Patch tracker / KB5055521

KB5055521: Windows Server 2019 Security Update (April 2025)

KB5055521 is a High security update for Windows Server 2019, released 2025-04-08. It closes 60 CVEs with a maximum CVSS of 8.8. At least one of them is actively exploited (CISA KEV) and linked to ransomware, so this is a deploy-first update. The most likely of them to be attacked is CVE-2025-26663, which FIRST.org rates at 14% probability of exploitation in the next 30 days.

Update summary

HighCISA KEVRansomware
2025-04-08
Released
60
CVEs fixed
8.8
Max CVSS
High
Severity
Deploy immediately
This update fixes vulnerabilities confirmed exploited in the wild, including ransomware-linked CVEs.

Fixes 60 CVEs. At least one is actively exploited (CISA KEV). Most severe CVSS 8.8 (High). EPSS exploit probability up to 14%. One is linked to ransomware. Among the top half of tracked Microsoft updates by EPSS exploit probability.

Senserva found thiswe track every release for this product line, so we can tell you this package is behind

A newer security update for Windows 10 Version 1809 for 32-bit Systems has shipped since this one: KB5094041 (2026-08-11). For cumulative update families the newer package includes these fixes, so installing that one is usually the shorter path. Verify against your own update rings before you skip this package.

Senserva found thisread these before you deploy broadly

Microsoft documents 1 known issue with this update.

  • Active Directory Group Policy: Events in local policy

The full text, quoted from Microsoft

Senserva AI Opinion for KB5055521

KB5055521 fixes 62 CVEs for the same April 2025 cycle on Windows 10 1809 and Windows Server 2019, High severity, CVSS 8.8, 18 percent EPSS, with the CISA KEV listing and ransomware linkage consistent across this update family. With this many overlapping builds sharing the same ransomware-linked core, the priority for admins is confirming that core set is closed everywhere, not which specific KB closed it. Don't let build-number confusion delay remediation.

Do this: Confirm the ransomware-linked CVE core is closed on hosts running KB5055521 by comparing its list against the largest sibling build.

AI-generated from public data, 2026-07-07. Verify against the vendor advisory before acting.

Senserva AI Opinion and rich prompt for KB5055521

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Full tracking and change history for KB5055521

Released
2025-04-08
Last changed
2026-08-12
Changes tracked
4

Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.

Senserva Watchevery change we have recorded for this one
What changed, and when

The strongest signal is a single downward revision recorded on 2026-08-07, when the CVE count for KB5055521 dropped from 62 to 60. With only one data point, the trail shows a minor correction rather than a trend, suggesting two fixes were reclassified or removed. For today, treat this as a stable update with no escalation.

  • 2026-08-07 CVEs fixed 62 to 60

Recorded by Senserva on the dates shown, from the MSRC release feed. This is what moved and when, which neither the vendor advisory nor NVD publishes.

Check if KB5055521 is installed

Elevated PowerShell. No output means it is not installed.

Known issues, from Microsoft

Quoted from Microsoft's support article for KB5055521 (checked 2026-08-12). Verify against the article before acting.

Active Directory Group Policy: Events in local policy

Symptoms

Audit Logon/Logoff events in the local policy of the Active Directory Group Policy might not show as enabled on the device even if they are enabled and working as expected. This can be observed in the Local Group Policy Editor or Local Security Policy, where local audit policies show the "Audit logon events" policy with Security Setting of "No auditing".

This issue might only manifest as a reporting inconsistency. It’s possible that logon events are correctly being audited on the device. However, the “Audit logon events” policy will reflect that this is not the case. Home users are unlikely to be affected by this issue, as logon auditing is generally only necessary in enterprise environments.

Resolution

This issue is resolved in the April 11, 2025—KB5058921 (OS Build 14393.7973) Out-of-band update. This out-of-band (OOB) update is available only on the Microsoft Update Catalog . Since this is a cumulative update, you do not need to apply any previous update before installing it, and it supersedes all previous updates. Installation of this OOB will require a device restart.

If your organization has not deployed this update yet and you utilize Active Directory Group Policy, we recommend you apply the April 11, 2025—KB5058921 (OS Build 14393.7973) Out-of-band update instead.

As always, we recommend you install the ...

CVEs fixed by this update

Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.

CVESeverityCVSSEPSSExploited
CVE-2025-29824High7.814%KEV Ransomware
CVE-2025-21205High8.814%No
CVE-2025-21221High8.814%No
CVE-2025-21222High8.814%No
CVE-2025-26647High8.814%No
CVE-2025-26669High8.814%No
CVE-2025-27477High8.814%No
CVE-2025-27481High8.814%No
CVE-2025-27740High8.814%No
CVE-2025-27737High8.614%No
CVE-2025-26663High8.114%No
CVE-2025-26670High8.114%No
CVE-2025-26671High8.114%No
CVE-2025-27480High8.114%No
CVE-2025-27482High8.114%No
CVE-2025-27487High8.014%No
CVE-2025-21204High7.814%No
CVE-2025-24073High7.814%No
CVE-2025-26648High7.814%No
CVE-2025-26679High7.814%No
CVE-2025-26688High7.814%No
CVE-2025-27483High7.814%No
CVE-2025-27727High7.814%No
CVE-2025-27733High7.814%No
CVE-2025-27741High7.814%No
CVE-2025-21174High7.514%No
CVE-2025-26641High7.514%No
CVE-2025-26652High7.514%No
CVE-2025-26668High7.514%No
CVE-2025-26673High7.514%No
CVE-2025-26680High7.514%No
CVE-2025-26686High7.514%No
CVE-2025-26687High7.514%No
CVE-2025-27469High7.514%No
CVE-2025-27470High7.514%No
CVE-2025-27473High7.514%No
CVE-2025-27479High7.514%No
CVE-2025-27484High7.514%No
CVE-2025-27485High7.514%No
CVE-2025-27486High7.514%No
CVE-2025-29810High7.514%No
CVE-2025-27491High7.114%No
CVE-2025-29809High7.114%No
CVE-2025-21191High7.014%No
CVE-2025-26665High7.014%No
CVE-2025-27478High7.014%No
CVE-2025-27732High7.014%No
CVE-2025-26637Medium6.814%No
CVE-2025-21197Medium6.514%No
CVE-2025-21203Medium6.514%No
CVE-2025-26664Medium6.514%No
CVE-2025-26667Medium6.514%No
CVE-2025-26672Medium6.514%No
CVE-2025-26676Medium6.514%No
CVE-2025-27474Medium6.514%No
CVE-2025-27738Medium6.514%No
CVE-2025-27735Medium6.014%No
CVE-2025-27471Medium5.914%No
CVE-2025-27736Medium5.514%No
CVE-2025-27742Medium5.514%No

See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.