Patch tracker / KB5129194
KB5129194: Windows 11 version 26H1 for x64-based Security Update (September 2026)
KB5129194 is a High security update for Windows 11 version 26H1 for x64-based, released 2026-09-08. It closes 2 CVEs with a maximum CVSS of 8.2. It is the 39th largest of the 69 updates Microsoft shipped that month, by CVEs closed.
Update summary
Fixes 2 CVEs. Most severe CVSS 8.2 (High). EPSS exploit probability up to <1%. Among the lower half of tracked Microsoft updates by EPSS exploit probability.
Microsoft documents 4 known issues with this update.
- Devices might experience a black screen or desktop loading issues after sign-in
- Domain-joined devices might lose their secure trust relationship with the domain
- USB Audio Class 1.0 devices with error Code 10 or no output
Senserva AI Opinion and rich prompt for KB5129194
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
Full tracking and change history for KB5129194
- Released
- 2026-09-08
- Last changed
- 2026-10-03
- Changes tracked
- 4
Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.
Check if KB5129194 is installed
Elevated PowerShell. No output means it is not installed.
Known issues, from Microsoft
Quoted from Microsoft's support article for KB5129194 (checked 2026-10-05). Verify against the article before acting.
Devices might experience a black screen or desktop loading issues after sign-in
Symptoms:
After installing the August 2026 Windows non-security preview update KB5120996 and subsequent updates, some devices might experience desktop loading issues. This issue has been primarily observed on Azure Virtual Desktop (AVD) hosts using FSLogix. This issue appears to occur more frequently with some existing user profiles.
Affected users might see a black screen after sign-in, with the desktop session failing to load automatically. In some cases, users might be unable to access their desktop until the desktop session is started manually. Application event logs might also show Windows Explorer crashes.
Workaround
Affected customers can apply one of the following workarounds to mitigate the issue:
Manually launch explorer.exe : Users can temporarily mitigate this issue by opening Task Manager (Ctrl+Shift+Esc), selecting Run new task , entering explorer.exe , and selecting OK .
Mitigate through Known Issue Rollback (KIR) : This issue is mitigated using Known Issue Rollback (KIR).
For enterprise-managed devices where Windows updates are managed by IT departments, IT administrators can apply the KIR by installing and configuring the Group policy listed below. The special Group Policy can be found in Computer Configuration > Administrative Templates > Group Policy name listed below
Group Policy downloads with Group Policy name:
Download for Windows 11, version 26H1: KB5124006 260924_20071 Known Issue Rollback
Important
You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the group policy setting. Note that this Group Policy will disable the change causing this issue until a resolution is released in a future Windows update.
For information on deploying and configuring this special Group Policy, please see How to use Group Policy to deploy a Known Issue Rollback
Resolution
We are working on a resolution for this issue, and it will be released in a future Windows update.
Domain-joined devices might lose their secure trust relationship with the domain
Symptoms
After installing the September 8, 2026, Windows security update KB5124012 , or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. ...
Windows release health for this update
From Microsoft's Windows release health for Windows 11, version 26H1, checked 2026-10-06. Microsoft's issue text is linked from each title.
Issues this update resolves
- Remote Desktop Services might stop responding after Sept. 2026 security update
Resolved. Microsoft last updated it 2026-09-17 19:22 PT. - Host folder shares might be unavailable in Hyper-V-based Linux VMs
Resolved. Microsoft last updated it 2026-09-14 13:30 PT.
Other open issues on these Windows versions
- USB audio devices might fail to start or produce no sound
Mitigated. Microsoft last updated it 2026-09-29 10:12 PT. - Domain-joined devices might lose their secure trust relationship with the domain
Mitigated. Microsoft last updated it 2026-09-29 10:12 PT. - Devices might experience a black screen or desktop loading issues after sign-in
Mitigated. Microsoft last updated it 2026-09-29 10:12 PT.
CVEs fixed by this update
Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.
| CVE | Severity | CVSS | EPSS | Exploited |
|---|---|---|---|---|
| CVE-2026-85921 | High | 8.2 | <1% | No |
| CVE-2026-62721 | High | 7.8 | 1.2% | No |
Scope and sources
- Affected products
- Also released in September 2026
KB5122871
679 CVEs · Critical · exploitedKB5122876
616 CVEs · Critical · exploitedKB5122878
568 CVEs · Critical · exploitedKB5122880
602 CVEs · Critical · exploitedKB5122882
641 CVEs · Critical · exploitedKB5123065
393 CVEs · Critical · exploitedKB5123066
418 CVEs · Critical · exploitedKB5123099
555 CVEs · Critical · exploitedThe full month, summarized: Microsoft Patch Tuesday.
- Authoritative references
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.