July 2026 Patch TuesdayKB5099538Out-of-band action

Microsoft · KB5099538

KB5099538 release notes, known issues and patch guidance

This official Microsoft Patch Tuesday update addresses 311 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2026-56155.

Product
Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more
Release
10.0.17763.9020
Published
2026-07-14
Updated
2026-07-14
Cycle
July 2026 Patch Tuesday
Out-of-band actionBlackTree recommended timinghigh confidence
311Vendor-linked CVEsComplete For Update
1Preserved revisionsCanonical history remains visible
0Known issuesVendor-documented context only

Archived official source

KB5099538 release notes and known issues

BlackTree retains a versioned copy of the official Microsoft article for evidence. These facts do not prove that this update fixes every linked product or CVE.

Official article
July 14, 2026—KB5099538 (OS Build 17763.9020) | Microsoft Support ↗
Known issues
Microsoft documents a known issue: We are currently not aware of any issues with this update..
CVEs named in article
CVE-2026-56155
Deployment sections
No prerequisite or restart section verified
Snapshot
Captured 27 Sept 2026, 08:30 UTC.

Action and evidence

Operational decision

Action type
Deploy Patch
Platform
Windows
Restart
yes
Vendor signal
Critical

Why this urgency

  • Fix Available
  • Active Exploitation Confirmed

Evidence signals kept separate

CISA KEV
Unknown
Confirmed exploitation
Confirmed
Vendor exploitability
Exploitation reported by the vendor source
Maximum CVSS
9.9 (CVSS 3.1, CVE-2026-57092)
Maximum EPSS
Not loaded for this patch record
Out-of-band action

BlackTree recommends an out-of-band change assessment. Do not wait for the normal patch window when this update applies, but still use tested deployment and rollback controls.

BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.

Environment override questions

  • Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?
  • Does this update affect an identity, management, backup or other control-plane system?
  • Are compensating controls tested and monitored until the selected patch window?

Deployment context

Effects and caveats

  • Use the vendor update channel or update catalogue entry for the applicable product release.
  • Plan a restart when the vendor remediation marks one as required.

Known data gaps

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.

Deployment plan

Guidance basis: Blacktree Generic

Prerequisites

  • Confirm the affected product, edition, architecture and current build before deployment.

Sequencing

  • Test the update in a representative ring before broad deployment.

Downtime

A restart is required. Plan service interruption and validation.

Rollback and recovery

  • Capture the current version and a recoverable backup or snapshot before the change.
  • Use the vendor-supported uninstall or recovery path when one is available.

Workarounds

  • No vendor workaround is asserted unless it appears in the official advisory.

Vulnerability relationships

Vendor-linked CVEs

The complete CVE relationship set is not available in this bounded record.

Linked CVEs
311
Confirmed exploited
1
PoC or lab evidence
2
Maximum CVSS
9.9
Open linked CVE review

Provenance

Field verification

  • Patch_identity_and_productsmsrc-cvrf/vendor-fixVerified Automatic · Retrieved 25 Aug 2026, 19:50 UTC
  • Cve_relationships_and_exploit_statusmsrc-cvrf/vulnerabilityVerified Automatic · Retrieved 25 Aug 2026, 19:50 UTC
Open official vendor source

Revision history

Canonical record changes

  1. Revision 12026-07-14

    Initial Patch Tuesday publication.

Publication review

The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner approved automatic Patch Tuesday publication. Each published record passed its own official-source completeness gate. Pending sources expose readiness only and prior approved records are retained on refresh failure.