Patch tracker / KB5129241
KB5129241: Windows 11 Version 25H2 for x64-based Security Update (August 2026)
KB5129241 is a High security update for Windows 11 Version 25H2 for x64-based, released 2026-08-11. It closes 1 CVE with a maximum CVSS of 7.8. It is the 51st largest of the 65 updates Microsoft shipped that month, by CVEs closed.
Update summary
Fixes 1 CVE. Most severe CVSS 7.8 (High). EPSS exploit probability up to <1%. Among the lower half of tracked Microsoft updates by EPSS exploit probability.
A newer security update for Windows 11 Version 25H2 for ARM64-based Systems has shipped since this one: KB5124008 (2026-09-08). For cumulative update families the newer package includes these fixes, so installing that one is usually the shorter path. Verify against your own update rings before you skip this package.
Microsoft documents 5 known issues with this update.
- Devices might experience a black screen or desktop loading issues after sign-in
- Domain-joined devices might lose their secure trust relationship with the domain
- USB Audio Class 1.0 devices with error Code 10 or no output
Senserva AI Opinion and rich prompt for KB5129241
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
Full tracking and change history for KB5129241
- Released
- 2026-08-11
- Last changed
- 2026-08-11
- Changes tracked
- 1
Senserva began recording day-to-day change history on 2026-07-07, and refreshes it several times a day. Release dates are historical where Microsoft publishes them; revision history is tracked from that date forward, so it does not include changes made before then.
Check if KB5129241 is installed
Elevated PowerShell. No output means it is not installed.
Known issues, from Microsoft
Quoted from Microsoft's support article for KB5129241 (checked 2026-09-29). Verify against the article before acting.
Devices might experience a black screen or desktop loading issues after sign-in
Symptoms
After installing the August 2026 Windows non-security preview update KB5120998 and subsequent updates, some devices might experience desktop loading issues. This issue has been primarily observed on Azure Virtual Desktop (AVD) hosts using FSLogix. This issue appears to occur more frequently with some existing user profiles.
Affected users might see a black screen after sign-in, with the desktop session failing to load automatically. In some cases, users might be unable to access their desktop until the desktop session is started manually. Application event logs might also show Windows Explorer crashes.
Workaround
Affected customers can apply one of the following workarounds to mitigate the issue:
Manually launch explorer.exe
Users can temporarily mitigate this issue by opening Task Manager ( Ctrl+Shift+Esc ), selecting Run new task , entering explorer.exe , and selecting OK .
Mitigate through Known Issue Rollback (KIR)
This issue is mitigated using Known Issue Rollback (KIR) .
For enterprise-managed devices where Windows updates are managed by IT departments, IT administrators can apply the KIR by installing and configuring the Group Policy listed below.
The special Group Policy can be found in:
Computer Configuration > Administrative Templates > Group Policy name listed below
Group Policy downloads with Group Policy name
Download for Windows 11, version 25H2 and Windows 11, version 24H2: KB5124010 260924_20021 Known Issue Rollback
Important
You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the Group Policy setting. This Group Policy disables the change causing this issue until a resolution is released in a future Windows update.
For information about deploying and configuring this special Group Policy, see How to use Group Policy to deploy a Known Issue Rollback .
Resolution
We are working on a resolution for this issue, and it will be released in a future Windows update.
Domain-joined devices might lose their secure trust relationship with the domain
Symptoms
After installing the September 8, 2026, Windows security update ( KB5124008 ), or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the ...
CVEs fixed by this update
Sorted exploited-first, then by CVSS. Every CVE links to its Senserva page with the full risk facts, references, and a ready-to-paste AI prompt.
| CVE | Severity | CVSS | EPSS | Exploited |
|---|---|---|---|---|
| CVE-2026-62721 | High | 7.8 | 1.2% | No |
Scope and sources
- Affected products
- Also released in August 2026
KB5120228
215 CVEs · Critical · exploitedKB5120229
195 CVEs · Critical · exploitedKB5120233
215 CVEs · Critical · exploitedKB5120238
183 CVEs · Critical · exploitedKB5120240
170 CVEs · Critical · exploitedKB5120242
195 CVEs · Critical · exploitedKB5120385
144 CVEs · Critical · exploitedKB5120386
139 CVEs · Critical · exploitedThe full month, summarized: Microsoft Patch Tuesday.
- Authoritative references
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.