Microsoft Releases Major Security Update for Windows 10, Patching Over 570 Vulnerabilities
In a significant move to bolster the security of its operating system, Microsoft has released the Windows 10 KB5099539 extended security update. This patch brings together not only the July 2026 Patch Tuesday security updates, which addressed an astonishing 570 vulnerabilities, but also additional fixes for known issues and security hardening changes.
The update is a crucial step in protecting users from various threats, including two exploited and one publicly disclosed zero-day flaws that were patched as part of today’s record-breaking Patch Tuesday. Microsoft has made it clear that this update is not only essential for Enterprise LTSC 2021 users but also for consumers who are enrolled in the Extended Security Updates (ESU) program.
For those who may be unfamiliar, the ESU program was initially limited to one year of extended security updates for consumers. However, last month, Microsoft quietly extended its free ESU program for an additional year, allowing enrolled devices to receive security updates until October 12, 2027. This means that users with Enterprise LTSC 2021 or those who are part of the ESU program can install this update like normal by going into Settings and manually checking for updates.
The KB5099539 update is primarily focused on security patches and bug fixes, rather than introducing new features to Windows 10. Among its many fixes are solutions to known issues with OLE Automation, File Explorer, Recycle Bin, Input, Secure Boot, Networking, and Remote Desktop (RDP) Security. One of the notable changes includes the introduction of SHA-2 certificate thumbprints for trusted RDP publishers, which will help reduce phishing risks by controlling which .rdp files users can open.
However, it’s essential to note that an intentional security hardening change may impact legacy applications that rely on unregistered third-party TDI transports. Microsoft warns that these apps might stop working after installing this update. To determine whether you are affected, check the Windows System event log in Event Viewer for AFD Event ID 16003 entries.
In practical terms, what does this mean for users? It’s crucial to install this update as soon as possible to ensure your device remains secure and protected from various threats. For those who may be concerned about potential disruptions or issues with legacy applications, Microsoft provides guidance on how to manage RDP file security through Group Policy. The company recommends IT administrators migrate to SHA-256 thumbprints or a stronger algorithm as soon as possible.
In conclusion, the Windows 10 KB5099539 extended security update is a significant step forward in protecting users from various threats. With over 570 vulnerabilities patched and additional fixes for known issues, it’s essential that all eligible users install this update without delay.
Source: Bleeping Computer — 2026-07-14