Microsoft Issues KB5099539 Update Fixing 570 Vulnerabilities, Including Exploited Zero‑Days, Extends ESU to 2027
What Happened — Microsoft released the Windows 10 KB5099539 extended‑security update, delivering July 2026 Patch‑Tuesday fixes for 570 vulnerabilities (two of which were actively exploited and one publicly disclosed zero‑day). The update also prolongs the free Windows 10 Extended Security Updates (ESU) program for consumers through 12 Oct 2027.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for a documented patch‑management process that aligns with SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management).
- Continuous evidence of timely patching serves as audit‑ready proof that the organization mitigates known exploitable flaws.
- Mapping each vulnerability fix to a control helps maintain a defensible audit trail and supports the Trust Center’s continuous‑compliance reporting.
Who Is Affected – All enterprises and consumers running Windows 10 Enterprise LTSC or enrolled in the ESU program across all industry sectors.
Recommended Actions – Verify that KB5099539 is applied to all eligible endpoints, update your patch‑management inventory, map the fixes to SOC 2 change‑management controls, and capture installation logs as audit evidence. Source: BleepingComputer
Technical Notes – The update addresses 570 CVE‑listed flaws (details in Microsoft KB), includes fixes for a zero‑day in the Windows kernel, and adds dynamic Secure Boot status reporting. Source: Microsoft Security Update Guide