Security advisory
Patch TuesdayCriticalResolved

Microsoft Ships KB5094123 for Windows Server 2019, Patching Five CVEs

The cumulative security update targets Enterprise, Education and Server 2019 systems still under extended support, closing kernel RCE, CLFS privilege escalation and three other flaws.

Emanuel De AlmeidaJun 10, 2026, 12:21 AM4 min read
Severity
Critical
Status
Resolved
Entity
Microsoft
Confirmed by
Microsoft update documentation

Microsoft released KB5094123 on June 9, 2026, a cumulative security update for Windows 10 Version 1809 and Windows Server 2019 that addresses five CVE-tracked vulnerabilities and moves the OS build number to 17763.8880. The most severe is a critical Windows kernel remote code execution flaw, CVE-2026-26001, with a reported CVSS score of 8.8.

For organizations still running these legacy platforms under extended support, the update closes a remotely exploitable kernel flaw and a local CLFS privilege escalation issue that could each lead to full system compromise.

Key takeaways

  • KB5094123 shipped on June 9, 2026, in Microsoft's monthly Patch Tuesday cycle.
  • It patches five CVEs, including critical kernel RCE CVE-2026-26001 (CVSS 8.8).
  • The update raises the OS build number to 17763.8880.
  • It targets Windows 10 1809 (Enterprise/Education) and Windows Server 2019, including Server Core.
  • A restart is required and the update bundles a servicing stack update (SSU).

Affected

Vendors
Microsoft
Products
Windows 10 Version 1809Windows Server 2019
Geography
Global
CVEs
CVE-2026-26001CVE-2026-26002CVE-2026-26003CVE-2026-26004CVE-2026-26005

What KB5094123 fixes

KB5094123 is the June 2026 cumulative security update for Windows 10 Version 1809 and Windows Server 2019. Microsoft describes it as addressing five distinct CVE-identified vulnerabilities that range from remote code execution to a security feature bypass. Installing it moves the operating system build number to 17763.8880.

Because Windows 10 Version 1809 reached end of service for Home and Pro editions in November 2020, this update is primarily relevant to Enterprise and Education editions still receiving extended support, alongside Windows Server 2019 deployments, including Server Core.

  • Released June 9, 2026
  • OS build after update: 17763.8880
  • Five CVEs addressed

Vulnerabilities addressed

Per Microsoft's description, the update resolves two higher-severity flaws and three additional important issues:

  • CVE-2026-26001 — Windows kernel remote code execution, reported CVSS 8.8. Described as exploitable via specially crafted network requests due to flaws in kernel memory management.
  • CVE-2026-26002 — Common Log File System (CLFS) privilege escalation allowing a local attacker to gain SYSTEM privileges; the fix modifies clfs.sys validation.
  • CVE-2026-26003 — Windows Graphics Component information disclosure that could expose kernel memory contents.
  • CVE-2026-26004 — Windows TCP/IP denial of service triggered by malformed network packets; the fix hardens tcpip.sys packet handling.
  • CVE-2026-26005 — Windows Defender Application Control (WDAC) security feature bypass that could permit unauthorized code execution despite policy.

Microsoft attributes the root causes to insufficient input validation and boundary checks in core Windows components, including improper memory allocation handling in kernel-mode drivers.

Verify the CVSS figure

The CVSS 8.8 score for CVE-2026-26001 comes from the supplied source material. Confirm CVE severity, exploitation status and any exploitability index rating against the official Microsoft Security Update Guide before publishing.

Affected systems

According to the update documentation, the following platforms are affected and updated to build 17763.8880:

  • Windows 10 Version 1809, x86 (32-bit)
  • Windows 10 Version 1809, x64 (64-bit)
  • Windows Server 2019, x64
  • Windows Server 2019 (Server Core), x64

How to deploy and verify

The update is delivered through Windows Update and is also available via WSUS, Microsoft Configuration Manager (SCCM) and Microsoft Intune. Standalone packages can be downloaded from the Microsoft Update Catalog for offline or custom deployment. A restart is required to complete installation, and a servicing stack update (SSU) is bundled to support future updates.

After installation, administrators can confirm the patch is present and the build has advanced to 17763.8880:

Get-HotFix -Id KB5094123
Get-ComputerInfo | Select-Object WindowsVersion, WindowsBuildLabEx

Disk space

Microsoft notes systems with less than 2 GB of free disk space may fail installation with error 0x80070070. Free up space with Disk Cleanup before deploying.

Known issues

  • Installation failures with error 0x80070070 on systems with under 2 GB free disk space.
  • Some third-party antivirus products may flag files modified by the update as suspicious; check with the vendor for updated definitions.

Timeline

Jun 9, 2026
KB5094123 releasedMicrosoft publishes KB5094123 as part of the June 2026 Patch Tuesday, raising the OS build to 17763.8880.

Impact & actions

Systems that do not install KB5094123 remain exposed to a critical kernel RCE, a SYSTEM-level privilege escalation, information disclosure, denial of service and a WDAC bypass.

Security: CVE-2026-26005 could undermine WDAC application control policies used to enforce security baselines.

Privacy: CVE-2026-26003 could expose sensitive kernel memory contents such as cryptographic keys.

Recommended actions · High urgency

  1. 1Test and deploy KB5094123 across affected 1809 and Server 2019 systems
  2. 2Verify OS build 17763.8880 after restart
  3. 3Prioritize network-exposed and multi-user systems

Technical details

CVEs
CVE-2026-26001, CVE-2026-26002, CVE-2026-26003, CVE-2026-26004, CVE-2026-26005
CVSS
8.8
Attack vector
Network (CVE-2026-26001, CVE-2026-26004); local (CVE-2026-26002)
Affected versions
Windows 10 Version 1809 (before 17763.8880), Windows Server 2019 (before 17763.8880)
Patched versions
17763.8880

Mitigations

  • Install KB5094123 through Windows Update, WSUS, SCCM or Intune

Response

Customer guidance

Microsoft advises deploying the update via Windows Update or enterprise tools, testing in a controlled environment before broad rollout, and ensuring at least 2 GB of free disk space.

FAQ

What does KB5094123 do?

It is the June 2026 cumulative security update for Windows 10 Version 1809 and Windows Server 2019, addressing five CVE-tracked vulnerabilities and raising the OS build to 17763.8880.

How do I confirm KB5094123 is installed?

Run Get-HotFix -Id KB5094123 in PowerShell, and verify the OS build shows 17763.8880 using Get-ComputerInfo.

Which systems need KB5094123?

Windows 10 Version 1809 (Enterprise and Education editions under extended support) and Windows Server 2019, including Server Core installations.

Is a restart required?

Yes. A system restart is required to complete installation, and the update includes a servicing stack update.

The bottom line

KB5094123, released June 9, 2026, patches five CVEs in Windows 10 1809 and Windows Server 2019, including a critical kernel RCE, and moves the build to 17763.8880.

What happens next

Administrators should schedule testing and deployment across affected fleets and monitor for the documented disk-space and antivirus-compatibility issues.

What to do

Deploy KB5094123 and confirm build 17763.8880 after restart.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles