NAVANEM
Security updateOS build 26100.32690

KB5082063 - Windows Server 2025 Cumulative Update (OS Build 26100.32690) April 2026

April 14, 2026 security cumulative update for Windows Server 2025, delivering OS build 26100.32690 with security fixes, Kerberos, Bluetooth, RDP, and networking improvements.

KB5082063: Windows Server 2025 Cumulative Update (OS Build 26100.32690) April 2026 — navanem Microsoft KB cover
KB5082063 · Windows Server · Security Update

Summary

KB5082063 is the April 14, 2026 security cumulative update for Windows Server 2025, bringing OS build 26100.32690 to April 14, 2026. It includes the latest security fixes plus non-security improvements carried forward from the previous month's optional preview release. See Microsoft Support for full details.

Highlights

  • Secure Boot certificate update coverage is expanded, with Windows quality updates now including additional high-confidence device targeting data to reach more devices eligible for new certificates automatically.
  • A phishing protection improvement for Remote Desktop (.rdp) files now shows all requested connection settings before connecting, with each setting off by default and a one-time security warning on first use.
  • Domain controllers and environments using Privileged Access Management (PAM) received an out-of-band fix (KB5091157) addressing repeated LSASS crash restarts introduced by this update.
  • Windows Deployment Services Hands-Free Deployment is disabled by default and is no longer a supported feature.

Improvements and fixes

  • Secure Boot: Quality updates now carry additional high-confidence device targeting data, broadening automatic delivery of new Secure Boot certificates in a phased rollout. The update also fixes a bug where devices could enter BitLocker Recovery after Secure Boot updates were applied.
  • Kerberos protocol: The default DefaultDomainSupportedEncTypes value for Kerberos Key Distribution Center (KDC) operations has changed to use AES-SHA1 for accounts that lack an explicit msds-SupportedEncryptionTypes Active Directory attribute, related to CVE-2026-20833.
  • Authentication: Windows now correctly reads configured Kerberos encryption policy settings during authentication, ensuring encryption behavior is applied consistently across the domain.
  • Bluetooth: Bluetooth device management in Settings and Quick Settings is improved so that connected devices appear more consistently and are easier to add and manage.
  • Graphics: Color rendering is improved when printing from Win32 desktop applications.
  • Networking: SMB compression over QUIC is more reliable; compression requests now complete more consistently, reducing timeouts.
  • PowerShell: The Set-GPPrefRegistryValue cmdlet now preserves registry preference values in full when importing, including the final character of each value.
  • Remote Desktop: Protection against phishing via .rdp files is strengthened. Remote Desktop now displays all requested connection settings before connecting, with each setting turned off by default, plus a one-time security warning on first use per device.
  • Texts and Fonts: Windows fonts now include the new Saudi Riyal currency symbol, keeping text accurate and visually consistent.
  • Vulnerable driver blocklist: Known vulnerable kernel drivers are added to the Microsoft vulnerable driver blocklist. Backup applications relying on blocked drivers may encounter failures when mounting or managing disk images, including VSS timeout errors or VSS_E_BAD_STATE. Affected users should update to application versions that use newer, protected drivers.
  • Windows Deployment Services (WDS): The Hands-Free Deployment feature is disabled by default and is no longer supported, related to CVE-2026-0386.

Known issues

Installation might fail with error 0x800F0983 or 0x80073712

Symptom: A small number of devices may fail to install this update with either "Install error - 0x800F0983" or "Some update files are missing or have problems. We'll try to download the update again later. Error code: (0x80073712)".

Workaround: This issue is addressed in out-of-band update KB5091157. Hotpatch-enrolled Windows Server 2025 devices affected by this issue can install KB5091157 to receive the same protections as the April security update; however, installing KB5091157 requires a restart and pauses hotpatching. Hotpatch updates resume after the July 2026 baseline update.

Domain controllers might restart repeatedly after installing this update

Symptom: After installing this update and restarting, domain controllers in environments with multiple domains that use Privileged Access Management (PAM) may experience LSASS crashes during startup, causing repeated restarts and potentially making the domain unavailable.

Workaround: This issue is addressed in out-of-band update KB5091157. Devices enrolled in hotpatching should instead install OOB hotpatch update KB5091470, which is delivered through Windows Update and does not require a restart.

Devices with an unrecommended BitLocker Group Policy configuration might need to enter the recovery key

Symptom: Some devices with an unrecommended BitLocker Group Policy configuration may be prompted to enter their BitLocker recovery key on the first restart after installing this update. This affects devices where all of the following conditions are true: BitLocker is enabled on the OS drive; the Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is set with PCR7 included; System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding as "Not Possible"; the Windows UEFI CA 2023 certificate is present in the Secure Boot Signature Database; and the device is not already running the 2023-signed Windows Boot Manager. The recovery key is required only once on the first restart.

Workaround: This issue is addressed in KB5094125. After installing KB5094125, devices with this incompatible Group Policy configuration are prevented from installing the 2023-signed Windows Boot Manager. Microsoft recommends removing the Group Policy configuration before installing updates by setting "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured", running gpupdate /force, then suspending and re-enabling BitLocker using manage-bde. If removal of the policy is not desired, BitLocker can be temporarily suspended, the Secure Boot update scheduled via Start-ScheduledTask, and the device restarted before re-enabling BitLocker.

WSUS does not display synchronization error details

Symptom: After installing KB5070881 or later updates, Windows Server Update Services (WSUS) does not display synchronization error details within its error reporting.

Workaround: This functionality was temporarily removed to address the Remote Code Execution Vulnerability CVE-2025-59287. No additional workaround is stated.

Warnings related to Remote Desktop might not display correctly

Symptom: After installing this update, the security warning that appears when opening Remote Desktop (RDP) files might not display correctly in some cases. This may occur when using more than one monitor with different display scaling settings (for example, 100% and 125%). The warning window may show overlapping text or partially hidden buttons.

Workaround: This issue is addressed in KB5087539.

How to get this update

Microsoft combines the latest servicing stack update (SSU) - in this case KB5082062 (build 26100.32692) - with the cumulative update package. No separate SSU installation step is required before applying KB5082063.

The update is available through the following channels:

  • Windows Update and Microsoft Update: Downloads and installs automatically.
  • Windows Update for Business: Downloads and installs automatically in accordance with configured policies.
  • Windows Server Update Services (WSUS): Available for administrators to deploy.
  • Microsoft Update Catalog: Available for manual download.

Frequently asked questions

Does this update include fixes from the previous month's preview release?

Yes. KB5082063 includes security fixes specific to April 2026 along with non-security improvements that were first delivered in the prior month's optional preview release. Devices that already installed those preview updates will download only the new content added in this package.

Why might domain controllers restart repeatedly after applying this update?

Domain controllers in multi-domain forests that use Privileged Access Management (PAM) may experience LSASS crashes on startup following installation, leading to repeated restarts. Microsoft resolved this with out-of-band update KB5091157. Hotpatch-enrolled servers should use KB5091470 instead, which does not require a restart.

What should administrators do before installing this update to avoid BitLocker recovery prompts?

Administrators should audit BitLocker Group Policies for explicit PCR7 inclusion and check msinfo32.exe for PCR7 binding status. If the device reports PCR7 Binding as "Not Possible" and the relevant Group Policy is configured, Microsoft recommends setting that policy to "Not Configured" and re-binding BitLocker before applying the update to avoid a one-time recovery key prompt.

What is the impact of the vulnerable driver blocklist change in this update?

This update adds known vulnerable kernel drivers to the Microsoft vulnerable driver blocklist. Backup applications that depend on blocked drivers may fail when attempting to mount or manage disk images, producing VSS timeout errors or VSS_E_BAD_STATE messages. Affected organizations should update those backup applications to versions that use drivers meeting current protection requirements.

#windows-server-2025#security-update#kerberos#bitlocker#secure-boot#Remote Desktop#cumulative-update

Related topics