Microsoft confirmed that security update KB5087537 for Windows Server 2016 can break domain controller discovery on servers whose names are exactly the 15-character NetBIOS limit. After installing the May 2026 update, affected systems may return ERROR_INVALID_PARAMETER during DCLocator operations, including domain controller lookups performed by tools and applications, preventing systems from locating a domain controller and disrupting Active Directory-dependent functions such as authentication, Group Policy processing, and DFS Namespace administration.
Microsoft added the problem to the update’s known issues list and said it remains under investigation, with no fix timeline disclosed. Organizations running impacted domain controllers may need to use shorter hostnames or delay deployment of KB5087537 where possible until a corrective update is released. The issue adds to a broader history of Microsoft domain and Group Policy-related servicing and security problems, including the critical JASBUG flaw tracked as CVE-2015-0008, which allowed attackers on malicious networks to compromise domain-joined Windows systems through Group Policy and domain controller interactions.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft confirmed a known issue in KB5087537 on Windows Server 2016 where servers with 15-character hostnames can fail domain controller discovery, returning ERROR_INVALID_PARAMETER during DCLocator operations. The company added the problem to the update's known issues and said it was still investigating, with workarounds including shortening hostnames or delaying deployment.
Microsoft released the May 2026 Windows Server 2016 security update KB5087537. The update later proved to introduce a bug affecting domain controller discovery on some systems.
On Patch Tuesday, Microsoft released security bulletin MS15-011 (update 3000483) to fix the critical Group Policy remote code execution flaw CVE-2015-0008 affecting many supported Windows client and server versions. Microsoft said exploitation could let attackers fully compromise domain-joined systems on attacker-controlled networks, while Windows Server 2003 would not receive a patch.
JAS Advisors and simMachines privately reported the Active Directory/Group Policy design flaw later nicknamed Jasbug to Microsoft in January 2014. Microsoft began working on a fix for what it described as a core Windows design problem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcetechnet.microsoft.com
Open sourceics-cert.us-cert.gov
Open sourcethenextweb.com
Open sourcetheregister.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.