Skip to content
anavem.com logoanavem.com logo
ResolvedMicrosoftHigh severityNewsWindows Update

Microsoft Ships KB5087538 May 2026 Security Update for Windows 10 1809 and Server 2019

The cumulative update moves affected systems to build 17763.8755 and carries several known issues, including installation failures on low-disk-space machines.

On this page

Key takeaways

  • KB5087538 was released May 12, 2026 for Windows 10 1809 and Windows Server 2019.
  • It updates the OS build to 17763.8755.
  • Fixes cover kernel-driver EoP, networking RCE, graphics info disclosure, TCP/IP DoS and auth bypass.
  • A restart is mandatory to complete installation.
  • Known issues include installation failure (0x80070070) on low-disk-space systems.

What to do now

High urgency
  1. Test KB5087538 in a non-production environment
  2. Ensure at least 2 GB free disk space before installing
  3. Deploy via Windows Update, WSUS, SCCM or Intune and schedule the mandatory restart

Microsoft released KB5087538 on May 12, 2026 as part of its regular Patch Tuesday cycle, delivering a cumulative security update for Windows 10 Version 1809 and Windows Server 2019. The update raises the operating system build to 17763.8755 and resolves multiple vulnerability categories spanning kernel-mode drivers, networking components, graphics subsystems, the TCP/IP stack and authentication mechanisms.

For organizations still running the 1809 branch and Windows Server 2019, the update closes flaws that could enable local privilege escalation to SYSTEM, remote code execution over the network, information disclosure, and denial of service.

Microsoft's KB5087538 security update moves Windows 10 1809 and Server 2019 to build 17763.8755 and fixes multiple vulnerabilities.

Install KB5087538 to patch Windows 10 1809 and Server 2019 to build 17763.8755; ensure at least 2 GB free disk space and plan a mandatory restart.

Affected & context

Event summary

KB5087538 is the May 12, 2026 Patch Tuesday security update for Windows 10 Version 1809 and Windows Server 2019, updating the OS to build 17763.8755 and addressing multiple vulnerability categories.

Why it matters

Windows Server 2019 and Windows 10 1809 remain widely deployed in enterprise environments, and the update resolves flaws that could allow privilege escalation, remote code execution and denial of service.

Who is affected

Organizations and users running Windows 10 Version 1809 (x86/x64) and Windows Server 2019, including Server Core, across all listed editions.

Vendors
Microsoft
Products
Windows 10 Version 1809Windows Server 2019
Geography
Global

What KB5087538 delivers

KB5087538 is a cumulative security update released on May 12, 2026 for Windows 10 Version 1809 and Windows Server 2019. It is part of Microsoft's regular Patch Tuesday release and updates affected systems to build 17763.8755.

According to Microsoft's update documentation, the release addresses several categories of vulnerabilities that could allow attackers to execute arbitrary code, escalate privileges, disclose information, or cause denial-of-service conditions on affected systems.

  • Elevation-of-privilege vulnerabilities in Windows kernel-mode drivers
  • Remote code execution vulnerabilities in Windows networking components
  • Information-disclosure vulnerabilities in Windows graphics components
  • Denial-of-service vulnerabilities in the Windows TCP/IP stack
  • Security-bypass vulnerabilities in Windows authentication mechanisms
  • OS build after install: 17763.8755
  • Release date: May 12, 2026

Affected systems

The update applies to Windows 10 Version 1809 on both 32-bit (x86) and 64-bit (x64) architectures, and to Windows Server 2019 (x64), including Server Core installations. All impacted systems move to build 17763.8755.

  • Windows 10 Home, Pro, Enterprise and Education
  • Windows Server 2019 Standard and Datacenter
  • Windows Server 2019 Server Core

Technical details of the fixes

Microsoft attributes the underlying issues to improper input validation across various Windows components, insufficient boundary checks in kernel-mode drivers, and inadequate memory management in networking subsystems.

The kernel-mode driver fixes add enhanced input validation for driver communication interfaces, improved boundary checking for memory operations, and stronger access controls for privileged operations, addressing local EoP paths to SYSTEM. Networking changes strengthen packet validation and protocol parsing in TCP/IP processing, SMB handling and network authentication services.

Graphics subsystem patches add proper memory initialization and access controls to prevent information disclosure through malformed graphics API calls. TCP/IP stack changes improve error handling for malformed packets and resource management for connections, while authentication fixes strengthen credential validation, token handling and session management.

Deployment and installation

The update is available through Windows Update, the Microsoft Update Catalog, WSUS, SCCM and Microsoft Intune. Microsoft classifies it as a high-priority security update and recommends installing it as soon as possible.

To verify installation via PowerShell:

PowerShellcheck-kb.ps1
Get-HotFix -Id KB5087538
  • A system restart is mandatory to complete installation.
  • Ensure at least 2 GB of free disk space on the system drive.
  • Test in non-production before broad rollout, especially with custom kernel-mode drivers or specialized networking software.
  • Schedule installation during maintenance windows for VMs on older hypervisor platforms.

Known issues

Low disk space can block installation

Installation may fail with error code 0x80070070 on systems with insufficient disk space. Free at least 2 GB on the system drive before attempting the update.

  • Brief network connectivity interruptions during installation, expected to resolve after the required restart.
  • Some third-party antivirus solutions may flag the installation process.
  • Temporary performance degradation on VMs running on older hypervisors, typically resolved after restart.

Timeline

  1. KB5087538 released

    Microsoft publishes KB5087538 as the May 2026 Patch Tuesday security update for Windows 10 1809 and Windows Server 2019, moving systems to build 17763.8755.

    Source: Microsoft KB5087538 documentation

    Confidence: Medium

Impact

KB5087538 patches multiple vulnerability classes on Windows 10 1809 and Server 2019, requiring a mandatory restart and adequate free disk space.

Business impact

Systems require a maintenance window and restart; unpatched systems remain exposed to privilege escalation and remote code execution risks.

Technical impact

Updates OS to build 17763.8755; installation needs roughly 1.2 GB (x64) or 950 MB (x86) during setup and a restart.

Security impact

Resolves kernel-driver EoP, networking RCE, graphics info disclosure, TCP/IP DoS and authentication-bypass vulnerabilities.

Affected audience: IT admins, MSPs, Windows Server 2019 operators

Action required.

Technical details

Affected versions
Windows 10 Version 1809 (build below 17763.8755), Windows Server 2019 (build below 17763.8755)
Patched versions
17763.8755

Detection methods

  • Get-HotFix -Id KB5087538 in PowerShell to confirm the update is installed

Mitigations

  • Install KB5087538 to reach build 17763.8755

Response

Customer guidance

Microsoft recommends installing this security update as soon as possible and ensuring adequate free disk space before installation.

Response status: Patched

Patch available: Yes

Workaround available: No

FAQ

What does KB5087538 resolve?

It resolves multiple security vulnerabilities on Windows 10 1809 and Windows Server 2019, including kernel-driver elevation of privilege, networking remote code execution, graphics information disclosure, TCP/IP denial of service, and authentication bypass.

Which systems need KB5087538?

Windows 10 Version 1809 (32-bit and 64-bit) and Windows Server 2019, including Server Core, across all listed editions.

What build does KB5087538 install?

It updates affected systems to build 17763.8755.

Why might installation fail with error 0x80070070?

This error indicates insufficient disk space. Free at least 2 GB on the system drive before installing.

The bottom line

KB5087538, released May 12, 2026, is a Patch Tuesday security update that brings Windows 10 1809 and Windows Server 2019 to build 17763.8755 and fixes multiple vulnerability categories.

Install KB5087538 to close privilege-escalation, RCE, info-disclosure, DoS and auth-bypass flaws on legacy 1809 and Server 2019 systems.

What happens next

Administrators should test and roll out the update, monitor for the documented known issues, and confirm the target build after restart.

What to do

Deploy KB5087538 after testing and verify build 17763.8755 with Get-HotFix.

Sources

  1. Microsoft · May 12, 2026 · Primary source

    Claims supported
    • KB5087538 released May 12, 2026 and updates build to 17763.8755
    • Vulnerability categories addressed and known issues
Reader actions
Was this helpful?
Rate this articleRate
13 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.