Security advisory
Windows ServerCriticalResolved

Microsoft Ships KB5087539 Security Update for Windows Server 2025

The May 2026 cumulative security update addresses vulnerabilities rated CVSS 7.0 to 9.8 and is flagged as a high-priority patch for domain controllers and member servers.

Emanuel De AlmeidaMay 13, 2026, 1:17 AM5 min read
Severity
Critical
Status
Resolved
Entity
Microsoft
Confirmed by
KB5087539 update documentation

Microsoft released KB5087539, a security update for Windows Server 2025, on May 12, 2026. The update patches multiple vulnerabilities across the Windows kernel, Active Directory Domain Services and Remote Desktop Services, and raises the operating system build to 26100.32860 on both standard and Server Core installations.

According to the update documentation, the flaws span remote code execution, elevation of privilege and information disclosure — categories that directly threaten domain controllers and member servers — so administrators are advised to treat it as a high-priority deployment.

Key takeaways

  • KB5087539 was released on May 12, 2026 for Windows Server 2025 and brings the build to 26100.32860.
  • It addresses vulnerabilities documented with CVSS scores ranging from 7.0 to 9.8.
  • Fixes cover the kernel, Active Directory Domain Services, Remote Desktop Services, Server Core and Windows Defender Application Control.
  • It applies to Standard and Datacenter editions in both Desktop Experience and Server Core.
  • Domain controllers should be updated in a staggered fashion to preserve AD replication.

Affected

Vendors
Microsoft
Products
Windows Server 2025 StandardWindows Server 2025 Datacenter
Geography
Global

What KB5087539 fixes

KB5087539 is a cumulative security update for Windows Server 2025 released on May 12, 2026. It resolves multiple vulnerabilities described as ranging from important to critical, and updates the operating system build to 26100.32860 after a required restart.

The documented fixes span several server subsystems. Highlights include:

  • A critical remote code execution flaw in the Windows kernel that could allow code execution with SYSTEM privileges.
  • An elevation of privilege flaw in Active Directory Domain Services affecting domain controllers.
  • An information disclosure vulnerability in Remote Desktop Services related to session isolation.
  • A security feature bypass specific to Server Core installations.
  • Improvements to Windows Defender Application Control (WDAC) code integrity validation.
  • OS build after install: 26100.32860
  • Documented CVSS range: 7.0 to 9.8

Affected systems

The update applies to all Windows Server 2025 editions and installation types:

  • Windows Server 2025 Standard — Desktop Experience and Server Core
  • Windows Server 2025 Datacenter — Desktop Experience and Server Core

Server Core installations receive the same security improvements as Desktop Experience deployments and require no additional configuration, though administrators should confirm automatic restart policies match their maintenance windows.

Technical details

According to the update documentation, the underlying issues stem from improper input validation, memory management weaknesses and insufficient access controls in components including the kernel, Remote Desktop Services, Active Directory services and core system libraries.

Kernel

The update strengthens memory boundary checking and input validation in kernel-mode drivers to prevent arbitrary code execution with SYSTEM privileges.

Active Directory Domain Services

Authentication mechanisms and access control validation for domain operations are hardened to prevent unauthorized privilege escalation on domain controllers.

Remote Desktop Services

RDS components receive session isolation and memory protection improvements intended to prevent information leakage between sessions.

Deployment and verification

KB5087539 is delivered via Windows Update and is available for manual download from the Microsoft Update Catalog. Enterprises can deploy it through WSUS, Microsoft Configuration Manager (SCCM) or Microsoft Intune. Installation requires a minimum of 1.2 GB free disk space and a system restart, with an estimated 15–30 minute install time.

Stagger domain controller updates

Update domain controllers in a staggered approach and allow sufficient time between updates for Active Directory replication to complete normally.

After installation and restart, administrators can confirm the update using PowerShell:

Get-HotFix -Id KB5087539
[System.Environment]::OSVersion.Version

The build number should display as 26100.32860 after a successful install.

  • Minimum 1.2 GB free disk space required
  • Restart required; ~15–30 minute install

Known issues

The update documentation lists several known issues:

  • Installation may fail with error 0x80070643 when there is insufficient disk space — ensure at least 1.2 GB free.
  • Domain controllers may experience temporary AD replication delays that typically resolve within 30 minutes of restart.
  • Users may need to restart Remote Desktop Services sessions for all security improvements to take effect.

For installation failures, the documented workaround is to stop the Windows Update service, clear the SoftwareDistribution cache, and restart the service. For replication issues, monitor status with repadmin /showrepl and allow up to 30 minutes. Microsoft advises against rolling back the update given the severity of the vulnerabilities it addresses.

Timeline

May 12, 2026
KB5087539 releasedMicrosoft publishes the KB5087539 security update for Windows Server 2025, raising the build to 26100.32860.

Impact & actions

Windows Server 2025 systems that skip KB5087539 remain exposed to vulnerabilities that could enable remote code execution, administrative privilege escalation and information disclosure.

Security: Addresses documented remote code execution, elevation of privilege and information disclosure vulnerabilities rated up to CVSS 9.8.

Privacy: Information disclosure fixes in Remote Desktop Services reduce the risk of unauthorized access to sensitive data between sessions.

Recommended actions · High urgency

  1. 1Deploy KB5087539 to Windows Server 2025 systems within your maintenance window.
  2. 2Ensure at least 1.2 GB free disk space before installation.
  3. 3Update domain controllers in a staggered manner and verify AD replication afterward.
  4. 4Verify the build reaches 26100.32860 after restart.

Technical details

CVSS
9.8
Affected versions
Windows Server 2025 (pre-26100.32860)
Patched versions
26100.32860

Mitigations

  • Install KB5087539 via Windows Update, Update Catalog, WSUS, SCCM or Intune.

Response

Customer guidance

The update documentation advises organizations to prioritize deployment due to the critical nature of the vulnerabilities, to stagger domain controller updates to preserve AD availability, and not to roll back the update.

FAQ

What does KB5087539 resolve?

It resolves multiple Windows Server 2025 vulnerabilities, including a critical remote code execution flaw in the kernel, elevation of privilege issues in Active Directory Domain Services, and information disclosure vulnerabilities in Remote Desktop Services.

Which systems require KB5087539?

All Windows Server 2025 editions — Standard and Datacenter — in both Desktop Experience and Server Core installation types. The update brings the OS build to 26100.32860.

How severe is KB5087539?

The update documentation describes vulnerabilities with CVSS scores ranging from 7.0 to 9.8, so it should be treated as a high-priority security update.

What are the prerequisites for KB5087539?

It requires a minimum of 1.2 GB free disk space on the system drive and a system restart. No specific prerequisite updates are required.

Are there known issues with KB5087539?

Yes — possible installation failures with error 0x80070643 due to low disk space, temporary Active Directory replication delays on domain controllers, and the need to restart RDS sessions to activate all improvements.

The bottom line

KB5087539, released May 12, 2026, patches multiple Windows Server 2025 vulnerabilities across the kernel, AD Domain Services and Remote Desktop Services, updating the build to 26100.32860.

What happens next

Administrators should schedule deployment across their Windows Server 2025 estate and confirm the build number after restart. Watch for the documented known issues on domain controllers and RDS hosts.

What to do

Deploy KB5087539 within your maintenance window and stagger domain controller updates.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles