Updated 09:14
Windows 11 KB5129195: the emergency Remote Desktop fix also carries an August patch that 24H2 and 25H2 missed
KB5129195 fixes three regressions from September's Patch Tuesday and delivers, 34 days late, a SYSTEM-level privilege fix first published in August.
Microsoft shipped an out-of-band (OOB) cumulative update for Windows 11 on September 14, six days after the September security release. For versions 25H2 and 24H2 it is KB5129195, OS builds 26200.9457 and 26100.9457. Microsoft's own update index lists a matching OOB for 26H1 (KB5129194, build 28000.2956) and for 23H2 (KB5129242, build 22631.7584).
The stated purpose is repair. The KB lists three fixes for problems introduced by the September update, but its first line is a security item, and that is the part administrators should read twice.
The security line
The KB opens its improvements list with this:
This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
Microsoft, KB5129195 release notes
CVE-2026-62721 is not new. Microsoft's Security Update Guide shows it was published on August 11, rated Important, CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N), and not publicly disclosed or known exploited. The FAQ says a successful attacker "could gain SYSTEM privileges."
The revision history explains why an August CVE is in a September OOB. Version 2, dated September 14, reads: "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix. Microsoft recommends installing these updates as soon as possible."
The affected-products data backs that up. For 24H2 and 25H2 the fixed builds listed are 26100.9457/26200.9457 (this OOB) and .9448. The August cumulative update (build .9168) and the September one (.9445) are not among them. Windows 11 23H2, by contrast, lists its August build (22631.7517) as fixed. In other words, a fully patched 24H2 or 25H2 machine had no protection against a local path to SYSTEM from the day the CVE was published, August 11, until this OOB on September 14: 34 days.
The three regressions
The repair items, quoted from the KB:
- Remote Desktop Services: "RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration." MMC, RDS Licensing Diagnoser, File Explorer and the Windows Update page "might also stop responding."
- Hyper-V: folders shared from the host to Linux VMs over Plan9 in HCS-managed VMs "did not appear or could not be accessed in the guest environment."
- USB audio: some USB Audio Class 1.0 devices failed in 8-channel or 3D audio modes.
One editing error is worth knowing if you search by KB number: the RDS item attributes the problem to "the September 2026 Windows security update (KB5122880)." Microsoft's own index lists KB5122880 as the 23H2 September update; the 24H2/25H2 September update is KB5124008, which the same page cites elsewhere.
What it does not fix
Two September problems remain open in the KB's known-issues section:
- Domain trust loss. KB5124008 "and later updates" make Windows start honoring existing Machine Identity Isolation enforcement settings. Microsoft says the feature "is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above." Elsewhere, Credential Guard protected machine accounts can lose the secure channel and users see a failed trust-relationship message. The workaround is to disable the feature by the method that enabled it (Intune, Group Policy or the
MachineIdentityIsolationregistry value, set from 2 to 0), restart, then runTest-ComputerSecureChannel -Repair. - USB Audio Class 1.0 devices that fail with Code 10 or produce no sound. Microsoft "is working on a resolution."
What to do
The update installs automatically through Windows Update and Windows Update for Business, and is in the Update Catalog and WSUS. On 24H2, 25H2 and 26H1, treat it as a security update, not an optional fix: it is the first build that carries the CVE-2026-62721 protection. If a vulnerability scanner or patch report told you this CVE was closed in August on those versions, re-check the machines against the build numbers above.
Primary sources: Microsoft Support, KB5129195, Microsoft Security Update Guide, CVE-2026-62721, read 2026-09-18.