Security advisoryView advisory
MicrosoftCriticalResolved

Microsoft Patches Actively Exploited Windows 10 1809 Flaws in Emergency Update KB5091573

The April 19, 2026 out-of-band update patches actively exploited vulnerabilities in Windows 10 1809, including a kernel privilege escalation, a WDAC bypass, a TCP/IP stack RCE, and DLL hijacking flaws.

Emanuel De AlmeidaApr 20, 2026, 12:30 AM4 min read
Severity
Critical
Status
Resolved
Entity
Microsoft Windows 10 Version 1809
Confirmed by
Microsoft Security Response Center

Microsoft released KB5091573 on April 19, 2026, an out-of-band security update for Windows 10 Version 1809 patching four critical vulnerabilities that have been actively exploited in targeted attacks. The most severe, CVE-2026-28303, allows remote code execution through the TCP/IP stack without any user interaction.

Out-of-band releases are rare and indicate that the vulnerabilities pose an immediate threat. Combined with active exploitation confirmed by MSRC, this update demands immediate deployment on all Windows 10 1809 systems.

Key takeaways

  • KB5091573 is an out-of-band emergency patch released outside the Patch Tuesday cycle.
  • All four CVEs have been actively exploited in the wild, per MSRC.
  • CVE-2026-28301: kernel privilege escalation to SYSTEM via buffer overflow.
  • CVE-2026-28303: TCP/IP RCE requiring no user interaction.
  • The update covers Windows 10 1809 (all editions), updating to Build 17763.8647.

Affected

Vendors
Microsoft
Products
Windows 10 Version 1809
CVEs
CVE-2026-28301CVE-2026-28302CVE-2026-28303CVE-2026-28304

KB5091573: Microsoft Ships Emergency Patch for Actively Exploited Windows 10 1809 Flaws

Microsoft released KB5091573 on April 19, 2026, an out-of-band security update for Windows 10 Version 1809 that updates systems to Build 17763.8647. The emergency patch addresses four critical CVEs that have been actively exploited in targeted attacks, per the Microsoft Security Response Center. The out-of-band release signals these flaws were too severe to wait for the next Patch Tuesday.

CVE-2026-28301 is a kernel privilege escalation flaw that lets local attackers gain SYSTEM access via buffer overflow in memory allocation routines. CVE-2026-28302 bypasses Windows Defender Application Control (WDAC) policies through crafted executables. CVE-2026-28303 enables remote code execution in the TCP/IP stack without user interaction. CVE-2026-28304 covers multiple DLL hijacking vulnerabilities exploitable during application startup.

Actively Exploited: Why Immediate Patching Is Critical

The kernel escalation flaw (CVE-2026-28301) and the network-based RCE (CVE-2026-28303) are the most dangerous. The kernel flaw grants complete system control from a standard user account. The TCP/IP flaw requires no user interaction, making it a prime vector for worm-like attacks against internet-facing systems.

The WDAC bypass (CVE-2026-28302) undermines application whitelisting, a core enterprise defense. Attackers can run unauthorized code on WDAC-protected systems. The DLL hijacking flaws (CVE-2026-28304) affect multiple Windows components and can be triggered during routine service starts. Per MSRC, all four vulnerabilities have been exploited in the wild.

Affected Systems and Deployment Details

Windows 10 Version 1809 (all editions: Home, Pro, Enterprise, Education) running any build before 17763.8647 is vulnerable. The update supersedes KB5089234 (March 2026). It's available via Windows Update, WSUS, Configuration Manager, Intune, and Microsoft Update Catalog. File size is approximately 847 MB (x64) or 623 MB (x86). A restart is required.

Known issues

Installation may fail with error 0x800f0982 if disk space is insufficient (need 2 GB free). Some third-party antivirus tools may flag system files for 24 hours. Legacy network adapters may need driver updates after installation.

Timeline

Apr 19, 2026
KB5091573 released out-of-bandMicrosoft releases KB5091573 as an out-of-band emergency patch for four actively exploited CVEs in Windows 10 1809.

Impact & actions

Four actively exploited vulnerabilities in Windows 10 1809 allow kernel-level compromise, WDAC bypass, network-based RCE, and DLL hijacking.

Security: CVE-2026-28301 grants SYSTEM access from standard user. CVE-2026-28303 enables RCE via crafted TCP/IP packets with no user interaction. Both actively exploited.

Recommended actions · Immediate urgency

  1. 1Install KB5091573 immediately.
  2. 2Verify installation: Get-HotFix -Id KB5091573.
  3. 3Plan migration off Windows 10 1809 to a current supported version.

Technical details

CVEs
CVE-2026-28301, CVE-2026-28302, CVE-2026-28303, CVE-2026-28304
Exploitation
Exploited in the wild
Attack vector
Network (CVE-2026-28303), Local (CVE-2026-28301, CVE-2026-28302, CVE-2026-28304)
Affected versions
Windows 10 1809 Build 17763.x (all builds before 17763.8647)
Patched versions
Windows 10 1809 Build 17763.8647

Mitigations

  • Install KB5091573 immediately.
  • Restrict network exposure of unpatched systems via firewall rules.
  • Enforce WDAC policies with updated code integrity definitions.

Response

Vendor

Microsoft strongly recommends immediate deployment across all affected systems. The vulnerabilities have been actively exploited in targeted attacks.
Patch / advisory

FAQ

What does KB5091573 fix?

KB5091573 patches four critical CVEs: CVE-2026-28301 (kernel privilege escalation), CVE-2026-28302 (WDAC bypass), CVE-2026-28303 (TCP/IP remote code execution), and CVE-2026-28304 (DLL hijacking). It also strengthens the Windows Update client. All four vulnerabilities have been actively exploited.

Are these vulnerabilities being actively exploited?

Yes. Per MSRC, the vulnerabilities have been actively exploited in targeted attacks. The out-of-band release outside Patch Tuesday signals critical severity.

Which systems need KB5091573?

Windows 10 Version 1809 (October 2018 Update), all editions (Home, Pro, Enterprise, Education), running any build before 17763.8647. x64, x86, and ARM64 architectures.

Are there known issues?

Known issues include error 0x800f0982 if less than 2 GB disk space is available, temporary antivirus false positives (24 hours), and possible network issues with legacy adapters requiring driver updates.

The bottom line

KB5091573 is an emergency out-of-band patch for four actively exploited vulnerabilities in Windows 10 1809, including kernel escalation, WDAC bypass, network RCE, and DLL hijacking.

What happens next

These fixes will be included in the next monthly cumulative update. The companion patch KB5091572 addresses similar flaws in Windows 10 1607.

What to do

Install KB5091573 and verify with Get-HotFix -Id KB5091573. Check Build 17763.8647.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles