Microsoft KB5091157
Microsoft out-of-band patch fixing LSASS reboot loops on PAM-enabled domain controllers.
Last refreshed: 8 May 2026
Timeline for Microsoft KB5091157
KB5091157, Gentlemen C2 intel, ENISA CNAs: in brief
Cybersecurity: Threats and Defences- What is KB5091157?
- KB5091157 is a Microsoft out-of-band patch released on 19 April 2026 that fixes LSASS reboot loops on Windows Server domain controllers that have Privileged Access Management (PAM) enabled, caused by a regression in the April 2026 Patch Tuesday update.
- What is a Microsoft out-of-band patch?
- A Microsoft out-of-band (OOB) patch is an emergency update released outside the monthly Patch Tuesday schedule, issued when a critical bug or security issue is too severe or disruptive to wait for the next regular release cycle.
- Why did domain controllers reboot after April 2026 Windows Server update?
- A regression in the April 2026 Patch Tuesday cumulative update caused LSASS to enter a crash loop on Windows Server domain controllers with Privileged Access Management (PAM) enabled. Microsoft released KB5091157 out-of-band on 19 April 2026 to fix the issue.Source:
Background
Microsoft KB5091157 is a Knowledge Base (KB) article and associated out-of-band (OOB) patch issued on 19 April 2026 to fix a critical regression in Windows Server 2016, 2019, 2022, and 2025 that caused domain controllers with Privileged Access Management (PAM) enabled to enter continuous Local Security Authority Subsystem Service (LSASS) reboot loops. The bug rendered affected domain controllers inoperable, making KB5091157 an emergency fix rather than a scheduled Patch Tuesday release.
Microsoft's Knowledge Base is a repository of articles providing information on specific product issues and patches. An out-of-band patch is one released outside the normal monthly Patch Tuesday cycle, signalling that the severity or operational impact is too high to wait for the next scheduled release. KB numbers serve as stable identifiers for tracking which fix has been applied to a given system, recorded in Windows Update history and third-party patch management tools.
PAM (Privileged Access Management) on domain controllers is a Windows Server feature that enables just-in-time elevation of Active Directory privileges, used in hardened enterprise environments to limit standing administrator rights. The regression was introduced by the April 2026 Patch Tuesday cumulative update for Windows Server; the out-of-band KB5091157 reverted the defective component. The issue is noted in U#3 as part of the IN BRIEF section , reflecting the operational disruption to organisations with hardened PAM-enabled domain controller deployments.