that is affected by this change, check the Windows System event logs in Event Viewer > Windows > System. If you find an AFD Event ID: 16003 'An unregistered TDI provider (\Driver) was detected', then your TDI transport is affected by this change.
Otherwise, Microsoft says there are no known issues with this update.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
Source: BleepingComputer