XT.PT Patch Tuesday → This story
Filed

Updated 09:14
Reporting
Prelo
Verified by Roger Morais
4 min · 662 words
News Patch Tuesday

Windows 11 KB5129195: the emergency Remote Desktop fix also carries an August patch that 24H2 and 25H2 missed

KB5129195 fixes three regressions from September's Patch Tuesday and delivers, 34 days late, a SYSTEM-level privilege fix first published in August.

Filed15 Sep 2026, 07:15 UTC Length4 min · 662 words ReportingPrelo
Security - keyboard

Microsoft shipped an out-of-band (OOB) cumulative update for Windows 11 on September 14, six days after the September security release. For versions 25H2 and 24H2 it is KB5129195, OS builds 26200.9457 and 26100.9457. Microsoft's own update index lists a matching OOB for 26H1 (KB5129194, build 28000.2956) and for 23H2 (KB5129242, build 22631.7584).

The stated purpose is repair. The KB lists three fixes for problems introduced by the September update, but its first line is a security item, and that is the part administrators should read twice.

The security line

The KB opens its improvements list with this:

This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.

Microsoft, KB5129195 release notes

CVE-2026-62721 is not new. Microsoft's Security Update Guide shows it was published on August 11, rated Important, CVSS 3.1 base score 7.8 (AV:L/AC:L/PR:L/UI:N), and not publicly disclosed or known exploited. The FAQ says a successful attacker "could gain SYSTEM privileges."

The revision history explains why an August CVE is in a September OOB. Version 2, dated September 14, reads: "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix. Microsoft recommends installing these updates as soon as possible."

The affected-products data backs that up. For 24H2 and 25H2 the fixed builds listed are 26100.9457/26200.9457 (this OOB) and .9448. The August cumulative update (build .9168) and the September one (.9445) are not among them. Windows 11 23H2, by contrast, lists its August build (22631.7517) as fixed. In other words, a fully patched 24H2 or 25H2 machine had no protection against a local path to SYSTEM from the day the CVE was published, August 11, until this OOB on September 14: 34 days.

The three regressions

The repair items, quoted from the KB:

  • Remote Desktop Services: "RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration." MMC, RDS Licensing Diagnoser, File Explorer and the Windows Update page "might also stop responding."
  • Hyper-V: folders shared from the host to Linux VMs over Plan9 in HCS-managed VMs "did not appear or could not be accessed in the guest environment."
  • USB audio: some USB Audio Class 1.0 devices failed in 8-channel or 3D audio modes.

One editing error is worth knowing if you search by KB number: the RDS item attributes the problem to "the September 2026 Windows security update (KB5122880)." Microsoft's own index lists KB5122880 as the 23H2 September update; the 24H2/25H2 September update is KB5124008, which the same page cites elsewhere.

What it does not fix

Two September problems remain open in the KB's known-issues section:

  • Domain trust loss. KB5124008 "and later updates" make Windows start honoring existing Machine Identity Isolation enforcement settings. Microsoft says the feature "is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above." Elsewhere, Credential Guard protected machine accounts can lose the secure channel and users see a failed trust-relationship message. The workaround is to disable the feature by the method that enabled it (Intune, Group Policy or the MachineIdentityIsolation registry value, set from 2 to 0), restart, then run Test-ComputerSecureChannel -Repair.
  • USB Audio Class 1.0 devices that fail with Code 10 or produce no sound. Microsoft "is working on a resolution."

What to do

The update installs automatically through Windows Update and Windows Update for Business, and is in the Update Catalog and WSUS. On 24H2, 25H2 and 26H1, treat it as a security update, not an optional fix: it is the first build that carries the CVE-2026-62721 protection. If a vulnerability scanner or patch report told you this CVE was closed in August on those versions, re-check the machines against the build numbers above.

Primary sources: Microsoft Support, KB5129195, Microsoft Security Update Guide, CVE-2026-62721, read 2026-09-18.

Corrections and source documents: contact the desk
Read next →
Read next
Runtimes · 4 min

Node.js 26.9.0 turns on node:ffi by default, six weeks before Node 26 becomes LTS

Recovery · 4 min

Windows 11 Cloud rebuild reaches the Beta channel: a full reinstall from WinRE, with drivers pulled from Windows Update