After the April 2026 KB5082063 security update, non-GC DCs in PAM-enabled environments experienced LSASS crashes → restart loops. Microsoft released out-of-band fixes on April 19 (KB5091157, KB5091575). Three scenarios: defer if not yet installed; install out-of-band if currently running; safe mode + wusa /uninstall if boot looping. DSRM password recovery included.
Actively exploited XSS zero-day in Exchange Server OWA (CVE-2026-42897). Microsoft released permanent patch KB5094139 on June 9, 2026. Exchange 2016/2019 require ESU Period 2. EEMS temporary mitigation, version table, SU installation procedure, exploitation detection, and Exchange Online migration recommendations.




