Affected Systems

Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.

Exploitation Status

Not a vulnerability; this is a confirmed software defect in a security update. No exploitation involved—systems experience operational failure after patching.

Business Impact

Domain controller lookups fail, breaking Active Directory authentication and domain services. Workstations and member servers may lose domain connectivity, preventing user authentication, Group Policy application, and access to domain resources. Critical impact for environments relying on Windows Server 2016 DCs. No CVE assigned as this is a patch-induced bug, not a security flaw.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately halt deployment of KB5087537 to Windows Server 2016 domain controllers until Microsoft releases a fix
  • Uninstall KB5087537 from affected Windows Server 2016 DCs experiencing domain lookup failures using WUSA /uninstall /kb:5087537 or DISM
  • Monitor Microsoft Security Update Guide and Windows Server release notes for corrective patch or workaround guidance
  • Test KB5087537 in isolated lab environment with domain controller functionality before any future deployment
  • Document affected systems and verify domain services (DNS, LDAP, Kerberos) return to normal after KB removal