KB5082200


Microsoft released cumulative update KB5082200 for Windows 10, version 22H2 as part of the April 2026 Patch Tuesday for devices enrolled in the Extended Security Updates (ESU) program. The cumulative update package KB5026435 (Build 19045.7184) is intended for Windows 10 version 22H2 (2022 Update) on x86, x64 (amd64), and ARM64 processors. Support for Windows 10 has ended: as of October 14, 2025, the system only receives updates under the Extended Security Updates (ESU) program.

After installing Windows updates released starting March 10, 2026, some users may have experienced an issue when signing into applications using a Microsoft account. Even with an active internet connection, an error no connection was displayed, which blocked access to services and applications, including Microsoft Teams.

The cumulative update KB5082200 for PCs is installed automatically via Windows Update. To check, go to Settings > Update & Security and click Check for updates. A system restart is required to complete the installation. After the update, the Windows 10 (version 22H2) build number will change to 19045.7184. The update does not include new system features, only quality improvements.


How the new features work:

Security improvements for internal OS functions: The update includes internal fixes in the kernel and critical subsystems (e.g., win32k.sys, ntoskrnl.exe). 167 vulnerabilities (including two zero‑days) are resolved. Code integrity mechanisms (PatchGuard) and process isolation are hardened to prevent privilege escalation.

Protection against phishing via RDP: When opening an .rdp file, the system parses its XML parameters and displays them before session start. Dangerous resource redirections (disks, printers, clipboard) are disabled by default. A MarkOfTheWeb tag is added for new files, triggering a security warning.

Secure Boot certificate update status: Windows Security adds a new data provider (Windows.SecurityCenter.SecureBoot) querying UEFI firmware for db and dbx variable status. Icons and notifications are shown. On commercial devices, this is disabled via Group Policy.

Precise detection of compatible devices for Secure Boot: The Windows quality update adds device ID hashes (SMBIOS GUID, UEFI version) to the registry (HKLM\SOFTWARE\Microsoft\SecureBoot\Compat). The system compares them with Microsoft’s approved list before deploying new certificates. Rollout is gradual — only for devices with successful update records.

Fix for BitLocker recovery issue: Fixed a bug in Secure Boot validation chain — after db/dbx certificate updates, the SecureBoot register in the TCG log was improperly updated. This caused PCR[7] mismatch between the bootloader and BitLocker. Measurements are now synchronized, preventing recovery mode.


Official announcement on the Microsoft website.

The last 10 Windows updates:

Update Build Version Windows Channel Date
KB5101587 28020.2539 26H1 Windows 11 Beta 2026-07-20
KB5101594 26220.8925 25H2 Windows 11 Beta 2026-07-20
KB5101589 26300.8935 26H2 Windows 11 Experimental 2026-07-20
KB5101681 28000.2605 26H1 Windows 11 Preview 2026-07-20
KB5101684 26200.8968 25H2 Windows 11 Preview 2026-07-20
KB5121767 26200.8894 25H2 Windows 11 Stable 2026-07-19
KB5099414 22631.7376 23H2 Windows 11 Stable 2026-07-14
KB5099539 19045.7548 22H2 (ESU) Windows 10 Stable 2026-07-14
KB5101649 28000.2525 26H1 Windows 11 Stable 2026-07-14
KB5101650 26200.8875 25H2 Windows 11 Stable 2026-07-14