Welcome to Microsoft Q&A!
Thank you for taking the time to provide detailed information about your environment and the results you've observed.
Based on the information currently available, this does not appear to be a documented known issue with KB5126144. Microsoft indicates that the September 2026 update addresses CVE-2026-62886 and does not list any known issues related to this release.
One detail that may help with troubleshooting is that KB5126144 serves as the umbrella update for Windows Server 2019. Depending on the .NET Framework versions installed on the server, Windows will apply one of the following component updates:
- KB5126043 for .NET Framework 3.5 and 4.7.2
- KB5126048 for .NET Framework 3.5 and 4.8
Because of this, checking only for KB5126144 or relying on a single DLL version may not be enough to confirm that the security update has been fully applied.
To help verify the installation, I would recommend you check the following:
- Ensure the server has been restarted after the update installation.
- Confirm that KB5126043 or KB5126048 is installed successfully:
dism /online /get-packages /format:table | findstr "5126043 5126048"
- Verify the file version of System.Web.dll in both Framework locations:
(Get-Item "$env:windir\Microsoft.NET\Framework\v2.0.50727\System.Web.dll").VersionInfo.FileVersion
(Get-Item "$env:windir\Microsoft.NET\Framework64\v2.0.50727\System.Web.dll").VersionInfo.FileVersion
- Compare the reported file versions with the file information published in the applicable KB article.
- If the expected package or file version is missing, try reinstalling the applicable update from the Microsoft Update Catalog and then restart the server.
As a best practice, I would recommend not manually replacing or copying System.Web.dll from another server. This file is serviced through Windows and the .NET Framework servicing stack, and manual replacement can lead to inconsistencies in the component store.
If the applicable update is installed successfully and the DLL version matches Microsoft's published file information, but Rapid7 continues to report CVE-2026-62886, it may be worth opening a case with Rapid7 and providing the installed package information and file version details for review of the detection logic.
On the other hand, if the installed file version does not match the version expected in the Microsoft update package, I recommend you opening a Microsoft support case so the servicing state of the affected servers can be investigated further.
September 2026 cumulative update - .NET Framework | Microsoft Learn
If you find it useful, please click Accept Answer.
Thank you for choosing Microsoft Q&A.