Microsoft’s July 2026 cumulative update for Windows 10, KB5099539, is now available to devices enrolled in the Extended Security Updates (ESU) program. It’s shipping via Windows Update and also as offline .msu packages in the Microsoft Update Catalog. According to coverage from Windows Latest and Neowin, this release focuses on tightening Remote Desktop security, hardening parts of the networking stack, and cleaning up a handful of lingering bugs.
Who gets KB5099539
Both sources note the update targets supported Windows 10 releases under ESU. Neowin specifies versions 21H2 and 22H2, and Windows Latest reports the build numbers advance to 19045.7548 (22H2) and 19044.7548 (Enterprise LTSC 2021) after installation. Windows Latest also points out that the .msu offline installers will not apply unless ESU is already active on the device.
If you’re checking manually, Windows Latest says the label to look for is “2026-07 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5099539).” The Update Catalog download is around 1.06GB.
What’s new and what to watch for
The most consequential change lands on the Remote Desktop side. KB5099539 adds support for SHA-2 certificate thumbprints for trusted RDP publishers. SHA-1 remains for backward compatibility for now, but both reports note Microsoft plans to remove it in the future. Microsoft has also published new guidance to manage RDP file security through Group Policy so organizations can control which .rdp files users are allowed to open—useful against phishing attempts that rely on malicious RDP files. If you’re still using SHA-1 thumbprints, the recommendation is to migrate to SHA-256 or stronger.
Networking gets a security hardening update that enforces TDI transport registration. Apps that use sockets over unregistered third-party TDI transports might stop working after this update. Registered transports are not affected. In practice, this is more likely to affect older networking or VPN software that never registered correctly. If you depend on such tools, plan for verification after deploying KB5099539.
Microsoft also lists several fixes and adjustments:
- OLE Automation: Resolves a compatibility issue in oleaut32.dll introduced by June’s security update. Some apps using IDispatch::Invoke with BYREF parameters that share the same storage could fail with parameter marshaling or automation errors; this is corrected.
- File Explorer and OneDrive: Fixes a problem where the OneDrive shortcut in File Explorer stopped working when Explorer ran with administrative rights.
- Recycle Bin: Corrects a bug where the permanent-delete confirmation dialog sometimes showed an internal Recycle Bin file name instead of the original file name.
- Input hotkeys: Changes to hotkey unregister and cleanup behavior could, in rare cases, make some built-in Windows experiences stop responding to certain shortcuts temporarily. Restarting the affected app typically resolves it; Microsoft asks for reports via Feedback Hub if not.
- Secure Boot: Enables dynamic status reporting for Secure Boot states in the Windows Security app and expands device targeting for automatic delivery of new Secure Boot certificates. Microsoft says certificate deployment via Windows Update continues in the coming months on eligible devices.
How to get the update
- Windows Update: Settings > Update & Security > Windows Update.
- Microsoft Update Catalog: Offline .msu packages are available, useful for administrators handling multiple PCs or working around Windows Update issues. Per Windows Latest, these installers require ESU to be active on the device.
If your environment relies on older third-party networking or VPN components, test those scenarios promptly after updating. For RDP, start planning the move to SHA‑2 (for example, SHA‑256) certificate thumbprints ahead of Microsoft’s stated future removal of SHA‑1 support.
Sources: Windows Latest and Neowin.
Alex Mira is a fictitious AI-assisted author created for the Toolslib blog. Designed to support cybersecurity education, Alex writes about malware trends, software utilities, privacy practices, Windows internals, and practical defensive workflows. Articles published under Alex’s name are generated or assisted by AI and reviewed according to Toolslib’s editorial standards before publication.
Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!