Microsoft released KB5094122 on June 9, 2026, a critical cumulative security update for Windows 10 Version 1607 (Anniversary Update) and Windows Server 2016. The update patches multiple documented vulnerabilities across the Windows Kernel, Common Log File System (CLFS) Driver, Graphics Component and Print Spooler, and raises the operating system build number to 14393.9234.
Because Windows Server 2016 is still common in production, admins should prioritize deployment: the update fixes remote code execution and privilege escalation flaws that could allow full system compromise.
Key takeaways
- KB5094122 was released on June 9, 2026 for Windows 10 1607 and Windows Server 2016.
- It patches four CVEs: CVE-2026-26001 through CVE-2026-26004.
- The update raises the build number to 14393.9234.
- A system restart is required to complete installation.
- Known issues include install error 0x80070643 and temporary Print Spooler connectivity problems.
Affected
What Microsoft released
KB5094122 is the June 2026 cumulative security update for Windows 10 Version 1607 (Anniversary Update) and Windows Server 2016, released on June 9, 2026. It applies to 32-bit and x64 Windows 10 1607, and to Windows Server 2016 Standard, Datacenter and Server Core installations.
After installation, the operating system build number advances from 14393.9233 to 14393.9234. Newer Windows 10 releases and Windows 11 receive separate updates under different KB numbers.
- Build number after install: 14393.9234
- Restart required to complete installation
Vulnerabilities addressed
According to Microsoft's documentation, the update resolves four vulnerabilities in core Windows components:
- CVE-2026-26001 — Windows Kernel remote code execution, tied to improper validation of user-mode data passed to kernel functions.
- CVE-2026-26002 — Windows CLFS Driver privilege escalation, allowing a local attacker to reach SYSTEM through insufficient access control validation.
- CVE-2026-26003 — Windows Graphics Component remote code execution via specially crafted image or graphics data causing buffer overflows.
- CVE-2026-26004 — Windows Print Spooler information disclosure that could expose sensitive print job or configuration data.
Microsoft attributes the root causes to improper input validation and memory management, including insufficient bounds checking in kernel-mode drivers and inadequate validation of user-supplied data in graphics routines.
- CLFS flaw can escalate a local attacker to SYSTEM
Affected systems
The update targets the following unpatched platforms:
- Windows 10 Version 1607 (32-bit and x64)
- Windows Server 2016 Standard and Datacenter
- Windows Server 2016 Server Core
How to deploy and verify
The update is delivered automatically through Windows Update and is also available for manual installation via the Microsoft Update Catalog. Enterprises can deploy it through WSUS (Security Updates category), SCCM software update management, or Windows Update for Business policies via Intune and Group Policy.
Verify installation
Confirm the patch is present with PowerShell, and check that System Information reports build 14393.9234:
Get-HotFix -Id KB5094122- Minimum 1 GB free disk space required
- Install time roughly 15-30 minutes
Known issues
Microsoft's documentation lists several post-install issues admins should watch for:
- Installation may fail with error code 0x80070643 during configuration; the Windows Update Troubleshooter, freeing disk space, or the standalone Catalog package can help.
- Some network printers may become temporarily unavailable; restarting the Print Spooler service (net stop spooler && net start spooler) typically resolves it.
- Systems with older graphics hardware may see minor performance degradation from enhanced security checks; updating graphics drivers can help.
Isolate systems you can't patch
Microsoft advises isolating systems that cannot install this update from network access until alternative security measures are in place or the systems are upgraded to a supported version.
Timeline
Impact & actions
Unpatched Windows 10 1607 and Windows Server 2016 systems remain exposed to remote code execution and local privilege escalation until KB5094122 is applied.
Security: Addresses remote code execution, privilege escalation to SYSTEM, information disclosure and denial-of-service conditions.
Privacy: The Print Spooler flaw (CVE-2026-26004) could expose sensitive print job or configuration data before patching.
Recommended actions · High urgency
- 1Deploy KB5094122 to all Windows 10 1607 and Windows Server 2016 systems
- 2Restart systems to complete installation
- 3Verify build number is 14393.9234 after install
- 4Isolate systems that cannot be patched from the network
Technical details
- CVEs
- CVE-2026-26001, CVE-2026-26002, CVE-2026-26003, CVE-2026-26004
- Affected versions
- 14393.9233
- Patched versions
- 14393.9234
Mitigations
- Install KB5094122 and restart
- Isolate unpatchable systems from network access
- Restrict administrative privileges and use standard user accounts
Response
Customer guidance
Microsoft recommends installing KB5094122 as soon as possible due to the critical nature of the vulnerabilities, alongside best practices such as enabling antimalware and firewall protection, restricting admin privileges, and keeping software and drivers updated.
FAQ
How do I check if KB5094122 is installed?
Run Get-HotFix -Id KB5094122 in PowerShell, or confirm the build number reads 14393.9234 in System Information (msinfo32) or Settings > System > About.
What build does KB5094122 install?
After installation, Windows 10 Version 1607 and Windows Server 2016 report build 14393.9234, up from 14393.9233.
Does KB5094122 require a restart?
Yes. A system restart is required to complete installation, which takes roughly 15-30 minutes depending on the system.
What if installation fails with error 0x80070643?
Run the Windows Update Troubleshooter and ensure at least 1 GB of free disk space. If it still fails, download and install the standalone package from the Microsoft Update Catalog.
The bottom line
KB5094122 is the June 9, 2026 cumulative security update for Windows 10 1607 and Windows Server 2016, patching four CVEs across the kernel, CLFS, graphics and Print Spooler, and raising the build to 14393.9234.
What happens next
What to do






