NAVANEM
Out-of-bandOS build 14393.9062

KB5091572 (OS Build 14393.9062): April 19, 2026 Out-of-Band Update for Windows Server 2016

Out-of-band fix for Windows Server 2016 (OS Build 14393.9062) addressing a domain controller LSASS crash introduced by the April 14, 2026 security update.

KB5091572: KB5091572 (OS Build 14393.9062): April 19, 2026 Out-of-Band Update for Windows Server 2016 — navanem Microsoft KB cover
KB5091572 · Windows Server · Out-of-Band Update

Summary

This out-of-band update, KB5091572 (OS Build 14393.9062), was released on April 19, 2026 for Windows Server 2016. It addresses a critical domain controller startup failure introduced by the April 14, 2026 security update (KB5082198). The update is non-security and is available exclusively through the Microsoft Update Catalog. See Microsoft Support for the official page.

Improvements and fixes

  • Domain controller startup failure (PAM environments): After installing KB5082198 and restarting, domain controllers in multi-domain forests that use Privileged Access Management (PAM) could experience startup problems. In some cases, Local Security Authority Subsystem Service (LSASS) stopped responding, causing repeated restarts and blocking authentication and directory services - potentially making the entire domain unavailable. This update resolves that issue.

Known issues

Remote Desktop security warnings might not display correctly

Symptom: After installing this update, the security warning that appears when opening Remote Desktop (RDP) files may not display correctly in certain configurations. Specifically, when using more than one monitor with different display scaling settings - for example, one display at 100% and another at 125% - the warning window may show overlapping text or partially hidden buttons, making the message difficult to read or interact with.

Workaround: This issue is resolved in Windows updates released on and after May 12, 2026 (such as KB5087537). Microsoft recommends installing the latest Windows update for your device, as it contains important improvements and issue resolutions, including this one.

How to get this update

Prerequisite - Servicing Stack Update (SSU): Before installing this update, Microsoft recommends first installing the latest Servicing Stack Update. For Windows Server 2016, the required SSU is KB5082089. Without the latest SSU installed, this update may not be offered to your device, and installation may fail. Devices using Windows Update or Windows Update for Business will receive the SSU automatically. WSUS administrators must manually approve both KB5082089 and KB5091572.

This out-of-band update is not distributed through Windows Update automatic channels. It is available only through the following:

  • Microsoft Update Catalog - Download the standalone package directly from the Microsoft Update Catalog website.
  • Windows Update for Business - Available from the Update Catalog only.
  • Windows Server Update Services (WSUS) - WSUS administrators must approve KB5082089 (SSU) and KB5091572 separately before the update is offered to managed devices.

File information for this update is available as a downloadable CSV file from the official Microsoft Support page.

Frequently asked questions

Why was this update released out-of-band rather than through the normal monthly schedule?

Microsoft released KB5091572 outside the regular Patch Tuesday cadence because the April 14, 2026 security update (KB5082198) introduced a critical regression. Domain controllers running in multi-domain PAM environments faced LSASS failures and repeated restarts after that update, making directory services and authentication unavailable. The severity of the impact required an immediate, targeted fix.

Does this update apply to Windows 10 LTSB 2016 clients as well as Windows Server 2016?

No. Although the update shares OS Build 14393 with Windows 10 version 1607 and Win 10 Ent LTSB 2016, Microsoft explicitly states that this out-of-band update applies to Windows Server 2016 only. Administrators managing Windows 10 LTSB 2016 clients do not need to deploy KB5091572 to those devices.

What is the end-of-support timeline for Windows Server 2016 and related 2016 LTSB editions?

Microsoft has published the following end-of-support dates: Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB both reach end of support on October 13, 2026. Windows Server 2016 reaches end of support on January 12, 2027. After these dates, Microsoft will no longer provide free updates, technical assistance, or security fixes.

Should I be concerned about the Secure Boot certificate expiration mentioned on this page?

Microsoft notes that Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. Devices that have not yet received the newer certificates will continue to start and operate normally, and standard Windows updates will continue to install. Microsoft is rolling out updated certificates via Windows Update over the coming months. IT administrators can check device status using the Windows Security app and should consult the Secure Boot Playbook for Windows clients and Windows Server for managed environment guidance.

#windows-server-2016#domain-controller#lsass#pam#out-of-band#secure-boot#rdp

Related topics