KB5091573 (OS Build 17763.8647) Out-of-Band Update for Windows Server 2019 - April 19, 2026
Out-of-band update for Windows Server 2019 (OS Build 17763.8647) released April 19, 2026, fixing a domain controller LSASS crash in multi-domain PAM environments.

Summary
This is an out-of-band update for Windows Server 2019, released April 19, 2026, producing OS Build 17763.8647. It addresses a critical post-patch regression introduced by the April 14, 2026 security update (KB5082123) that caused domain controllers to fail at startup in specific configurations. Source: Microsoft Support.
Improvements and fixes
- Fixes a startup failure on domain controllers running in multi-domain forests that use Privileged Access Management (PAM) after the April 14, 2026 security update (KB5082123) was installed. In affected environments, the Local Security Authority Subsystem Service (LSASS) could stop responding, causing repeated restarts and making authentication and directory services - and therefore the domain itself - unavailable.
- Incorporates all fixes and improvements already present in the April 14, 2026 update (KB5082123). If earlier updates are already installed, only the new changes in this package will be downloaded and applied.
- Includes a combined servicing stack update (SSU KB5082118, version 17763.8642) that improves the reliability of the update installation process. The SSU also adds enhanced logic to verify whether a device is hosted on Azure, using an updated certificate chain for that validation.
Known issues
Remote Desktop security warnings might not display correctly
Symptom: After installing this update, the security warning that appears when opening Remote Desktop (RDP) files may not display correctly in certain cases. The issue is specifically observed when using more than one monitor with different display scaling settings - for example, one display set to 100% and another set to 125%. When triggered, the warning window may show overlapping text or partially hidden buttons, making the message difficult to read or interact with.
Workaround: This issue is resolved in Windows updates released on and after May 12, 2026 (such as KB5087538). Microsoft recommends installing the latest Windows update for the device, as it contains important improvements and issue resolutions, including this one.
How to get this update
Prerequisite: The August 10, 2021 servicing stack update (KB5005112) must be installed before applying KB5091573.
This out-of-band update is available only from the Microsoft Update Catalog - it is not distributed through the standard Windows Update channel. It is also available through Windows Update for Business and Server Update Services (WSUS). Retrieve the standalone package directly from the Microsoft Update Catalog website.
To remove the cumulative update portion after installation, use the DISM /online /remove-package command with the LCU package name as the argument. Running wusa.exe /uninstall against the combined package will not work because the package includes the SSU, and the SSU cannot be removed after installation.
Note on Secure Boot certificates: Microsoft notes that Secure Boot certificates on most Windows devices are set to expire starting June 2026. Devices that have not yet received updated certificates will continue to start and operate normally, and standard Windows updates will continue to install. IT administrators should consult the Secure Boot Playbook for Windows clients and Windows Server for guidance.
Frequently asked questions
Which systems are affected by this update?
This update applies to Windows Server 2019 only. While the page notes Windows 10 Enterprise LTSC 2019 shares the same OS build lineage, Microsoft explicitly states this out-of-band update applies to Windows Server 2019 only. Both products share an end-of-support date of January 9, 2029.
Why was an out-of-band update necessary instead of waiting for the next Patch Tuesday?
The April 14, 2026 security update (KB5082123) introduced a regression causing LSASS to stop responding on domain controllers in multi-domain forests using PAM, leading to repeated restarts and domain unavailability. This severity justified an out-of-band release rather than waiting for the next scheduled monthly update cycle.
Is this update available through Windows Update automatic delivery?
No. Microsoft is distributing KB5091573 exclusively through the Microsoft Update Catalog, Windows Update for Business, and WSUS. It will not appear as an automatic update through the standard Windows Update channel, so administrators must retrieve and deploy it manually or through their update management infrastructure.
What should administrators do if they need to uninstall this update?
Administrators can remove the cumulative update (LCU) component using DISM /online /remove-package with the LCU package name, which can be found by running DISM /online /get-packages. Using wusa.exe /uninstall will not work on the combined SSU-plus-LCU package. The SSU component cannot be removed once installed. Microsoft also cautions administrators to review the risks before removing any security update.







