Hello everyone !
We have identified an issue affecting the September 2026 Cumulative Update for Windows Server 2016 (KB5123099), where the same Microsoft download URL may intermittently serve different files.
In the affected downloads, one package is valid, while another package has been observed with a mismatched SHA1 hash, no valid Microsoft digital signature, and an inability to extract the MSU package. This behavior can result in checksum mismatch failures while downloading or deploying KB5123099 through ManageEngine Patch Management.
Microsoft Q&A reports also indicate similar symptoms, including extraction failures and installation errors such as 0x8007065E.
Customers encountering a checksum mismatch for KB5123099 can use either of the following approaches:
90b81aeccbf44e626d57fe86446e68ecb8b1fc44b1bcce365e7b1ed26a050ceaBefore deploying the package manually, ensure that the checksum matches the expected value and that the file contains a valid Microsoft digital signature.
We have raised this issue with Microsoft through the Microsoft Q&A forum and are awaiting further clarification.
Microsoft’s current KB5123099 documentation does not list this download-integrity issue as a known issue.
For more information, refer to:
Microsoft Q&A – KB5123099: Inconsistent File Served from Single Download URL
https://learn.microsoft.com/en-us/answers/questions/5998838/kb5123099-inconsistent-file-served-from-single-dow
Microsoft Q&A – KB5123099 Server 2016 September 2026 LCU installation issue
https://learn.microsoft.com/en-nz/answers/questions/5998147/kb5123099-server-2016-sept-2026-lcu-fails-with-0x8
Microsoft KB5123099 documentation
https://support.microsoft.com/en-us/servicing/os/windows-10/2026/09/kb5123099-windows-10-1607-security-update
We will update this post once additional information or a resolution is available from Microsoft.
Regards,
The ManageEngine Team