This out-of-band update for Windows 11, version 26H1 (KB5129194) includes the latest fixes and improvements. Visit the Windows release health dashboard for the latest status on this release.
Improvements
This out-of-band update includes the following improvements:
[Security] This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.
[Security] This update includes protections documented in CVE-2026-85921, which refers to a Windows Secure Kernel Mode Elevation of Privilege vulnerability.
[Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5124012). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.
[Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.
[8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)
If you've already installed previous updates, your device will download and install only the new updates included in this package.
Component updates
AI components
This release updates the following AI components to version 1.2608.951.0: Image Search, Content Extraction, Semantic Analysis, and Settings Model.
To learn more, see Release information for AI components.
Servicing stack update
Includes KB5125104 (Build 28000.2950), which improves the reliability of the Windows update installation process.Known issues in this update
Domain-joined devices might lose their secure trust relationship with the domain
Symptoms
After installing the September 8, 2026, Windows security update KB5124012, or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. Offline sign-in using previously cached credentials might continue to work. AD replication and AD services on the domain controllers are not affected.
This issue occurs because KB5124012 and later updates enable the Machine Identity Isolation feature. While the update does not directly enable Machine Identity Isolation enforcement, it does cause Windows to begin honoring any existing or policy-provisioned settings that enabled Machine Identity Isolation enforcement. However, this feature is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above. The feature should be disabled elsewhere. Any devices previously configured to use Machine Identity Isolation that are not connected to Windows Server 2025 domain controllers will experience this issue and will need to disable the feature.
Workaround
Important: This section contains information about modifying the registry. Before you modify the registry, back it up and make sure that you know how to restore it if a problem occurs. For more information, see How to back up and restore the registry in Windows.
To work around this issue, disable Machine Identity Isolation using the same management method that was used to enable it. Choose the applicable option below:
If Machine Identity Isolation was enabled by Intune policy, disable Machine Identity Isolation with Intune.
If Machine Identity Isolation was enabled by Group Policy, disable Machine Identity Isolation with Group Policy.
If Machine Identity Isolation was enabled directly in the registry, use these steps to disable it:
On the Windows 11, version 24H2 or 25H2 device, locate the following registry paths:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolationHKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolationFor either of these registry keys, if the value of
MachineIdentityIsolationis set to2, change it to:MachineIdentityIsolation = 0
After you disable Machine Identity Isolation, restart the device.
Then reset the secure channel using the following command:
Test-ComputerSecureChannel -Repair -Credential (Get-Credential)
Resolution
Microsoft plans to resolve this issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while improvements are made to the feature.
USB Audio Class 1.0 devices with error Code 10 or no output
Symptoms
After installing the September 8, 2026, Windows security update, some USB Audio Class 1.0 devices might fail to start or produce audio. Affected devices might experience one or more of the following symptoms:
- The device displays an error in Device Manager: "This device cannot start (Code 10).”
- No audio output.
- Volume controls are unresponsive or remain at zero.
- Sound settings are unresponsive or unavailable.
This issue is limited to USB Audio Class 1.0 devices.
Resolution
Microsoft is working on a resolution and will update this documentation when more information is available.
How to get this update
Before you install this update
Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.
Deployment
If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.
Note
The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.
To ensure the boot.stl file is included as part of the installation media, do one of the following:
- Use the Update WinPE script to update an existing Windows image. (Recommended)
- Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.
For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.
Install this update
To install this out-of-band update, use one of the following Windows and Microsoft release channels.
| Available | Next Step |
|---|---|
|
This update downloads and installs automatically from Windows Update and Microsoft Update. |
File information
For a list of the files provided in this update, download the file information for out-of-band update KB5129194.
For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5125104) - version 28000.2950.
Related topics
Windows monthly updates explained
Description of the standard terminology used for Microsoft software updates