Patch tracker / KB5122880
KB5122880: Windows Server 2019 Security Update (September 2026)
KB5122880 is a Critical security update for Windows Server 2019, released 2026-09-08. It closes 602 CVEs with a maximum CVSS of 9.8. At least one of them is actively exploited (CISA KEV), so this is a deploy-first update. It is the sixth largest of the 67 updates Microsoft shipped that month, by CVEs closed.
Update summary
Fixes 602 CVEs. At least one is actively exploited (CISA KEV). Most severe CVSS 9.8 (Critical). EPSS exploit probability up to 1.7%. Among the lower half of tracked Microsoft updates by EPSS exploit probability.
Microsoft documents 2 known issues with this update.
- Host folder shares might be unavailable in Hyper-V-based Linux VMs
- Remote Desktop Services might stop responding after September 2026 security update
Senserva AI Opinion and rich prompt for KB5122880
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
Full tracking and change history for KB5122880
- Released
- 2026-08-11
- Last changed
- 2026-09-12
- Changes tracked
- 4
Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.
Microsoft revised KB5122880 on 2026-09-12: CVEs fixed 601 to 602.
- 2026-09-12 CVEs fixed 601 to 602
Recorded by Senserva on the dates shown, from the MSRC release feed. This is what moved and when, which neither the vendor advisory nor NVD publishes.
Check if KB5122880 is installed
Elevated PowerShell. No output means it is not installed.
Known issues, from Microsoft
Quoted from Microsoft's support article for KB5122880 (checked 2026-09-18). Verify against the article before acting.
Host folder shares might be unavailable in Hyper-V-based Linux VMs
**Symptoms**
After installing the September 2026 security update (KB5122880), applications that use [HCS-managed](https://learn.microsoft.com/virtualization/api/hcs/overview) virtual machines might experience issues when sharing host folder with Linux VMs using Plan9. Affected virtual machines start normally, but folders shared from the Windows host using Plan9 do not appear or cannot be accessed in the guest environment.
Applications or sandbox environments that depend on these shared folders might display an error indicating that no Plan9 drive shares were mounted. Claude Cowork and the Windows Subsystem for Linux (WSL) are two of the applications affected by this issue. Standard Hyper-V virtual machines that do not use the Plan9 feature are not affected by this issue.
**Next steps**
Microsoft is working on a resolution and will update this documentation when more information is available.
Remote Desktop Services might stop responding after September 2026 security update
Symptoms
After installing the September 2026 Windows security update, some organizations might experience issues with Remote Desktop Services (RDS).
In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive. Additionally, the Windows Update page might stop responding and continuously display a loading indicator.
Note
This issue does not affect Windows 365 or Azure Virtual Desktop.
Microsoft Support : IT administrators who need an immediate workaround should contact Microsoft Support for Business for assistance.
Resolution
This issue is resolved in Windows updates released on and after September 14, 2026 such as KB5129242 . We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.
CVEs fixed by this update
Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.
Scope and sources
- Affected products
- Also released in September 2026
KB5122871
679 CVEs · Critical · exploitedKB5122876
616 CVEs · Critical · exploitedKB5122878
568 CVEs · Critical · exploitedKB5122882
641 CVEs · Critical · exploitedKB5123065
393 CVEs · Critical · exploitedKB5123066
418 CVEs · Critical · exploitedKB5123099
555 CVEs · Critical · exploitedKB5124008
628 CVEs · Critical · exploitedThe full month, summarized: Microsoft Patch Tuesday.
- Authoritative references
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.