Microsoft has released cumulative update KB5099539 (Build 19045.7548) for Windows 10 version 22H2 as part of the July 2026 Patch Tuesday. The package is intended for devices based on x86, x64 (AMD64), and ARM64 processors enrolled in the Extended Security Updates (ESU) program. The update includes various security improvements for internal OS functions. In total, Microsoft fixed 570 security issues, including three zero-day vulnerabilities.
- Third-party applications and OLE Automation. Fixed an issue introduced after installing the June security update. Some applications using OLE Automation to interact with Microsoft Office were unable to launch Office or open documents.
- File Explorer and OneDrive. Fixed an issue where the OneDrive shortcut did not work when launching File Explorer as an administrator.
- Recycle Bin. Fixed a bug where the permanent deletion confirmation dialog displayed the internal file name from the Recycle Bin instead of the original name.
- Hotkeys. Modified behavior when unregistering and clearing key combinations. In rare cases, some built-in Windows functions may temporarily stop responding to certain combinations. Restarting the application usually helps.
- Dynamic Secure Boot indication. A dynamic indication of the Secure Boot status has appeared in the Windows Security app. Windows quality updates now include additional high-confidence data for device targeting, expanding the coverage of devices that can automatically receive new Secure Boot certificates. Devices receive new certificates only after demonstrating a sufficient number of successful update signals, allowing for a controlled and phased deployment.
- Network security hardening. Security requirements for registering TDI transports have been strengthened. Applications using sockets via unregistered third-party TDI transports may stop working after installing the update. Registered transports are not affected by this change.
- RDP security. Support for SHA-2 certificate fingerprints has been added for trusted RDP publishers. SHA-1 is retained for compatibility for now, but will be removed in the future. Microsoft recommends transitioning to SHA-256 or a stronger algorithm as soon as possible.
To install the update, open Settings, go to Update & Security, and click Check for updates. Cumulative package KB5099539 will install automatically via Windows Update.
How the new features work:
Third-party applications and OLE Automation. Fixed an issue introduced after the June security update where calling CoCreateInstance or IUnknown interfaces to automate Microsoft Office failed with a COM server initialization error. The OLE Automation mechanism could not correctly map the application's CLSID in the registry, blocking out-of-process launch and document manipulation due to a class factory failure.
File Explorer and OneDrive. Resolved a defect where the OneDrive sync client would not initialize its namespace handler when the explorer.exe process privileges were elevated to administrator level. Mandatory integrity control separation caused a junction point injection failure, so clicking the root link in the navigation pane did not trigger a redirect to the locally cached file system snapshot.
Recycle Bin. Fixed a bug in the permanent deletion confirmation dialog where the internal system identifier from the $I file within the hidden S-1-5-21-* folder was displayed instead of the original name. During an SHFileOperation call, the parser incorrectly resolved the symbolic link at the data-matching stage from the PropertySetStorage stream, substituting the user-friendly name with a technical one.
Hotkeys. Logic for unregistering global key combinations via UnregisterHotKey and clearing atoms through GlobalDeleteAtom has been modified. In rare thread race conditions, the kernel-level internal hash table could hold stale pointers to freed tagSHOTKEY structures. This temporarily blocked the dispatching of system combinations, taking the WM_HOTKEY handler out of service until the shell was restarted.
Dynamic Secure Boot indication. A dynamic indicator of the Secure Boot status, reflecting the current state of the SetupMode and SecureBoot UEFI variables, has been implemented in the Windows Security app. Quality updates now include high-confidence telemetry signals for device targeting, expanding the coverage of machines that can automatically receive new db subsystem certificates only after reaching a threshold of successful updates within a controlled deployment phase.
Network security hardening. Security requirements for registering TDI transports via TdiRegisterPnPHandlers have been strengthened. Applications creating sockets through unregistered third-party filter drivers may lose network functionality. Legitimate transports correctly listed in the HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage registry key are unaffected by the I/O manager validation flag change.
RDP security. Built-in support for SHA-2 fingerprints for trusted Remote Desktop publishers has been added, enabling server authentication using the CERT_SHA256_HASH_PROP_ID algorithm. SHA-1 is currently retained for backward compatibility at the Schannel level but is scheduled for removal. A transition to SHA-256 or a stronger algorithm in the certificate's SignatureAlgorithm field is recommended to prevent collisions and strengthen the TLS tunnel.
Official announcement on the Microsoft website.
The last 10 Windows updates:
| Update | Build | Version | Windows | Channel | Date |
|---|---|---|---|---|---|
| KB5101587 | 28020.2539 | 26H1 | Windows 11 | Beta | 2026-07-20 |
| KB5101594 | 26220.8925 | 25H2 | Windows 11 | Beta | 2026-07-20 |
| KB5101589 | 26300.8935 | 26H2 | Windows 11 | Experimental | 2026-07-20 |
| KB5101681 | 28000.2605 | 26H1 | Windows 11 | Preview | 2026-07-20 |
| KB5101684 | 26200.8968 | 25H2 | Windows 11 | Preview | 2026-07-20 |
| KB5121767 | 26200.8894 | 25H2 | Windows 11 | Stable | 2026-07-19 |
| KB5099414 | 22631.7376 | 23H2 | Windows 11 | Stable | 2026-07-14 |
| KB5099539 | 19045.7548 | 22H2 (ESU) | Windows 10 | Stable | 2026-07-14 |
| KB5101649 | 28000.2525 | 26H1 | Windows 11 | Stable | 2026-07-14 |
| KB5101650 | 26200.8875 | 25H2 | Windows 11 | Stable | 2026-07-14 |