Microsoft Windows Server 2016 domain controller discovery failure after KB5087537
Service Disruption
Summary
Hide ▲
Show ▼
Microsoft confirmed a known issue in Windows Server 2016 after KB5087537 that can prevent domain controller discovery, disrupting administrative operations and application access. The failure affects systems with 15-character hostnames and can cause `DCLocator` calls to return `ERROR_INVALID_PARAMETER`. Microsoft is investigating and has not yet provided a resolution timeline.
Related Happenings
Microsoft Windows Update restricted-network download failure
Service Disruption
First: 19.05.2026 14:22
Last: 19.05.2026 14:22
Sources 1
About this happening:
Microsoft's **Windows Update** is failing in **restricted network environments** after the **January 2026 optional non-security preview updates**, leaving affected systems unable...
Microsoft Windows Update restricted-network download failure
Service DisruptionAbout this happening: Microsoft's **Windows Update** is failing in **restricted network environments** after the **January 2026 optional non-security preview updates**, leaving affected systems unable...
Microsoft Windows Autopatch fix for EU restricted driver update deployment bug
Security Tool/Service
First: 13.05.2026 17:36
Last: 13.05.2026 17:36
Sources 1
About this happening:
**Microsoft** fixed a **Windows Autopatch** service bug that let **restricted driver updates** reach some managed devices in the **EU**, bypassing admin approval controls and crea...
Microsoft Windows Autopatch fix for EU restricted driver update deployment bug
Security Tool/ServiceAbout this happening: **Microsoft** fixed a **Windows Autopatch** service bug that let **restricted driver updates** reach some managed devices in the **EU**, bypassing admin approval controls and crea...
Windows DNS heap-based buffer overflow remote code execution flaw (CVE-2026-41096)
Vulnerability
First: 13.05.2026 13:36
Last: 13.05.2026 13:36
Sources 1
About this happening:
Microsoft patched **CVE-2026-41096**, a **heap-based buffer overflow** in **Windows DNS** that could let an unauthorized attacker execute code remotely on vulnerable Windows syste...
Windows DNS heap-based buffer overflow remote code execution flaw (CVE-2026-41096)
VulnerabilityAbout this happening: Microsoft patched **CVE-2026-41096**, a **heap-based buffer overflow** in **Windows DNS** that could let an unauthorized attacker execute code remotely on vulnerable Windows syste...
Windows Netlogon stack-based buffer overflow security flaw (CVE-2026-41089)
Vulnerability
First: 13.05.2026 11:15
Last: 13.05.2026 11:15
Sources 1
About this happening:
Microsoft’s **May Patch Tuesday** fixed **CVE-2026-41089**, a **critical** stack-based buffer overflow in **Windows Netlogon** that could let attackers gain **system privileges**...
Windows Netlogon stack-based buffer overflow security flaw (CVE-2026-41089)
VulnerabilityAbout this happening: Microsoft’s **May Patch Tuesday** fixed **CVE-2026-41089**, a **critical** stack-based buffer overflow in **Windows Netlogon** that could let attackers gain **system privileges**...
Microsoft Defender false-positively flags DigiCert root certificates and removes some from Windows trust store
Security Tool/Service
First: 03.05.2026 21:11
Last: 03.05.2026 21:11
Sources 1
About this happening:
**Microsoft Defender** began falsely flagging valid **DigiCert root certificates** as **Trojan:Win32/Cerdigent.A!dha**, creating widespread false positives and risking certificate...
Microsoft Defender false-positively flags DigiCert root certificates and removes some from Windows trust store
Security Tool/ServiceAbout this happening: **Microsoft Defender** began falsely flagging valid **DigiCert root certificates** as **Trojan:Win32/Cerdigent.A!dha**, creating widespread false positives and risking certificate...
Timeline
-
26.05.2026 10:41 2 articles · 1d ago
Windows Server 2016 domain controller discovery fails after KB5087537
Initial DisclosureMicrosoft confirmed a known issue affecting Windows Server 2016 systems after installation of the KB5087537 May 2026 security update. On servers with hostnames exactly 15 characters long, domain controller discovery can fail because DCLocator calls such as nltest /dsgetdc:<domain> /pdc return ERROR_INVALID_PARAMETER, preventing applications and administrative tools from locating a domain controller and potentially disrupting administrative tasks such as DFS Namespace management. Microsoft said it is investigating and has not yet provided a resolution timeline.
Show sources
- Microsoft: Domain Controller lookup may fail on Windows Server 2016 — www.bleepingcomputer.com — 26.05.2026 10:41
- Microsoft: Domain Controller lookup may fail on Windows Server 2016 — www.bleepingcomputer.com — 26.05.2026 10:41