Windows Server · 2022 · Release · Security update (Patch Tuesday)
May 12, 2026—KB5087545 (OS Build 20348.5139)
- Release
- Cumulative update
- KB5087545 — Microsoft's article, opens in a new tab
Windows Server 2022: Supported LTSC release
Microsoft's known issues — KB5087545
- Issue Known issue Some devices with an unrecommended BitLocker Group Policy configuration might be required to enter their BitLocker recovery key on the first restart after installing this update. This issue only affects a limited number of systems in which ALL of the following conditions are true. These conditions are unlikely to be found on personal devices not managed by IT departments. BitLocker is enabled on the OS drive. The Group Policy "Configure TPM platform validation profile for native UEFI firmware configurations" is configured, and PCR7 is included in the validation profile (or the equivalent registry key is set manually). System Information (msinfo32.exe) reports Secure Boot State PCR7 Binding a Workaround: Remove the Group Policy configuration before installing the update (Recommended) Open Group Policy Editor (gpedit.msc) or your Group Policy Management Console. Navigate to: Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives. Set "Configure TPM platform validation profile for native UEFI firmware configurations" to "Not Configured". Run the following command on affected devices to propagate the policy change: gpupdate /force Run the following command to suspend BitLocker (where BitLocker is enabled on the C: drive): manage-bde -protectors -disable C: Run the following command to resume BitLocker (where BitLocker is ena
Known issues — reported on the forum
No problems reported on the forum for this build yet. Threads that name 20348.5139 or KB5087545 and describe a fault appear here automatically.
In the news
- Fix CVE-2026-41088 AFD.sys: Patch Tuesday Local EoP to SYSTEM (May 12, 2026)
- Fix CVE-2026-40410: Patch Now—Confirmed Windows SMB Client Use-After-Free Priv Esc
- Fix CVE-2026-35417: Win32k Type Confusion Local EoP to SYSTEM—May 12 Patch Urgency
- Coverage CVE-2026-34351 Windows TCP/IP Race Condition Enables SYSTEM Privilege Escalation
- Fix CVE-2026-33841 Windows Kernel EoP: May 2026 patch you shouldn’t ignore
- Fix Hitachi Energy GMS600 CVE-2022-4304: Fix OpenSSL RSA Timing Risk (v1.3.2)
- Coverage Wittytool Disk Clone: Can You Change SIDs on Cloned Windows Server 2019/2022?
Discussed on the forum
No member thread names 20348.5139 yet.