KB5099414: what it fixes and who gets it

KB5099414 is a security update from Microsoft's July 2026 release for Windows 11 Version 23H2.

Microsoft data read
17CVEs fixed
1rated Critical
0already exploited
Yesrestart required

Should you install it?

Yes. It closes holes Microsoft rates Critical, the most serious rating it uses. Windows Update installs it automatically on supported home PCs.

If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.

Security fixes in KB5099414

CVETypeCVSSSeverity
CVE-2026-42982Windows Secure Kernel Mode Elevation of Privilege VulnerabilityElevation of Privilege7.8Critical
CVE-2026-42990SQL Server ODBC driver Elevation of Privilege VulnerabilityRemote Code Execution9.8Important
CVE-2026-49172Windows FTP Service Remote Code Execution VulnerabilityRemote Code Execution9.8Important
CVE-2026-44800Windows Push Notifications Elevation of Privilege VulnerabilityElevation of Privilege7.8Important
CVE-2026-50471Windows NTFS Remote Code Execution VulnerabilityRemote Code Execution7.8Important
CVE-2026-58601Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege VulernabilityElevation of Privilege7.8Important
CVE-2026-40378Windows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-50696Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityDenial of Service7.5Important
CVE-2026-58640Windows NTFS Remote Code Execution VulnerabilityRemote Code Execution7.3Important
CVE-2026-48571Windows App Package Installer Elevation of Privilege VulnerabilityElevation of Privilege7.0Important
CVE-2026-48572Windows App Package Installer Elevation of Privilege VulnerabilityElevation of Privilege7.0Important
CVE-2026-56173Windows WebView Elevation of Privilege VulnerabilityElevation of Privilege7.0Important
CVE-2026-58629DirectX Graphics Kernel Elevation of Privilege VulnerabilityElevation of Privilege7.0Important
CVE-2026-34348Windows Event Logging Service Information Disclosure VulnerabilityInformation Disclosure6.5Important
CVE-2026-33842Windows File Explorer Information Disclosure VulnerabilityInformation Disclosure5.5Important
CVE-2026-34328Windows Audio Service Information Disclosure VulnerabilityInformation Disclosure5.5Important
CVE-2026-34346Windows Ancillary Function Driver for WinSock Information Disclosure VulnerabilityInformation Disclosure5.5Important

Questions and experiences

Ask about this page: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

4,322 members already hereThey read, write, comment and vote. 0 verified · 31 joined this year

Cookies

We use essential cookies to run the platform. Analytics and marketing cookies are only turned on once you consent — you can change your choice at any time.