KB5075906: Windows Server 2022 Cumulative Update - February 10, 2026 (OS Build 20348.4773)
February 2026 security cumulative update for Windows Server 2022, bringing OS build 20348.4773 with security fixes, quality improvements, and a new DNS feature.

Summary
This is the February 10, 2026 security cumulative update for Windows Server 2022, released as KB5075906 and bringing the OS to build 20348.4773. It is a monthly security update that also incorporates non-security fixes from the January 2026 optional preview release. See Microsoft Support for full details.
Highlights
- Fixes a File Explorer folder-renaming bug where custom names defined via
LocalizedResourceNameindesktop.inifiles were not displayed correctly. - Updates Chinese fonts to support the GB18030-2022A standard for improved character coverage and display.
- Resolves a system crash (
KERNEL_SECURITY_CHECK_FAILUREindxgmms2.sys) affecting certain GPU configurations. - Fixes a known issue where Virtual Secure Mode (VSM) devices could not shut down or hibernate after the January 13, 2026 security update, restarting instead.
- Adds an optional DNS Server feature that randomly shuffles resource records in responses, reducing the risk of a single record becoming overloaded.
Improvements and fixes
- File Explorer: A bug has been corrected where renaming folders that contain
desktop.inifiles did not work as expected. TheLocalizedResourceNamesetting was being ignored, causing custom folder names to fail to appear. - Fonts and display: Chinese fonts have been updated to meet the GB18030-2022A standard, improving character coverage and on-screen rendering.
- Graphics: A system error tied to
dxgmms2.sys- which triggered aKERNEL_SECURITY_CHECK_FAILUREstop error on some GPU configurations - has been resolved. - OS security (known issue resolution): Devices running Virtual Secure Mode (VSM) that were unable to shut down or enter hibernation after installing the January 13, 2026 or later Windows security update - restarting instead - are now fixed by this update.
- Networking - new feature: Windows Server now supports random shuffling of DNS Server resource records in query responses. This prevents a single resource record from becoming a bottleneck simply because it appears first in the list. To enable the feature, create a DWORD registry value named
RandomShuffleset to1atComputer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters. Set the value to0to disable it.
Known issues
WSUS synchronization error details not displayed
Symptom: After installing KB5070884 or a later update, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting interface.
Workaround: Microsoft states this functionality has been temporarily removed to address the Remote Code Execution vulnerability CVE-2025-59287. No workaround is documented on the page at this time.
How to get this update
Microsoft now combines the latest servicing stack update (SSU) with the latest cumulative update (LCU) in a single package. This update is available through the following channels:
- Windows Update / Microsoft Update: Downloads and installs automatically.
- Windows Update for Business: Deploys automatically in line with configured policies.
- Microsoft Update Catalog: A standalone package can be downloaded directly from the Microsoft Update Catalog website.
- Windows Server Update Services (WSUS): Syncs automatically when Products and Classifications are configured as Product -
Microsoft Server operating system-21H2and Classification -Security Updates.
Prerequisite for offline OS image servicing: The offline image must include KB5030216 (released September 12, 2023) or a later LCU before this update is applied. That update brings the SSU to version 20348.1960, which is the minimum required to avoid error 0x800f0823 (CBS_E_NEW_SERVICING_STACK_REQUIRED).
Removing the LCU: Use the DISM /Remove-Package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the package includes the SSU, which cannot be removed after installation.
Important - Secure Boot certificate expiration: Secure Boot certificates used by most Windows devices are scheduled to begin expiring in June 2026. Microsoft has been distributing updated certificates to consumer and non-managed business devices. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance.
Frequently asked questions
Does this update include fixes beyond the February 2026 security patches?
Yes. In addition to the February 2026 security fixes, KB5075906 includes quality improvements from three earlier releases: KB5073457 (January 13, 2026), KB5077800 (January 17, 2026), and KB5078136 (January 24, 2026). Devices with those updates already installed will download only the new components in this package.
What is the servicing stack update bundled with this release?
The accompanying servicing stack update is KB5075905, bringing the SSU to version 20348.4763. Microsoft now ships the SSU and LCU together in one combined package. The SSU component cannot be uninstalled after installation, so only the LCU portion can be removed via DISM /Remove-Package.
How do I enable the new DNS random record shuffling feature?
Create a DWORD registry value named RandomShuffle with a data value of 1 at the path Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS\Parameters. To disable the feature, set the value to 0 or delete the key. No restart requirement is documented on the page.
Will the AI component updates in this package install on Windows Server?
No. Although this cumulative update includes AI component updates - applicable to Windows Copilot+ PCs - the AI components will not install on standard Windows PCs or Windows Server machines. They are included in the package but are only applicable to Copilot+ hardware.









