Patch tracker / KB5129194

KB5129194: Windows 11 version 26H1 for x64-based Security Update (September 2026)

KB5129194 is a High security update for Windows 11 version 26H1 for x64-based, released 2026-09-08. It closes 2 CVEs with a maximum CVSS of 8.2. It is the 39th largest of the 69 updates Microsoft shipped that month, by CVEs closed.

Update summary

High
2026-09-08
Released
2
CVEs fixed
8.2
Max CVSS v3
High
Severity
Deploy this cycle
Fixes 2 CVEs for Windows 11 version 26H1 for x64-based. No confirmed in-the-wild exploitation in this set today.

Fixes 2 CVEs. Most severe CVSS 8.2 (High). EPSS exploit probability up to <1%. Among the lower half of tracked Microsoft updates by EPSS exploit probability.

Senserva found thisread these before you deploy broadly

Microsoft documents 4 known issues with this update.

  • Devices might experience a black screen or desktop loading issues after sign-in
  • Domain-joined devices might lose their secure trust relationship with the domain
  • USB Audio Class 1.0 devices with error Code 10 or no output

The full text, quoted from Microsoft

Senserva AI Opinion and rich prompt for KB5129194

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Full tracking and change history for KB5129194

Released
2026-09-08
Last changed
2026-10-03
Changes tracked
4

Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.

Check if KB5129194 is installed

Elevated PowerShell. No output means it is not installed.

Known issues, from Microsoft

Quoted from Microsoft's support article for KB5129194 (checked 2026-10-05). Verify against the article before acting.

Devices might experience a black screen or desktop loading issues after sign-in

Symptoms:

After installing the August 2026 Windows non-security preview update KB5120996 and subsequent updates, some devices might experience desktop loading issues. This issue has been primarily observed on Azure Virtual Desktop (AVD) hosts using FSLogix. This issue appears to occur more frequently with some existing user profiles.

Affected users might see a black screen after sign-in, with the desktop session failing to load automatically. In some cases, users might be unable to access their desktop until the desktop session is started manually. Application event logs might also show Windows Explorer crashes.

Workaround

Affected customers can apply one of the following workarounds to mitigate the issue:

Manually launch explorer.exe : Users can temporarily mitigate this issue by opening Task Manager (Ctrl+Shift+Esc), selecting Run new task , entering explorer.exe , and selecting OK .

Mitigate through Known Issue Rollback (KIR) : This issue is mitigated using Known Issue Rollback (KIR).

For enterprise-managed devices where Windows updates are managed by IT departments, IT administrators can apply the KIR by installing and configuring the Group policy listed below. The special Group Policy can be found in Computer Configuration > Administrative Templates > Group Policy name listed below

Group Policy downloads with Group Policy name:

Download for Windows 11, version 26H1: KB5124006 260924_20071 Known Issue Rollback

Important

You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the group policy setting. Note that this Group Policy will disable the change causing this issue until a resolution is released in a future Windows update.

For information on deploying and configuring this special Group Policy, please see How to use Group Policy to deploy a Known Issue Rollback

Resolution

We are working on a resolution for this issue, and it will be released in a future Windows update.

Domain-joined devices might lose their secure trust relationship with the domain

Symptoms

After installing the September 8, 2026, Windows security update KB5124012 , or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. ...

Windows release health for this update

From Microsoft's Windows release health for Windows 11, version 26H1, checked 2026-10-06. Microsoft's issue text is linked from each title.

Issues this update resolves

Other open issues on these Windows versions

CVEs fixed by this update

Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.

CVESeverityCVSSEPSSExploited
CVE-2026-85921High8.2<1%No
CVE-2026-62721High7.81.2%No

See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
All information provided as is, without warranty; verify against the vendor advisory before acting. All information and usage is subject to the Senserva EULA. Data notice and terms.