Microsoft released KB5087539, a security update for Windows Server 2025, on May 12, 2026. The update patches multiple vulnerabilities across the Windows kernel, Active Directory Domain Services and Remote Desktop Services, and raises the operating system build to 26100.32860 on both standard and Server Core installations.
According to the update documentation, the flaws span remote code execution, elevation of privilege and information disclosure — categories that directly threaten domain controllers and member servers — so administrators are advised to treat it as a high-priority deployment.
Key takeaways
- KB5087539 was released on May 12, 2026 for Windows Server 2025 and brings the build to 26100.32860.
- It addresses vulnerabilities documented with CVSS scores ranging from 7.0 to 9.8.
- Fixes cover the kernel, Active Directory Domain Services, Remote Desktop Services, Server Core and Windows Defender Application Control.
- It applies to Standard and Datacenter editions in both Desktop Experience and Server Core.
- Domain controllers should be updated in a staggered fashion to preserve AD replication.
Affected
What KB5087539 fixes
KB5087539 is a cumulative security update for Windows Server 2025 released on May 12, 2026. It resolves multiple vulnerabilities described as ranging from important to critical, and updates the operating system build to 26100.32860 after a required restart.
The documented fixes span several server subsystems. Highlights include:
- A critical remote code execution flaw in the Windows kernel that could allow code execution with SYSTEM privileges.
- An elevation of privilege flaw in Active Directory Domain Services affecting domain controllers.
- An information disclosure vulnerability in Remote Desktop Services related to session isolation.
- A security feature bypass specific to Server Core installations.
- Improvements to Windows Defender Application Control (WDAC) code integrity validation.
- OS build after install: 26100.32860
- Documented CVSS range: 7.0 to 9.8
Affected systems
The update applies to all Windows Server 2025 editions and installation types:
- Windows Server 2025 Standard — Desktop Experience and Server Core
- Windows Server 2025 Datacenter — Desktop Experience and Server Core
Server Core installations receive the same security improvements as Desktop Experience deployments and require no additional configuration, though administrators should confirm automatic restart policies match their maintenance windows.
Technical details
According to the update documentation, the underlying issues stem from improper input validation, memory management weaknesses and insufficient access controls in components including the kernel, Remote Desktop Services, Active Directory services and core system libraries.
Kernel
The update strengthens memory boundary checking and input validation in kernel-mode drivers to prevent arbitrary code execution with SYSTEM privileges.
Active Directory Domain Services
Authentication mechanisms and access control validation for domain operations are hardened to prevent unauthorized privilege escalation on domain controllers.
Remote Desktop Services
RDS components receive session isolation and memory protection improvements intended to prevent information leakage between sessions.
Deployment and verification
KB5087539 is delivered via Windows Update and is available for manual download from the Microsoft Update Catalog. Enterprises can deploy it through WSUS, Microsoft Configuration Manager (SCCM) or Microsoft Intune. Installation requires a minimum of 1.2 GB free disk space and a system restart, with an estimated 15–30 minute install time.
Stagger domain controller updates
Update domain controllers in a staggered approach and allow sufficient time between updates for Active Directory replication to complete normally.
After installation and restart, administrators can confirm the update using PowerShell:
Get-HotFix -Id KB5087539
[System.Environment]::OSVersion.VersionThe build number should display as 26100.32860 after a successful install.
- Minimum 1.2 GB free disk space required
- Restart required; ~15–30 minute install
Known issues
The update documentation lists several known issues:
- Installation may fail with error 0x80070643 when there is insufficient disk space — ensure at least 1.2 GB free.
- Domain controllers may experience temporary AD replication delays that typically resolve within 30 minutes of restart.
- Users may need to restart Remote Desktop Services sessions for all security improvements to take effect.
For installation failures, the documented workaround is to stop the Windows Update service, clear the SoftwareDistribution cache, and restart the service. For replication issues, monitor status with repadmin /showrepl and allow up to 30 minutes. Microsoft advises against rolling back the update given the severity of the vulnerabilities it addresses.
Timeline
Impact & actions
Windows Server 2025 systems that skip KB5087539 remain exposed to vulnerabilities that could enable remote code execution, administrative privilege escalation and information disclosure.
Security: Addresses documented remote code execution, elevation of privilege and information disclosure vulnerabilities rated up to CVSS 9.8.
Privacy: Information disclosure fixes in Remote Desktop Services reduce the risk of unauthorized access to sensitive data between sessions.
Recommended actions · High urgency
- 1Deploy KB5087539 to Windows Server 2025 systems within your maintenance window.
- 2Ensure at least 1.2 GB free disk space before installation.
- 3Update domain controllers in a staggered manner and verify AD replication afterward.
- 4Verify the build reaches 26100.32860 after restart.
Technical details
- CVSS
- 9.8
- Affected versions
- Windows Server 2025 (pre-26100.32860)
- Patched versions
- 26100.32860
Mitigations
- Install KB5087539 via Windows Update, Update Catalog, WSUS, SCCM or Intune.
Response
Customer guidance
The update documentation advises organizations to prioritize deployment due to the critical nature of the vulnerabilities, to stagger domain controller updates to preserve AD availability, and not to roll back the update.
FAQ
What does KB5087539 resolve?
It resolves multiple Windows Server 2025 vulnerabilities, including a critical remote code execution flaw in the kernel, elevation of privilege issues in Active Directory Domain Services, and information disclosure vulnerabilities in Remote Desktop Services.
Which systems require KB5087539?
All Windows Server 2025 editions — Standard and Datacenter — in both Desktop Experience and Server Core installation types. The update brings the OS build to 26100.32860.
How severe is KB5087539?
The update documentation describes vulnerabilities with CVSS scores ranging from 7.0 to 9.8, so it should be treated as a high-priority security update.
What are the prerequisites for KB5087539?
It requires a minimum of 1.2 GB free disk space on the system drive and a system restart. No specific prerequisite updates are required.
Are there known issues with KB5087539?
Yes — possible installation failures with error 0x80070643 due to low disk space, temporary Active Directory replication delays on domain controllers, and the need to restart RDS sessions to activate all improvements.
The bottom line
KB5087539, released May 12, 2026, patches multiple Windows Server 2025 vulnerabilities across the kernel, AD Domain Services and Remote Desktop Services, updating the build to 26100.32860.
What happens next
What to do






