NAVANEM
Security updateOS build 14393.9060

KB5082198 (OS Build 14393.9060) - April 2026 Security Update for Windows Server 2016 and Windows 10 LTSB 2016

April 14, 2026 security update for Windows Server 2016 and Windows 10 LTSB 2016, bringing OS build 14393.9060 with security fixes and quality improvements.

KB5082198: KB5082198 (OS Build 14393.9060) - April 2026 Security Update for Windows Server 2016 and Windows 10 LTSB 2016 — navanem Microsoft KB cover
KB5082198 · Windows Server · Security Update

Summary

This is a security update released on April 14, 2026, bringing affected systems to OS Build 14393.9060. It applies to Windows Server 2016 (all editions), Windows 10 Enterprise LTSB 2016, and Windows 10 IoT Enterprise LTSB 2016. The update delivers security fixes and quality improvements, building on the March 10, 2026 update (KB5078938). See Microsoft Support for full details.

Important - Secure Boot certificate expiration: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Microsoft has been updating these certificates on consumer and non-managed business devices. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should follow the Secure Boot Playbook for Windows clients and Windows Server.

Highlights

  • Windows Configuration System (WinCS) components restored so Secure Boot can be enabled via WinCS
  • Remote Desktop (.rdp) file phishing protections improved with full settings disclosure and a one-time security warning
  • Windows Deployment Services Hands-Free Deployment feature disabled by default (Windows Server 2016 only)
  • Kerberos KDC default encryption type updated to AES-SHA1 for accounts without an explicit msds-SupportedEncryptionTypes attribute (Windows Server 2016 only)
  • Secure Boot certificate rollout expanded with additional high-confidence device targeting data

Improvements and fixes

  • WinCS fix: A problem causing missing Windows Configuration System components on Windows 10 version 1607 and Windows Server 2016 has been corrected. The missing components previously prevented users from enabling Secure Boot through WinCS.
  • Remote Desktop phishing protection: When a user opens an .rdp file, Remote Desktop now displays all requested connection settings before establishing a connection, with each setting disabled by default. A one-time security warning is also shown the first time an .rdp file is opened on a device. Microsoft references the article "Understanding security warnings when opening Remote Desktop (RDP) files" for further guidance.
  • WDS Hands-Free Deployment hardening (Windows Server 2016 only): The "Hands-Free Deployment" feature in Windows Deployment Services is now disabled by default and is no longer a supported feature. This change is related to CVE-2026-0386.
  • Kerberos encryption default change (Windows Server 2016 only): The default DefaultDomainSupportedEncTypes value for Kerberos KDC operations has been updated to use AES-SHA1 for service accounts that do not have an explicit msds-SupportedEncryptionTypes Active Directory attribute defined. This is related to CVE-2026-20833.
  • Secure Boot certificate rollout expansion: Windows quality updates now include additional high-confidence device targeting data to widen coverage of devices that can automatically receive new Secure Boot certificates. Devices only receive new certificates after demonstrating sufficient successful update signals, keeping the rollout controlled and phased.

Known issues

Domain controllers might restart repeatedly after installing this update

Symptom: After installing this update, domain controllers in environments with multiple domains in the forest that use Privileged Access Management (PAM) might experience LSASS crashes during startup. Affected domain controllers may restart repeatedly, preventing authentication and directory services from functioning and potentially making the domain unavailable. This issue applies to Windows Server 2016 only.

Workaround: This issue is addressed in out-of-band update KB5091572.

Remote Desktop security warnings might not display correctly

Symptom: After installing this update, the security warning that appears when opening Remote Desktop (RDP) files might not display correctly in some cases. This issue can occur when more than one monitor is in use with different display scaling settings - for example, one display set to 100% and another set to 125%. When this happens, the warning window may show overlapping text or partially hidden buttons, making the message difficult to read or interact with.

Workaround: This issue is resolved in Windows updates released on and after May 12, 2026 (such as KB5087537). Microsoft recommends installing the latest Windows update for the affected device.

How to get this update

Prerequisite: To install updates released on or after January 14, 2025, Microsoft recommends first installing the latest Servicing Stack Update (SSU). The required SSU for this update is KB5082089. Without the latest SSU installed, this update may not be offered to the device, increasing security risk.

  • Windows Update and Windows Update for Business: KB5082089 (SSU) is offered automatically before this update. The cumulative update is then downloaded and installed automatically according to configured policies.
  • Microsoft Update Catalog: Download and install SSU KB5082089 first, then obtain the standalone package for KB5082198 from the Microsoft Update Catalog website.
  • Windows Server Update Services (WSUS): Administrators must approve both SSU KB5082089 and KB5082198. Configure Products and Classifications as follows - Product: Windows Server 2016, Windows 10, and Windows 10 LTSB; Classification: Security Updates.

Frequently asked questions

Does this update apply to Windows Server 2016 and Windows 10 LTSB 2016 differently?

Yes. Both editions receive the WinCS fix, Remote Desktop phishing protection improvements, and Secure Boot certificate rollout enhancements. However, the Kerberos KDC encryption default change and the WDS Hands-Free Deployment hardening apply only to Windows Server 2016, not to Windows 10 Enterprise LTSB 2016 or Windows 10 IoT Enterprise LTSB 2016.

What should WSUS administrators do before deploying KB5082198?

WSUS administrators must approve SSU KB5082089 before approving KB5082198. Without the SSU, the cumulative update may not install successfully. Ensure Products and Classifications are set to Windows Server 2016, Windows 10, and Windows 10 LTSB under Security Updates so both packages sync correctly to managed devices.

When does support end for Windows Server 2016 and Windows 10 LTSB 2016?

Microsoft lists the following end-of-support dates: Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise LTSB 2016 reach end of support on October 13, 2026. Windows Server 2016 reaches end of support on January 12, 2027. After those dates, Microsoft will no longer provide free updates, technical assistance, or security fixes.

How does the Secure Boot certificate rollout work with this update?

This update adds high-confidence device targeting data to Windows quality updates, expanding the pool of devices eligible to receive new Secure Boot certificates automatically. Certificates are delivered only after a device demonstrates sufficient successful update signals, keeping the rollout controlled. Administrators can check device status in the Windows Security app or follow the Secure Boot Playbook.

#windows-server-2016#windows-10-ltsb#secure-boot#Remote Desktop#kerberos#wds#security-update

Related topics