Anavem
Languagefr
Windows server room displaying system update installation screens
Knowledge BaseKB5087538Windows Update

KB5087538 — May 2026 Security Update for Windows 10 Version 1809 and Windows Server 2019

KB5087538 is a May 2026 security update that addresses multiple vulnerabilities in Windows 10 Version 1809 and Windows Server 2019, including critical security fixes for Windows kernel and networking components.

13 May 2026 12 min read
KB5087538Windows UpdateSecurity Update 5 fixes 12 min Windows 10 Version 1809 (32-bit and x64-based Systems) +2Download
Quick Overview

KB5087538 is a May 12, 2026 security update for Windows 10 Version 1809 and Windows Server 2019 systems. This update addresses multiple security vulnerabilities and updates the OS build to 17763.8755. The update is delivered automatically through Windows Update and includes critical security patches for kernel-mode drivers and networking components.

PowerShellCheck if KB5087538 is installed
PS C:\> Get-HotFix -Id KB5087538

# Returns patch details if KB5087538 is installed

Download Update

Download from Microsoft Update Catalog

Get the official update package directly from Microsoft

KB5087538
Diagnostic

Issue Description

Issue Description

This security update addresses several vulnerabilities that could allow attackers to execute arbitrary code, escalate privileges, or cause denial of service conditions on affected systems. The following security issues are resolved:

  • Elevation of privilege vulnerabilities in Windows kernel-mode drivers
  • Remote code execution vulnerabilities in Windows networking components
  • Information disclosure vulnerabilities in Windows graphics components
  • Denial of service vulnerabilities in Windows TCP/IP stack
  • Security bypass vulnerabilities in Windows authentication mechanisms

Without this update, systems remain vulnerable to potential exploitation through these attack vectors.

Analysis

Root Causes

Root Cause

The vulnerabilities addressed by KB5087538 stem from improper input validation in various Windows components, insufficient boundary checks in kernel-mode drivers, and inadequate memory management in networking subsystems. These coding defects allow malicious actors to potentially compromise system integrity through crafted requests or malformed data packets.

Overview

KB5087538 is a comprehensive security update released on May 12, 2026, for Windows 10 Version 1809 and Windows Server 2019 systems. This update addresses multiple critical and important security vulnerabilities across various Windows components, updating the operating system build to 17763.8755. The update is part of Microsoft's regular Patch Tuesday release cycle and includes essential security fixes to protect systems from potential exploitation.

Security Vulnerabilities Addressed

This security update resolves several categories of vulnerabilities that pose significant risks to system security and stability. The vulnerabilities addressed include elevation of privilege issues in kernel-mode drivers, remote code execution flaws in networking components, information disclosure vulnerabilities in graphics subsystems, denial of service weaknesses in TCP/IP implementation, and authentication bypass vulnerabilities.

These security issues could potentially allow attackers to gain unauthorized access to systems, execute malicious code remotely, access sensitive information, disrupt system operations, or bypass security controls. The fixes implemented in KB5087538 strengthen the overall security posture of affected Windows systems.

Affected Systems and Compatibility

The update applies to the following Windows versions and editions:

Operating SystemArchitectureBuild NumberStatus
Windows 10 Version 180932-bit (x86)17763.8755Supported
Windows 10 Version 180964-bit (x64)17763.8755Supported
Windows Server 201964-bit (x64)17763.8755Supported
Windows Server 2019 (Server Core)64-bit (x64)17763.8755Supported

All editions of these operating systems, including Home, Pro, Enterprise, and Education editions for Windows 10, and Standard and Datacenter editions for Windows Server 2019, are covered by this update.

Installation Methods and Requirements

Organizations and individual users can obtain and install KB5087538 through several channels. Windows Update provides automatic delivery for most consumer and small business environments. Enterprise customers can leverage WSUS, SCCM, or Microsoft Intune for centralized deployment and management.

The update requires approximately 1.2 GB of disk space for 64-bit systems and 950 MB for 32-bit systems during the installation process. A system restart is mandatory to complete the installation and activate all security fixes. Installation time typically ranges from 15 to 45 minutes depending on system specifications and configuration.

Security Enhancements and Technical Details

The kernel-mode driver fixes address multiple elevation of privilege vulnerabilities that could allow local attackers to gain SYSTEM-level access. These fixes include enhanced input validation for driver communication interfaces, improved boundary checking for memory operations, and strengthened access controls for privileged operations.

Networking component updates resolve critical remote code execution vulnerabilities in TCP/IP processing, SMB protocol handling, and network authentication services. The fixes implement enhanced packet validation, improved memory management, and strengthened protocol parsing to prevent exploitation through malformed network traffic.

Graphics subsystem patches prevent information disclosure attacks by implementing proper memory initialization and enhanced access controls for graphics memory operations. These fixes ensure that sensitive memory contents cannot be accessed through malformed graphics API calls.

TCP/IP stack improvements address denial of service vulnerabilities through better error handling for malformed packets, enhanced resource management for network connections, and improved validation of network protocol parameters. These changes increase system resilience against network-based attacks.

Authentication mechanism enhancements strengthen credential validation, token handling, and authentication protocol implementations. The fixes include enhanced cryptographic validation and improved session management to prevent authentication bypass attacks.

Deployment Considerations

Enterprise administrators should test this update in non-production environments before widespread deployment. The update is compatible with existing group policies and security configurations. However, organizations using custom kernel-mode drivers or specialized networking software should verify compatibility before deployment.

Virtual machine environments may experience temporary performance impacts during installation, particularly on older hypervisor platforms. Planning installation during maintenance windows is recommended for critical production systems.

Systems with limited disk space may encounter installation failures. Administrators should ensure adequate free space is available before initiating the update process. The Windows Update troubleshooter can help resolve common installation issues.

Important: This security update addresses critical vulnerabilities. Microsoft recommends installing this update as soon as possible to maintain system security.
Resolution Methods

Key Fixes & Changes

01

Fixes elevation of privilege vulnerabilities in Windows kernel-mode drivers

This update patches multiple elevation of privilege vulnerabilities in Windows kernel-mode drivers that could allow local attackers to gain SYSTEM privileges. The fixes include improved input validation for driver communication interfaces and enhanced boundary checking for memory operations. Affected drivers include display drivers, storage drivers, and system service drivers.

02

Resolves remote code execution vulnerabilities in Windows networking components

The update addresses critical remote code execution vulnerabilities in Windows networking stack components, including TCP/IP processing, SMB protocol handling, and network authentication services. These fixes prevent attackers from executing arbitrary code by sending specially crafted network packets to vulnerable systems. Enhanced packet validation and improved memory management are implemented.

03

Patches information disclosure vulnerabilities in Windows graphics components

Security fixes are applied to Windows graphics subsystem components to prevent information disclosure attacks. The vulnerabilities could allow attackers to read sensitive memory contents through malformed graphics API calls. The update implements proper memory initialization and enhanced access controls for graphics memory operations.

04

Addresses denial of service vulnerabilities in Windows TCP/IP stack

The update resolves multiple denial of service vulnerabilities in the Windows TCP/IP implementation that could cause system crashes or service interruptions. Fixes include improved error handling for malformed packets, enhanced resource management for network connections, and better validation of network protocol parameters.

05

Fixes security bypass vulnerabilities in Windows authentication mechanisms

Security enhancements are implemented in Windows authentication subsystems to prevent bypass attacks. The fixes address weaknesses in credential validation, token handling, and authentication protocol implementations. Enhanced cryptographic validation and improved session management are included to strengthen authentication security.

Validation

Installation

Installation

KB5087538 is available through multiple deployment channels:

Windows Update

The update is automatically delivered to eligible systems through Windows Update. Systems configured for automatic updates will receive and install this update during the next update cycle.

Microsoft Update Catalog

Manual download is available from the Microsoft Update Catalog for offline installation or deployment through enterprise management tools. The update package size is approximately 1.2 GB for x64 systems and 950 MB for 32-bit systems.

Windows Server Update Services (WSUS)

Enterprise environments using WSUS can approve and deploy this update through their existing update infrastructure. The update is classified as a Security Update with high priority.

System Center Configuration Manager (SCCM)

SCCM administrators can deploy this update using software update management workflows. The update supports both online and offline installation scenarios.

Prerequisites

No specific prerequisites are required for this update. However, systems should have sufficient disk space (minimum 2 GB free) and be running a supported version of Windows 10 Version 1809 or Windows Server 2019.

Restart Requirements

A system restart is required after installing this update to complete the installation process and activate all security fixes.

If it still fails

Known Issues

Known Issues

Microsoft has identified the following known issues with KB5087538:

Installation Failures on Systems with Limited Disk Space

Installation may fail with error code 0x80070070 on systems with insufficient disk space. Ensure at least 2 GB of free space is available on the system drive before attempting installation.

Temporary Network Connectivity Issues

Some systems may experience brief network connectivity interruptions during the update installation process. This is expected behavior as networking components are updated and should resolve automatically after the required restart.

Third-Party Antivirus Compatibility

Certain third-party antivirus solutions may flag the update installation process as suspicious activity. Temporarily disable real-time protection during installation if installation failures occur.

Virtual Machine Performance Impact

Virtual machines running on older hypervisor platforms may experience temporary performance degradation during the update process. This typically resolves after the post-installation restart.

Note: If you encounter issues not listed here, use the Windows Update troubleshooter or contact Microsoft Support for assistance.

Frequently Asked Questions

What does KB5087538 resolve?+
KB5087538 resolves multiple security vulnerabilities in Windows 10 Version 1809 and Windows Server 2019, including elevation of privilege issues in kernel-mode drivers, remote code execution flaws in networking components, information disclosure vulnerabilities in graphics subsystems, denial of service weaknesses in TCP/IP implementation, and authentication bypass vulnerabilities.
Which systems require KB5087538?+
KB5087538 applies to Windows 10 Version 1809 (both 32-bit and 64-bit systems) and Windows Server 2019 (including Server Core installations). All editions of these operating systems, including Home, Pro, Enterprise, Education, Standard, and Datacenter editions, require this security update.
Is KB5087538 a security update?+
Yes, KB5087538 is a security update that addresses multiple critical and important security vulnerabilities. It is part of Microsoft's regular Patch Tuesday release cycle and includes essential security fixes to protect systems from potential exploitation through various attack vectors.
What are the prerequisites for KB5087538?+
No specific prerequisites are required for KB5087538. However, systems should have sufficient disk space (minimum 2 GB free) and be running a supported version of Windows 10 Version 1809 or Windows Server 2019. A system restart is required after installation to complete the update process.
Are there known issues with KB5087538?+
Known issues include potential installation failures on systems with limited disk space (error 0x80070070), temporary network connectivity interruptions during installation, possible compatibility issues with certain third-party antivirus solutions, and temporary performance impacts on virtual machines running on older hypervisor platforms.

References (3)

Discussion

Share your thoughts and insights

Sign in to join the discussion