Microsoft has released cumulative update KB5099414 for Windows 11 version 23H2 (2023 Update) as part of the July 2026 Patch Tuesday. The build number is 22631.7376. The main goal of the release is to address 570 security issues, including three zero-day vulnerabilities, along with several internal OS feature improvements. If you have previous updates installed, only the new components of this package will be downloaded and installed.
- Security. The built-in Windows curl tool has been updated to version 8.21.0. The update also includes various security improvements for internal OS functions for July 2026 and helps protect your device. In total, during the July 2026 Patch Tuesday, Microsoft fixed 570 security issues, including three zero-day vulnerabilities.
- Secure Boot. The list of devices that can automatically obtain new Secure Boot certificates has been expanded. Their deployment via Windows Update will continue in the coming months on supported PCs and unmanaged corporate devices.
- Third-party applications. Fixed an issue introduced after installing the June security update KB5093998. Some applications using OLE Automation to interact with Microsoft Office were unable to launch Office or open documents.
- File Explorer. Fixed an issue where the OneDrive shortcut did not work when launching File Explorer as an administrator.
- Country and operator settings. Updated profiles for some mobile operators.
- Hotkeys. Changed behavior when unregistering and clearing key combinations. In rare cases, some built-in Windows functions may temporarily stop responding to certain combinations. Usually, restarting the application helps.
- Network. Strengthened security requirements for TDI transport registration. Applications using sockets through unregistered third-party TDI transports may stop working after installing the update. Registered transports are not affected by this change.
- Recycle Bin. Fixed an error where the permanent deletion confirmation dialog displayed the internal file name from the Recycle Bin instead of the original name.
- RDP Security. Added support for SHA-2 certificate fingerprints for trusted RDP publishers. SHA-1 is still retained for compatibility, but will be removed in the future. Microsoft recommends migrating to SHA-256 or a stronger algorithm as soon as possible.
No known issues have been recorded at this time. To install update KB5099414, open Settings, go to Windows Update, and click Check for updates. The package installs automatically. What did not fit into the main text: this cumulative update is mandatory and is downloaded through the standard Windows servicing mechanism; for Home and Pro editions, deployment may follow the standard schedule, while Enterprise and Education editions have immediate availability.
How the new features work:
Security. The built-in Windows curl.exe utility has been upgraded to version 8.21.0, implying the integration of a refreshed codebase with resolved URL parsing vulnerabilities and enhanced TLS 1.3 support. The July cumulative package addresses 570 vulnerabilities across kernel components, the graphics subsystem, and the network stack, including three actively exploited zero-days, thereby preventing privilege escalation and remote code execution.
Secure Boot. The list of devices whose Trusted Platform Module and UEFI firmware allow them to automatically obtain renewed Secure Boot certificates via the signature database (DBX) and Key Exchange Key (KEK) update mechanism has been expanded. This automatic deployment through Windows Update affects supported PCs and unmanaged corporate devices, extending the lifecycle of the trusted environment without manual administrator intervention.
Third-party applications. A regression in the OLE Automation infrastructure introduced by the KB5093998 security update has been resolved. The issue involved a failure of interface marshalling when calling COM server methods of Microsoft Office applications from external clients: attempts to acquire the dispatch interface ended with an error, blocking the launch of Office processes and document opening via CoCreateInstance programmatic calls.
File Explorer. A failure in the logic of interaction with reparse points was fixed, which caused the OneDrive shortcut to become inaccessible when launching the shell with elevated privileges. The root cause lay in the namespace isolation of the redirector: a process running as Administrator lost access to the symbolic link created in a standard user context.
Country and operator settings. The Access Point Name (APN) databases and configuration profile packages for a number of mobile operators have been updated. This affects the preset parameters for cellular network registration and roaming settings, allowing devices with cellular modems to correctly identify the home network and obtain an IP address without manually entering PDP context settings.
Hotkeys. The internal handling of clearing global keyboard hook registrations and accelerator tables when unregistering key combinations has been changed. In rare conditions, the state of the input synchronization mutex could remain locked, causing temporary unresponsiveness of WM_HOTKEY system handlers; typically, forcibly restarting the application flushes the message queue.
Network. Security requirements for TDI transport registration have been tightened: the kernel now requires mandatory registration via a legitimate driver signature to invoke dispatch functions. Applications using low-level sockets through unregistered third-party driver filters that bypass the Winsock Kernel stack will cease to function, while registered transports remain unaffected.
Recycle Bin. An error in the permanent deletion confirmation dialog was resolved where, instead of the original display name, an internal placeholder reference assigned during relocation to the S-1-5-21-*\Recycle.Bin directory was shown. The failure occurred at the stage of retrieving the System.ItemNameDisplay property from the $I descriptor file, where metadata was incorrectly extracted prior to the final rendering of the dialog window.
RDP Security. Processing of SHA-2 certificate fingerprints has been implemented for validating Remote Desktop publishers, enabling the client to verify the gateway certificate using a more robust hash sum. SHA-1 is temporarily retained for backward compatibility with older deployments, but the client side now prefers SHA-256 by calling CertGetCertificateChain with the strict chain verification flag for algorithms deemed obsolete.
Official announcement on the Microsoft website.
The last 10 Windows updates:
| Update | Build | Version | Windows | Channel | Date |
|---|---|---|---|---|---|
| KB5101587 | 28020.2539 | 26H1 | Windows 11 | Beta | 2026-07-20 |
| KB5101594 | 26220.8925 | 25H2 | Windows 11 | Beta | 2026-07-20 |
| KB5101589 | 26300.8935 | 26H2 | Windows 11 | Experimental | 2026-07-20 |
| KB5101681 | 28000.2605 | 26H1 | Windows 11 | Preview | 2026-07-20 |
| KB5101684 | 26200.8968 | 25H2 | Windows 11 | Preview | 2026-07-20 |
| KB5121767 | 26200.8894 | 25H2 | Windows 11 | Stable | 2026-07-19 |
| KB5099414 | 22631.7376 | 23H2 | Windows 11 | Stable | 2026-07-14 |
| KB5099539 | 19045.7548 | 22H2 (ESU) | Windows 10 | Stable | 2026-07-14 |
| KB5101649 | 28000.2525 | 26H1 | Windows 11 | Stable | 2026-07-14 |
| KB5101650 | 26200.8875 | 25H2 | Windows 11 | Stable | 2026-07-14 |