KB5099414


Microsoft has released cumulative update KB5099414 for Windows 11 version 23H2 (2023 Update) as part of the July 2026 Patch Tuesday. The build number is 22631.7376. The main goal of the release is to address 570 security issues, including three zero-day vulnerabilities, along with several internal OS feature improvements. If you have previous updates installed, only the new components of this package will be downloaded and installed.

No known issues have been recorded at this time. To install update KB5099414, open Settings, go to Windows Update, and click Check for updates. The package installs automatically. What did not fit into the main text: this cumulative update is mandatory and is downloaded through the standard Windows servicing mechanism; for Home and Pro editions, deployment may follow the standard schedule, while Enterprise and Education editions have immediate availability.


How the new features work:

Security. The built-in Windows curl.exe utility has been upgraded to version 8.21.0, implying the integration of a refreshed codebase with resolved URL parsing vulnerabilities and enhanced TLS 1.3 support. The July cumulative package addresses 570 vulnerabilities across kernel components, the graphics subsystem, and the network stack, including three actively exploited zero-days, thereby preventing privilege escalation and remote code execution.

Secure Boot. The list of devices whose Trusted Platform Module and UEFI firmware allow them to automatically obtain renewed Secure Boot certificates via the signature database (DBX) and Key Exchange Key (KEK) update mechanism has been expanded. This automatic deployment through Windows Update affects supported PCs and unmanaged corporate devices, extending the lifecycle of the trusted environment without manual administrator intervention.

Third-party applications. A regression in the OLE Automation infrastructure introduced by the KB5093998 security update has been resolved. The issue involved a failure of interface marshalling when calling COM server methods of Microsoft Office applications from external clients: attempts to acquire the dispatch interface ended with an error, blocking the launch of Office processes and document opening via CoCreateInstance programmatic calls.

File Explorer. A failure in the logic of interaction with reparse points was fixed, which caused the OneDrive shortcut to become inaccessible when launching the shell with elevated privileges. The root cause lay in the namespace isolation of the redirector: a process running as Administrator lost access to the symbolic link created in a standard user context.

Country and operator settings. The Access Point Name (APN) databases and configuration profile packages for a number of mobile operators have been updated. This affects the preset parameters for cellular network registration and roaming settings, allowing devices with cellular modems to correctly identify the home network and obtain an IP address without manually entering PDP context settings.

Hotkeys. The internal handling of clearing global keyboard hook registrations and accelerator tables when unregistering key combinations has been changed. In rare conditions, the state of the input synchronization mutex could remain locked, causing temporary unresponsiveness of WM_HOTKEY system handlers; typically, forcibly restarting the application flushes the message queue.

Network. Security requirements for TDI transport registration have been tightened: the kernel now requires mandatory registration via a legitimate driver signature to invoke dispatch functions. Applications using low-level sockets through unregistered third-party driver filters that bypass the Winsock Kernel stack will cease to function, while registered transports remain unaffected.

Recycle Bin. An error in the permanent deletion confirmation dialog was resolved where, instead of the original display name, an internal placeholder reference assigned during relocation to the S-1-5-21-*\Recycle.Bin directory was shown. The failure occurred at the stage of retrieving the System.ItemNameDisplay property from the $I descriptor file, where metadata was incorrectly extracted prior to the final rendering of the dialog window.

RDP Security. Processing of SHA-2 certificate fingerprints has been implemented for validating Remote Desktop publishers, enabling the client to verify the gateway certificate using a more robust hash sum. SHA-1 is temporarily retained for backward compatibility with older deployments, but the client side now prefers SHA-256 by calling CertGetCertificateChain with the strict chain verification flag for algorithms deemed obsolete.


Official announcement on the Microsoft website.

The last 10 Windows updates:

Update Build Version Windows Channel Date
KB5101587 28020.2539 26H1 Windows 11 Beta 2026-07-20
KB5101594 26220.8925 25H2 Windows 11 Beta 2026-07-20
KB5101589 26300.8935 26H2 Windows 11 Experimental 2026-07-20
KB5101681 28000.2605 26H1 Windows 11 Preview 2026-07-20
KB5101684 26200.8968 25H2 Windows 11 Preview 2026-07-20
KB5121767 26200.8894 25H2 Windows 11 Stable 2026-07-19
KB5099414 22631.7376 23H2 Windows 11 Stable 2026-07-14
KB5099539 19045.7548 22H2 (ESU) Windows 10 Stable 2026-07-14
KB5101649 28000.2525 26H1 Windows 11 Stable 2026-07-14
KB5101650 26200.8875 25H2 Windows 11 Stable 2026-07-14