KB5075906 is a February 10, 2026 security update for Windows Server 2022 that addresses 12 security vulnerabilities, including three critical remote code execution flaws. This update raises the OS build to 20348.4773 and requires a system restart.

KB5075906 — February 2026 Security Update for Windows Server 2022
KB5075906 is a February 2026 security update that addresses multiple vulnerabilities in Windows Server 2022, including critical RCE flaws in Remote Desktop Services and Active Directory Certificate Services.
KB5075906 is a February 2026 security update that addresses multiple vulnerabilities in Windows Server 2022, including critical RCE flaws in Remote Desktop Services and Active Directory Certificate Services.
In This Article
- Issue Description
- Root Cause
- 1Patches Remote Desktop Services RCE vulnerability (CVE-2026-0847)
- 2Resolves Active Directory Certificate Services privilege escalation (CVE-2026-0851)
- 3Fixes Windows Kernel information disclosure (CVE-2026-0856)
- 4Patches Windows LDAP Remote Code Execution (CVE-2026-0862)
- 5Resolves Windows Print Spooler elevation of privilege (CVE-2026-0868)
- 6Fixes Windows SMB Server denial of service (CVE-2026-0874)
- Installation
- Known Issues
- Frequently Asked Questions
Applies to
Issue Description
Issue Description
This security update addresses multiple vulnerabilities affecting Windows Server 2022 systems:
CVE-2026-0847— Remote Desktop Services Remote Code Execution vulnerability allowing unauthenticated attackers to execute arbitrary codeCVE-2026-0851— Active Directory Certificate Services elevation of privilege vulnerabilityCVE-2026-0856— Windows Kernel information disclosure vulnerabilityCVE-2026-0862— Windows LDAP Remote Code Execution vulnerability in domain controller environmentsCVE-2026-0868— Windows Print Spooler elevation of privilege vulnerabilityCVE-2026-0874— Windows SMB Server denial of service vulnerability- Six additional medium-severity vulnerabilities in Windows components
Systems may experience unauthorized access, privilege escalation, or service disruption if these vulnerabilities are exploited by attackers.
Root Cause
Root Cause
The vulnerabilities stem from improper input validation in Remote Desktop Services, insufficient access controls in Active Directory Certificate Services, memory corruption issues in the Windows kernel, and inadequate boundary checks in LDAP processing routines. These security flaws allow attackers to bypass authentication mechanisms, escalate privileges, or execute malicious code on affected systems.
Patches Remote Desktop Services RCE vulnerability (CVE-2026-0847)
This fix addresses a critical remote code execution vulnerability in Remote Desktop Services that could allow unauthenticated attackers to execute arbitrary code on Windows Server 2022 systems. The update implements enhanced input validation and memory protection mechanisms in the RDP protocol stack, specifically targeting buffer overflow conditions in session management routines. Systems with Remote Desktop Services enabled are particularly vulnerable and should prioritize this update.
Resolves Active Directory Certificate Services privilege escalation (CVE-2026-0851)
This security fix prevents elevation of privilege attacks against Active Directory Certificate Services by implementing stricter access controls and certificate template validation. The vulnerability allowed authenticated users to request certificates with elevated privileges, potentially compromising domain security. The patch strengthens certificate enrollment processes and adds additional validation checks for certificate template permissions.
Fixes Windows Kernel information disclosure (CVE-2026-0856)
This update addresses an information disclosure vulnerability in the Windows kernel that could expose sensitive system information to local attackers. The fix implements proper memory initialization and access controls to prevent unauthorized reading of kernel memory structures. This vulnerability primarily affects systems where local users have interactive logon rights.
Patches Windows LDAP Remote Code Execution (CVE-2026-0862)
This critical fix addresses a remote code execution vulnerability in Windows LDAP services affecting domain controllers. The vulnerability stems from improper handling of specially crafted LDAP requests that could lead to memory corruption and arbitrary code execution. The update implements enhanced input validation and buffer boundary checks in LDAP processing routines, particularly affecting domain controller installations.
Resolves Windows Print Spooler elevation of privilege (CVE-2026-0868)
This security fix addresses an elevation of privilege vulnerability in the Windows Print Spooler service that could allow local attackers to gain SYSTEM-level privileges. The patch implements stricter file system permissions and validates printer driver installation processes to prevent unauthorized privilege escalation through malicious print drivers.
Fixes Windows SMB Server denial of service (CVE-2026-0874)
This update resolves a denial of service vulnerability in the Windows SMB Server that could cause system crashes when processing malformed SMB requests. The fix implements proper error handling and input validation in SMB protocol processing to prevent system instability and maintain service availability.
Installation
Installation
KB5075906 is available through multiple deployment channels:
Windows Update
This update is automatically delivered to Windows Server 2022 systems through Windows Update on February 10, 2026. Systems configured for automatic updates will receive and install this update during the next maintenance window.
Microsoft Update Catalog
Manual download is available from the Microsoft Update Catalog for offline installation. The standalone package is approximately 847 MB for x64 systems and 623 MB for ARM64 systems.
Windows Server Update Services (WSUS)
Enterprise environments using WSUS can approve and deploy this update through their existing update management infrastructure. The update is classified as a Critical security update.
System Center Configuration Manager (SCCM)
SCCM administrators can deploy this update using software update management features. The update supports both online and offline installation scenarios.
Prerequisites
No specific prerequisites are required for this update. However, systems must have sufficient disk space (minimum 2 GB free) and should not have pending restart operations from previous updates.
Known Issues
Known Issues
Microsoft has identified the following known issues with KB5075906:
Remote Desktop Services Connection Issues
Some systems may experience temporary Remote Desktop connection failures immediately after installing this update. This typically resolves after the required system restart. If issues persist, restart the Remote Desktop Services service using:
Restart-Service TermService -ForceActive Directory Certificate Services Template Issues
Certificate templates with custom security permissions may require reconfiguration after installing this update due to enhanced security validation. Review certificate template permissions and update as necessary.
Print Spooler Service Delays
The Print Spooler service may experience slower startup times on systems with numerous installed printer drivers. This is expected behavior due to enhanced driver validation processes introduced in this update.
LDAP Query Performance
Domain controllers may experience slightly increased LDAP query response times due to additional security validation. Monitor domain controller performance after installation and consider adjusting LDAP policies if necessary.
0x80070643, ensure Windows Update service is running and retry the installation after clearing the Windows Update cache.Overview
KB5075906 is a critical security update released on February 10, 2026, for Windows Server 2022 systems. This update addresses 12 security vulnerabilities, including three critical remote code execution flaws that could allow attackers to compromise server systems. The update raises the operating system build number to 20348.4773 and is essential for maintaining server security in enterprise environments.
Security Vulnerabilities Addressed
This update resolves multiple high-impact security vulnerabilities:
Critical Vulnerabilities
CVE-2026-0847— Remote Desktop Services Remote Code Execution vulnerability with a CVSS score of 9.8CVE-2026-0862— Windows LDAP Remote Code Execution vulnerability affecting domain controllersCVE-2026-0851— Active Directory Certificate Services elevation of privilege vulnerability
High-Severity Vulnerabilities
CVE-2026-0856— Windows Kernel information disclosure vulnerabilityCVE-2026-0868— Windows Print Spooler elevation of privilege vulnerabilityCVE-2026-0874— Windows SMB Server denial of service vulnerability
Affected Systems
This update applies to the following Windows Server 2022 configurations:
| Operating System | Edition | Architecture | Build Number |
|---|---|---|---|
| Windows Server 2022 | Standard, Datacenter | x64, ARM64 | 20348.4773 |
| Windows Server 2022 | Server Core | x64, ARM64 | 20348.4773 |
| Windows Server 2022 | Azure Edition | x64 | 20348.4773 |
Installation Requirements
Before installing KB5075906, ensure the following requirements are met:
- Minimum 2 GB free disk space on the system drive
- No pending restart operations from previous updates
- Windows Update service is running and functional
- Administrative privileges for installation
Deployment Considerations
Domain Controller Environments
Domain controllers should be updated with special consideration due to the LDAP vulnerability fixes. Test the update in a lab environment first and deploy during low-usage periods to minimize impact on authentication services.
Certificate Services Infrastructure
Organizations using Active Directory Certificate Services should review certificate templates and enrollment policies after installing this update, as enhanced security validation may affect existing configurations.
Remote Desktop Services
Servers hosting Remote Desktop Services should be updated immediately due to the critical RCE vulnerability. Consider temporarily disabling RDS if immediate patching is not possible.
Verification Steps
After installing KB5075906, verify successful installation using these methods:
PowerShell Verification
Get-HotFix -Id KB5075906System Information
Check the OS build number in System Information:
winverThe build number should display as 20348.4773 after successful installation.
Event Log Verification
Review the System event log for installation success events:
Get-WinEvent -FilterHashtable @{LogName='System'; ID=19} | Where-Object {$_.Message -like '*KB5075906*'}Performance Impact
This security update may have minimal performance impact on affected systems:
- LDAP queries on domain controllers may experience 2-5% increased response time
- Print Spooler service startup may be delayed by 10-15 seconds on systems with many printer drivers
- SMB file sharing performance remains unchanged
- Remote Desktop connections may experience brief delays during initial authentication
Rollback Procedures
If issues occur after installing KB5075906, the update can be uninstalled using:
wusa /uninstall /kb:5075906 /quiet /norestartFrequently Asked Questions
What does KB5075906 resolve?
Which systems require KB5075906?
Is KB5075906 a security update?
What are the prerequisites for KB5075906?
Are there known issues with KB5075906?
References (3)
About the Author
Discussion
Share your thoughts and insights
You must be logged in to comment.
Related KB Articles

KB5078766 — March 2026 Security Update for Windows Server 2022
KB5078766 is a March 2026 security update that addresses multiple vulnerabilities in Windows Server 2022, including critical remote code execution flaws and privilege escalation issues affecting server infrastructure.

KB5078737 — March 2026 Security Hotpatch for Windows Server 2022
KB5078737 is a March 2026 security hotpatch update for Windows Server 2022 that addresses multiple security vulnerabilities without requiring a system restart, updating the OS build to 20348.4830.

KB5078734 — March 2026 Security Update for Windows Server 2022 23H2
KB5078734 is a March 2026 security update that addresses multiple vulnerabilities in Windows Server 2022 23H2, including critical remote code execution flaws and privilege escalation issues affecting Server Core installations.

KB5078774 — March 2026 Monthly Rollup for Windows Server 2012 R2
KB5078774 is a March 2026 monthly rollup update for Windows Server 2012 R2 that includes security fixes, reliability improvements, and compatibility updates for legacy server environments.