NAVANEM
Security updateOS build 20348.4648

KB5073457: Windows Server 2022 Security Update (OS Build 20348.4648) - January 2026

January 2026 cumulative security update for Windows Server 2022, delivering OS build 20348.4648 with security fixes, quality improvements, and four known issues.

KB5073457: Windows Server 2022 Security Update (OS Build 20348.4648) - January 2026 — navanem Microsoft KB cover
KB5073457 · Windows Server · Security Update

Summary

KB5073457 is the January 2026 cumulative security update for Windows Server 2022, released on January 13, 2026, producing OS Build 20348.4648. It bundles the latest security fixes together with non-security improvements carried over from the prior optional preview release. A companion servicing stack update (KB5074428, version 20348.4640) is included. Full details are on Microsoft Support.

Improvements and fixes

  • Compatibility: Several legacy modem drivers have been removed - agrsm64.sys (x64), agrsm.sys (x86), smserl64.sys (x64), and smserial.sys (x86). Any modem hardware that depends on these specific drivers will no longer function under Windows after this update is applied.
  • Credentials autofill: A new security-hardening behavior restricts certain applications from autofilling credentials during remote support sessions or automated authentication workflows. Credential dialogs will no longer respond to virtual keyboard input sent by remote desktop or screen-sharing tools and apps.
  • Remote Desktop: A bug causing the SearchIndexer service to stop responding on Citrix hosts has been fixed. The hang could prevent users from starting new remote sessions on affected systems.
  • Windows Deployment Services (WDS): WDS will no longer support hands-free deployment functionality by default following this update. Microsoft has published separate hardening guidance for IT administrators managing WDS environments.
  • WinSqlite3.dll: The core Windows component WinSqlite3.dll has been updated to address a condition in which some security software incorrectly flagged it as vulnerable. Note that this component is distinct from the application-specific sqlite3.dll found in app directories, which is not a Windows component.

Known issues

WSUS does not display synchronization error details

Symptom: After installing KB5070884 or any later update, Windows Server Update Services (WSUS) no longer displays synchronization error details within its error-reporting interface. This functionality was temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287.

Workaround: Microsoft has not listed a separate workaround or resolution KB for this item at this time. The removal of the error-detail display is intentional as a security measure.

Connection and authentication failures in Azure Virtual Desktop and Windows 365

Symptom: After installing this January 2026 security update, credential prompt failures occurred during Remote Desktop connections using the Windows App on Windows client devices. The issue affects Azure Virtual Desktop and Windows 365 users on specific Windows builds, resulting in sign-in failures.

Workaround: This issue is addressed in KB5077800.

Apps might become unresponsive when saving files to cloud-based storage

Symptom: Following installation of this update, some applications may become unresponsive or encounter unexpected errors when opening or saving files to cloud-based storage services such as OneDrive or Dropbox. In certain Outlook configurations where PST files are stored on OneDrive, Outlook may hang and fail to reopen unless the process is terminated or the system is restarted. Missing sent items or previously downloaded emails being re-downloaded have also been reported.

Workaround: This issue is addressed in KB5078136.

Some devices with Virtual Secure Mode enabled might fail to shut down or hibernate

Symptom: On some Secure Launch-capable PCs with Virtual Secure Mode (VSM) enabled, the device is unable to shut down or enter hibernation after this update is installed. Instead of shutting down or hibernating, the device restarts.

Workaround: This issue is addressed in KB5075906.

How to get this update

Before installing, be aware that Microsoft now combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package. For offline OS image servicing, the target image must include KB5030216 (released 09/12/2023) or a later LCU before this update is applied. That prerequisite sets the SSU to version 20348.1960, which is the minimum required to avoid error 0x800f0823 (CBS_E_NEW_SERVICING_STACK_REQUIRED).

This update is available through the following channels:

  • Windows Update / Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Deploys automatically in accordance with configured policies.
  • Microsoft Update Catalog: A standalone package can be downloaded directly from the catalog website.
  • Windows Server Update Services (WSUS): Syncs automatically when Products is set to "Microsoft Server operating system-21H2" and Classification is set to "Security Updates."

To remove only the LCU after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe with the /uninstall switch will not work on the combined package because it also contains the SSU, and the SSU cannot be removed after installation.

Frequently asked questions

Does this update include the servicing stack, or do I need to install it separately?

Microsoft now ships the servicing stack update (SSU) and the cumulative update (LCU) as a single combined package. KB5073457 incorporates SSU KB5074428 at version 20348.4640. You do not need to locate or install the SSU as a separate step when deploying through standard channels.

Why do credential dialogs no longer respond to virtual keyboard input from remote tools?

This is an intentional security-hardening change introduced by this update. Credential dialogs are now restricted from accepting virtual keyboard input sent by remote desktop or screen-sharing applications during remote support sessions or automated authentication workflows. Administrators should review Microsoft's guidance on the new autofill behavior before deploying broadly.

What should I do if my WDS hands-free deployments stop working after this update?

This update changes WDS behavior so that hands-free deployment functionality is disabled by default. Microsoft has published dedicated hardening guidance titled "Windows Deployment Services (WDS) Hands-Free Deployment Hardening Guidance" to help IT administrators reconfigure their environments to account for this change.

How do I address the known issue with apps hanging when saving to OneDrive or Dropbox?

Microsoft has confirmed a resolution for the cloud-storage responsiveness issue in KB5078136. Administrators should deploy that update to affected Windows Server 2022 systems. The Outlook-specific symptoms - including hangs, missing sent items, and repeated email re-downloads - are also covered by that resolution.

#windows-server-2022#security-update#cumulative-update#Remote Desktop#servicing-stack#credentials-autofill#wds

Related topics