{"family":"windowsserver","family_label":"Windows Server","build":"20348.5386","base":"20348","tag":"2022","kb":"KB5099540","kb_url":"https://support.microsoft.com/help/5099540","kb_title":"July 14, 2026—KB5099540 (OS Build 20348.5386)","release_date":"2026-07-14","update_type":"2026-07 B","update_type_label":"Security update (Patch Tuesday)","servicing":"LTSC","ms_known_issues":[{"title":null,"symptom":"Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy \"Configure TPM platform validation profile for native UEFI firmware configurations\" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding a","workaround":"Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set \"Configure TPM platform validation profile for native UEFI firmware configurations\" to \"Not Configured\". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is ena","applies_to":"","status":""}],"ms_none_known":false,"ms_highlights":null,"title":"July 14, 2026—KB5099540 (OS Build 20348.5386)","build_type":"release","channel_label":"Release","branch":null,"kind":"cumulative","kind_label":"Cumulative update","is_dotnet":false,"status":null,"line":{"status":"supported","note":"Supported LTSC release"},"created":1784030400,"created_iso":"2026-07-14T12:00:00Z","uuid":null,"permalink":"/builds/windowsserver/20348.5386/","tag_url":"/builds/windowsserver/2022/","index_url":"/builds/windowsserver/","api_url":"https://search.windowsforum.com/api/builds/build/windowsserver/20348.5386","records":[],"summary":null,"known_issues":[{"thread_id":438860,"node_id":84,"title":"CVE-2026-58619: Install July Updates to Block Windows Sensor EoP","replies":0,"views":496,"post_date":1784151968,"last_post_date":1784151968,"url":"https://windowsforum.com/news/cve-2026-58619-install-july-updates-to-block-windows-sensor-eop.438860/","kind":"issue","match":"exact","pinned":true,"score":2.0},{"thread_id":438807,"node_id":84,"title":"CVE-2026-56650: Install July Updates to Block Windows SYSTEM Takeover","replies":0,"views":546,"post_date":1784145662,"last_post_date":1784145662,"url":"https://windowsforum.com/news/cve-2026-56650-install-july-updates-to-block-windows-system-takeover.438807/","kind":"issue","match":"exact","pinned":true,"score":2.0}],"linked":{"news":[{"thread_id":438985,"node_id":84,"title":"CVE-2026-59117: Verify Before Treating as Windows Terminal RCE","replies":0,"views":685,"post_date":1784239315,"last_post_date":1784239315,"url":"https://windowsforum.com/news/cve-2026-59117-verify-before-treating-as-windows-terminal-rce.438985/","kind":"coverage","match":"exact","pinned":true,"score":2.0},{"thread_id":438873,"node_id":84,"title":"CVE-2026-58638: Install July Updates to Fix Windows Boot Loader Bypass","replies":0,"views":957,"post_date":1784152838,"last_post_date":1784152838,"url":"https://windowsforum.com/news/cve-2026-58638-install-july-updates-to-fix-windows-boot-loader-bypass.438873/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438872,"node_id":84,"title":"CVE-2026-58637: KB5101650 Fixes Windows Offline Files EoP","replies":0,"views":520,"post_date":1784152733,"last_post_date":1784152733,"url":"https://windowsforum.com/news/cve-2026-58637-kb5101650-fixes-windows-offline-files-eop.438872/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438868,"node_id":84,"title":"CVE-2026-58632: Install July Updates to Fix Windows Win32K EoP","replies":0,"views":508,"post_date":1784152450,"last_post_date":1784152450,"url":"https://windowsforum.com/news/cve-2026-58632-install-july-updates-to-fix-windows-win32k-eop.438868/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438863,"node_id":84,"title":"CVE-2026-58628: Install July Updates to Fix Windows Wireless EoP","replies":0,"views":540,"post_date":1784152260,"last_post_date":1784152260,"url":"https://windowsforum.com/news/cve-2026-58628-install-july-updates-to-fix-windows-wireless-eop.438863/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438862,"node_id":84,"title":"CVE-2026-58627: Patch Windows DHCP Server DoS by July 14","replies":0,"views":528,"post_date":1784152162,"last_post_date":1784152162,"url":"https://windowsforum.com/news/cve-2026-58627-patch-windows-dhcp-server-dos-by-july-14.438862/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438861,"node_id":84,"title":"CVE-2026-58626: Install July Updates to Fix Windows RDS RCE","replies":0,"views":935,"post_date":1784152065,"last_post_date":1784152065,"url":"https://windowsforum.com/news/cve-2026-58626-install-july-updates-to-fix-windows-rds-rce.438861/","kind":"fix","match":"exact","pinned":true,"score":2.0},{"thread_id":438860,"node_id":84,"title":"CVE-2026-58619: Install July Updates to Block Windows Sensor EoP","replies":0,"views":496,"post_date":1784151968,"last_post_date":1784151968,"url":"https://windowsforum.com/news/cve-2026-58619-install-july-updates-to-block-windows-sensor-eop.438860/","kind":"issue","match":"exact","pinned":true,"score":2.0}],"tutorials":[],"threads":[],"total":48,"exact":40,"window_days":45},"related":{"history":[{"build":"20348.5631","title":null,"created":1789387200,"kb":"KB5129237","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5631/","current":false},{"build":"20348.5622","title":null,"created":1788868800,"kb":"KB5122882","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5622/","current":false},{"build":"20348.5499","title":null,"created":1786449600,"kb":"KB5120242","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5499/","current":false},{"build":"20348.5386","title":null,"created":1784030400,"kb":"KB5099540","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5386/","current":true},{"build":"20348.5256","title":null,"created":1781006400,"kb":"KB5094128","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5256/","current":false},{"build":"20348.5139","title":null,"created":1778587200,"kb":"KB5087545","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5139/","current":false},{"build":"20348.5024","title":null,"created":1776600000,"kb":"KB5091575","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5024/","current":false},{"build":"20348.5020","title":null,"created":1776168000,"kb":"KB5082142","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5020/","current":false}],"history_total":94,"prev":{"build":"20348.5256","title":null,"created":1781006400,"kb":"KB5094128","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5256/","current":false},"next":{"build":"20348.5499","title":null,"created":1786449600,"kb":"KB5120242","build_type":"release","channel_label":"Release","kind":null,"url":"/builds/windowsserver/20348.5499/","current":false},"wave":[]},"source":"microsoft","indexable":true,"generated":1790176111}