September 14, 2026—Hotpatch KB5129241 (OS Builds 26200.9448 and 26100.9448) Out-of-band

Applies To
Windows 11 Enterprise LTSC 2024

Important

This update applies only to devices enrolled in hotpatch updates and is offered to eligible devices that have installed the September security update (KB5124008). For more information, see Hotpatch updates.

This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5129241) includes the latest security and non-security improvements.

Improvements

This OOB update includes the following improvement:

  • [Security] This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.

  • [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5122880). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.

  • [Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.

  • [8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)

    Note

    This Hotpatch update will install and take effect without requiring you to restart your device if you have the September 2026 Windows security update (KB5124008) installed.

Known issues in this update

Devices might experience a black screen or desktop loading issues after sign-in

Symptoms

After installing the August 2026 Windows non-security preview update KB5120998 and subsequent updates, some devices might experience desktop loading issues. This issue has been primarily observed on Azure Virtual Desktop (AVD) hosts using FSLogix. This issue appears to occur more frequently with some existing user profiles.

Affected users might see a black screen after sign-in, with the desktop session failing to load automatically. In some cases, users might be unable to access their desktop until the desktop session is started manually. Application event logs might also show Windows Explorer crashes.

Workaround

Affected customers can apply one of the following workarounds to mitigate the issue:

  1. Manually launch explorer.exe

    Users can temporarily mitigate this issue by opening Task Manager (Ctrl+Shift+Esc), selecting Run new task, entering explorer.exe, and selecting OK.

  2. Mitigate through Known Issue Rollback (KIR)

    This issue is mitigated using Known Issue Rollback (KIR).

For enterprise-managed devices where Windows updates are managed by IT departments, IT administrators can apply the KIR by installing and configuring the Group Policy listed below.

The special Group Policy can be found in:

Computer Configuration > Administrative Templates > Group Policy name listed below

Group Policy downloads with Group Policy name

Important

You will need to install and configure the Group Policy for your version of Windows to resolve this issue. You will also need to restart your device(s) to apply the Group Policy setting. This Group Policy disables the change causing this issue until a resolution is released in a future Windows update.

For information about deploying and configuring this special Group Policy, see How to use Group Policy to deploy a Known Issue Rollback.

Resolution

We are working on a resolution for this issue, and it will be released in a future Windows update.

Domain-joined devices might lose their secure trust relationship with the domain

Symptoms

After installing the September 8, 2026, Windows security update (KB5124008), or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. Offline sign-in using previously cached credentials might continue to work. AD replication and AD services on the domain controllers are not affected.

This issue occurs because KB5124008 and later updates enable the Machine Identity Isolation feature. While the update does not directly enable Machine Identity Isolation enforcement, it does cause Windows to begin honoring any existing or policy-provisioned settings that enabled Machine Identity Isolation enforcement. However, this feature is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above. The feature should be disabled elsewhere. Any devices previously configured to use Machine Identity Isolation that are not connected to Windows Server 2025 domain controllers will experience this issue and will need to disable the feature.

Workaround

Important: This section contains information about modifying the registry. Before you modify the registry, back it up and make sure that you know how to restore it if a problem occurs. For more information, see How to back up and restore the registry in Windows.

To work around this issue, disable Machine Identity Isolation using the same management method that was used to enable it. Choose the applicable option below:

  1. If Machine Identity Isolation was enabled by Intune policy, disable Machine Identity Isolation with Intune.

  2. If Machine Identity Isolation was enabled by Group Policy, disable Machine Identity Isolation with Group Policy.

  3. If Machine Identity Isolation was enabled directly in the registry, use these steps to disable it:

    • On the Windows 11, version 24H2 or 25H2 device, locate the following registry paths:

      HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation
      
      HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation
      
    • For either of these registry keys, if the value of MachineIdentityIsolation is set to 2, change it to:

      MachineIdentityIsolation = 0
      

After you disable Machine Identity Isolation, restart the device.

Then reset the secure channel using the following command:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)

Resolution

Microsoft plans to resolve this issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while improvements are made to the feature.

USB Audio Class 1.0 devices with error Code 10 or no output

Symptoms

After installing the September 8, 2026, Windows security update, some USB Audio Class 1.0 devices might fail to start or produce audio. Affected devices might experience one or more of the following symptoms:

  • The device displays an error in Device Manager: "This device cannot start (Code 10).”
  • No audio output.
  • Volume controls are unresponsive or remain at zero.
  • Sound settings are unresponsive or unavailable.

This issue is limited to USB Audio Class 1.0 devices.

Resolution

Microsoft is working on a resolution and will update this documentation when more information is available.

File History might stop working after installing September 2026 Windows update

Symptoms

After installing the September 2026 Windows security update KB5124008, some customers using File History, might be unable to create or update backups. File History, available through Control Panel > System and Security > File History, is used to back up files to an external drive or network location. Affected devices might incorrectly display a "Reconnect your drive" message even when a compatible backup drive is connected and functioning properly. Additionally, the "Last Backup" timestamp might not update, and previously backed up files might show "No previous version available." In some cases, Event Viewer might record application crash events referencing FileHistory.exe and KERNELBASE.dll.

Resolution

Microsoft is working on a resolution for this issue in a future Windows update and will provide more information when it is available.

How to get this update

Before you install this update

Microsoft combines the latest servicing stack update (SSU) for your operating system with the hotpatch update. For general information about SSUs, see Servicing stack updates.

If you are using Windows Update, the latest SSU installs with this update.

Install this update

To install this update, use one of the following Windows and Microsoft release channels.

Release Channels Available Next step
Windows Update Available This update downloads and installs automatically from Windows update.
Catalog Not available See the other options.
Server Update Services Not available See the other options.

File information

For a list of the files provided in this update, download the file information for the out-of-band hotpatch update KB5129241.

For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5124007) - version 26100.9441.

Change log
Change date Change description
September 25, 2026 Known issues added:

• Devices might experience a black screen or desktop loading issues after sign-in.
• Remote Desktop Services (RDS) might stop responding after installing the September 2026 security update.
• Host folder shares might be unavailable in Hyper-V-based Linux virtual machines using Plan9 folder sharing.