KB5073722 - Windows Server 2016 / Windows 10 LTSB 2016 Security Update (January 13, 2026)
KB5073722 is the January 13, 2026 cumulative security update for Windows Server 2016 and Windows 10 Enterprise LTSB 2016, bringing OS Build 14393.8783.

Summary
KB5073722 is the cumulative security update released on January 13, 2026 for Windows Server 2016 and Windows 10 Enterprise LTSB 2016, bringing both products to OS Build 14393.8783. It incorporates all fixes shipped in prior cumulative updates through December 2025 and addresses several security hardening areas. Source: Microsoft Support.
Highlights
- Credential autofill is now restricted during remote support sessions and automated authentication workflows, preventing credential dialogs from responding to virtual keyboard input from remote desktop or screen-sharing tools.
- Windows Deployment Services (WDS) no longer supports hands-free deployment functionality by default; administrators must review the WDS Hands-Free Deployment Hardening Guidance.
- Several legacy modem drivers have been removed from Windows entirely.
- The WinSqlite3.dll core component has been updated to resolve false-positive vulnerability detections by some security software.
Improvements and fixes
- Credentials autofill (security hardening): The update restricts certain applications from autofilling credentials during remote support sessions or automated authentication workflows. Credential dialogs will no longer respond to virtual keyboard input sent by remote desktop or screen-sharing tools. Administrators can find additional guidance in the linked Microsoft article on this new behavior.
- Windows Deployment Services (WDS) - Windows Server 2016 only: WDS will stop supporting hands-free deployment by default after this update. Admins should consult the WDS Hands-Free Deployment Hardening Guidance to understand the impact and required configuration steps.
- Driver removal: The modem drivers agrsm64.sys (x64), agrsm.sys (x86), smserl64.sys (x64), and smserial.sys (x86) have been removed from Windows. Any modem hardware that relies exclusively on these drivers will no longer function after this update is installed.
- WinSqlite3.dll update: The Windows core component WinSqlite3.dll has been updated. Prior to this fix, certain security software could flag this file as vulnerable. Note that WinSqlite3.dll is distinct from sqlite3.dll, which lives in application-specific directories and is not a Windows component. If a security product continues to flag sqlite3.dll, the appropriate course of action is to contact the application developer, or - if the file belongs to a Microsoft app - install the latest version of that app from the Microsoft Store.
- Change log addition (February 12, 2026): Microsoft added an improvement for credentials autofill to this update after the original release date.
Known issues
Microsoft lists no known issues for this update at the time of writing.
How to get this update
Prerequisite - Servicing Stack Update (SSU): Before installing KB5073722 on any device or offline image, Microsoft strongly recommends installing the latest Servicing Stack Update, KB5073447. Without it, this update may not be offered to the device, increasing security risk. WSUS administrators must explicitly approve both KB5073447 and KB5073722.
Delivery channels:
- Windows Update / Microsoft Update: KB5073722 downloads and installs automatically. The latest SSU (KB5073447) is offered automatically alongside it.
- Windows Update for Business: The update deploys automatically in accordance with configured policies. The SSU is also offered automatically.
- Microsoft Update Catalog: Download the standalone package directly from the Catalog website. Microsoft recommends also downloading and installing KB5073447 manually if it is not already present.
- Windows Server Update Services (WSUS): The update syncs automatically when Products and Classifications are configured as Product: Windows 10, Classification: Security Updates. WSUS administrators must also approve SSU KB5073447 separately.
A CSV file listing all files included in this cumulative update is available for download from the Microsoft Support page.
Frequently asked questions
Does the credentials autofill change affect all remote desktop scenarios?
The new hardening behavior restricts credential dialogs from responding to virtual keyboard input sent by remote desktop or screen-sharing tools and applications. This applies to remote support sessions and automated authentication workflows. Microsoft has published a dedicated article titled "New behavior restricting certain applications to autofill credentials introduced by the Windows January 2026 security update" with full details.
What should I do if a modem stops working after installing this update?
This update permanently removes four modem drivers: agrsm64.sys, agrsm.sys, smserl64.sys, and smserial.sys. Any modem hardware that depends solely on these drivers will no longer function in Windows after installation. Microsoft does not document a workaround; administrators should identify affected hardware before deploying this update broadly.
Is the WDS hands-free deployment change relevant to Windows 10 LTSB 2016 devices?
No. Based on the page content, the WDS hands-free deployment hardening change is documented only under the Windows Server 2016 section of this update. The Windows 10 Enterprise LTSB 2016 section does not include this item among its listed fixes.
When do Windows Server 2016 and Windows 10 LTSB 2016 reach end of support?
Microsoft has published the following end-of-support dates: Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB both reach end of support on October 13, 2026. Windows Server 2016 reaches end of support on January 12, 2027. After those dates, free updates, technical assistance, and security fixes will no longer be provided.

