KB5099538: what it fixes and who gets it
KB5099538 is a security update from Microsoft's July 2026 release for Windows 10 Version 1809.
Microsoft data read
Should you install it?
Yes, and soon: it closes a hole that was already being used in real attacks before the fix was released. Windows Update installs it automatically on supported home PCs.
If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.
Security fixes in KB5099538
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-56155Active Directory Federation Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | ExploitedImportant |
| CVE-2026-57092Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | Elevation of Privilege | 9.9 | Critical |
| CVE-2026-50518Windows DHCP Server Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-56159DHCP Server Service Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-56188Windows Server Network driver Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-50380Windows GDI+ Remote Code Execution Vulnerability | Remote Code Execution | 9.6 | Critical |
| CVE-2026-48564DHCP Server Service Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-50370DHCP Server Service Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-50382DirectX Graphics Kernel Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-50444Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Critical |
| CVE-2026-50474Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-54121Active Directory Certificate Services Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Critical |
| CVE-2026-54982Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-54999Windows TCP/IP Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-57087Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-57090Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-57094Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-58608Windows Print Spooler Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-54128Windows DHCP Client Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical |
| CVE-2026-54992Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Critical |
| CVE-2026-50680Windows Hyper-V Elevation of Privilege Vulnerability | Elevation of Privilege | 8.2 | Critical |
| CVE-2026-49164Windows Active Directory Domain Services Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Critical |
| CVE-2026-50694Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Critical |
| CVE-2026-54995Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Critical |
| CVE-2026-42982Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Critical |
| CVE-2026-49796Windows GDI+ Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical |
| CVE-2026-50655Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical |
| CVE-2026-56189Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Critical |
| CVE-2026-42990SQL Server ODBC driver Elevation of Privilege Vulnerability | Remote Code Execution | 9.8 | Important |
| CVE-2026-49172Windows FTP Service Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Important |
| CVE-2026-50447Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Important |
| CVE-2026-56190Remote Desktop Protocol Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Important |
| CVE-2026-49798Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 9.3 | Important |
| CVE-2026-49178Windows Active Directory Domain Services Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-49795Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50369Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50477Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50489Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50666Windows Remote Access Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50670Windows Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-50692Desktop Window Manager Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-54107Windows Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-56194Windows NFS Server Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-56647Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-58534Windows Input Method Editor (IME) Elevation of Privilege Vulnerability | Elevation of Privilege | 8.8 | Important |
| CVE-2026-58594Remote Desktop Client Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-49184Windows NTFS Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Important |
| CVE-2026-54122Windows GDI+ Remote Code Execution Vulnerability | Remote Code Execution | 8.4 | Important |
| CVE-2026-50429Windows Kernel Information Disclosure Vulnerability | Information Disclosure | 8.2 | Important |
| CVE-2026-42900Microsoft Windows App Store Elevation of Privilege Vulnerability | Elevation of Privilege | 8.1 | Important |
| CVE-2026-50439Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important |
| CVE-2026-50460Windows Runtime Elevation of Privilege Vulnerability | Elevation of Privilege | 8.1 | Important |
| CVE-2026-50686Windows OLE Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important |
| CVE-2026-56186Windows Secure Channel Information Disclosure Vulnerability | Information Disclosure | 8.1 | Important |
| CVE-2026-40400Windows PowerShell Remote Code Execution Vulnerability | Remote Code Execution | 8.0 | Important |
| CVE-2026-42975Windows Bluetooth Port Driver Remote Code Execution | Remote Code Execution | 8.0 | Important |
| CVE-2026-50365Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | Elevation of Privilege | 8.0 | Important |
| CVE-2026-50502Windows Event Logging Service Remote Code Execution Vulnerability | Remote Code Execution | 8.0 | Important |
| CVE-2026-50683Windows DHCP Client Elevation of Privilege Vulnerability | Elevation of Privilege | 8.0 | Important |
| CVE-2026-49170Windows StateRepository API Server file Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
Showing the 60 most severe of 311. The full list is in Microsoft's Security Update Guide.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
0 comments
…