September 8, 2026—KB5124012 (OS Build 28000.2954)

Applies To
Windows 11 version 26H1, all editions

This cumulative update for Windows 11, version 26H1 (KB5124012) includes the latest security fixes and improvements, along with non-security updates from last month's optional preview release. Visit the Windows release health dashboard for the latest status on this release.

Improvements

This update includes new features and quality improvements that were part of the following update:

The following summary outlines key quality improvements addressed by this update. The bold text within the brackets indicates the item or area of the change.

  • [Security updates] This update provides security improvements. For more information about the security vulnerabilities resolved by this update, see the Security Update Guide

  • [Secure Boot] This update includes additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot certificates. Certificate deployment via Windows updates continues across supported PCs and non-managed business devices in the coming months.

  • [Teams and Outlook on Arm64 PCs] Fixed: This update addresses an issue that could cause Microsoft Teams and Microsoft Outlook to unexpectedly close on Arm64-based PCs.

  • [Date and Time] This update adjusts Morocco Standard Time to reflect Morocco's transition to permanent UTC+00:00 effective September 20, 2026. This change ensures that the correct local time is displayed after the transition.

  • [Remote Desktop Audio Redirection] This update addresses an issue affecting Remote Desktop audio redirection that could prevent audio from a remote session from playing on the local device in certain configurations.

  • [OMA-DM Client Logging] This update improves diagnostic logging for the OMA-DM client by adding certificate chain information for server connections, helping administrators troubleshoot device management connectivity issues.

If you've already installed previous updates, your device will download and install only the new updates included in this package.

Component updates

AI components

This release updates the following AI components to version 1.2608.951.0: Image Search, Content Extraction, Semantic Analysis, and Settings Model.

To learn more, see Release information for AI components.​​​​​​​

Servicing stack update ​​​​​​​​​ Includes KB5125104 (Build 28000.2950), which improves the reliability of the Windows update installation process. To learn more about SSUs, see [Simplifying on-premises deployment of servicing stack updates](https://learn.microsoft.com/windows/deployment/update/servicing-stack-updates#simplifying-on-premises-deployment-of-servicing-stack-updates).

Known issues in this update

Domain-joined devices might lose their secure trust relationship with the domain

Symptoms

After installing the September 8, 2026, Windows security update KB5124012, or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. Offline sign-in using previously cached credentials might continue to work. AD replication and AD services on the domain controllers are not affected.

This issue occurs because KB5124012 and later updates enable the Machine Identity Isolation feature. While the update does not directly enable Machine Identity Isolation enforcement, it does cause Windows to begin honoring any existing or policy-provisioned settings that enabled Machine Identity Isolation enforcement. However, this feature is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above. The feature should be disabled elsewhere. Any devices previously configured to use Machine Identity Isolation that are not connected to Windows Server 2025 domain controllers will experience this issue and will need to disable the feature.

Workaround

Important: This section contains information about modifying the registry. Before you modify the registry, back it up and make sure that you know how to restore it if a problem occurs. For more information, see How to back up and restore the registry in Windows.

To work around this issue, disable Machine Identity Isolation using the same management method that was used to enable it. Choose the applicable option below:

  1. If Machine Identity Isolation was enabled by Intune policy, disable Machine Identity Isolation with Intune.

  2. If Machine Identity Isolation was enabled by Group Policy, disable Machine Identity Isolation with Group Policy.

  3. If Machine Identity Isolation was enabled directly in the registry, use these steps to disable it:

    • On the Windows 11, version 24H2 or 25H2 device, locate the following registry paths:

      HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation
      
      HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation
      
    • For either of these registry keys, if the value of MachineIdentityIsolation is set to 2, change it to:

      MachineIdentityIsolation = 0
      

After you disable Machine Identity Isolation, restart the device.

Then reset the secure channel using the following command:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)

Resolution

Microsoft plans to resolve this issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while improvements are made to the feature.

USB audio devices might fail to start or produce no sound

​​​​​​​​​ Symptoms

After installing the September 8, 2026, Windows security update (KB5124012), some USB Audio Class 1.0 devices might fail to start or produce audio. Affected devices might experience one or more of the following symptoms:

  • ​The device displays an error in Device Manager: "This device cannot start (Code 10).” ​
  • No audio output. ​
  • Volume controls are unresponsive or remain at zero. ​
  • Sound settings are unresponsive or unavailable. ​
  • Some devices might function in standard stereo configurations but fail when using multichannel audio features, including 8-channel or 3D audio modes. Some customers have reported that they're able to restore audio in these cases by switching to 2-channel mode.

This issue is limited to USB Audio Class 1.0 devices.

Resolution

This issue is partially resolved in the out-of-band (OOB) update released on September 14, 2026, (KB5129194). This OOB update resolves the symptoms experienced on devices using 8-channel or 3D audio modes. Microsoft is working to address the other symptoms and will provide more information when it is available.

IT administrators who need an immediate workaround for the symptoms not addressed yet by the OOB update should contact Microsoft Support for Business for assistance.

Host folder shares might be unavailable in Hyper-V-based Linux VMs

​​​​​​​​​ Symptoms

After installing the September 2026 security update (KB5124012), applications that use HCS-managed virtual machines might experience issues when sharing host folder with Linux VMs using Plan9. Affected virtual machines start normally, but folders shared from the Windows host using Plan9 do not appear or cannot be accessed in the guest environment.

Applications or sandbox environments that depend on these shared folders might display an error indicating that no Plan9 drive shares were mounted. Claude Cowork and the Windows Subsystem for Linux (WSL) are two of the applications affected by this issue. Standard Hyper-V virtual machines that do not use the Plan9 feature are not affected by this issue.

Resolution

This issue is resolved in Windows updates released on and after September 14, 2026 such as KB5129194.

Remote Desktop Services might stop responding after September 2026 security update

Symptoms

After installing the September 2026 Windows security update, some organizations might experience issues with Remote Desktop Services (RDS).

In some environments, RDS might become unstable, resulting in RDP connections failing after several minutes, sign-in issues, or servers hanging at "Please wait for the Remote Desktop Configuration". Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, and File Explorer might also become unresponsive. Additionally, the Windows Update page might stop responding and continuously display a loading indicator.

Note

This issue does not affect Windows 365 or Azure Virtual Desktop.

Resolution

This issue is resolved in Windows updates released on and after September 14, 2026 such as KB5129194. We recommend you install the latest Windows update for your device as it contains important improvements and issue resolutions, including this one.

File History might stop working after installing September 2026 Windows update

Symptoms

After installing the September 2026 Windows security update KB5124008, some customers using File History, might be unable to create or update backups. File History, available through Control Panel > System and Security > File History, is used to back up files to an external drive or network location. Affected devices might incorrectly display a "Reconnect your drive" message even when a compatible backup drive is connected and functioning properly. Additionally, the "Last Backup" timestamp might not update, and previously backed up files might show "No previous version available." In some cases, Event Viewer might record application crash events referencing FileHistory.exe and KERNELBASE.dll.

Resolution

Microsoft is working on a resolution for this issue in a future Windows update and will provide more information when it is available.

How to get this update

Before you install this update

Microsoft combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates.

Deployment

If you deploy dynamic updates such as this update to an existing Windows image, ensure the boot.stl file is included as part of the installation media. Failure to include the file might prevent devices from successfully starting from the installation media and can result in error code 0xc0430001.

Note

The boot.stl file is used during Secure Boot validation and must match the Windows version and architecture of the image you are updating.

To ensure the boot.stl file is included as part of the installation media, do one of the following:

  • Use the Update WinPE script to update an existing Windows image. (Recommended)
  • Manually copy the boot.stl file from the device Windows\Boot\EFI folder to the corresponding folder on your installation media before deploying the update.

For information about how to apply Dynamic Update packages to existing Windows images, see Update Windows installation media with Dynamic Update.

Install this update

To install this update, use one of the following Windows and Microsoft release channels.


Available Next Step
Available This update downloads and installs automatically from Windows Update and Microsoft Update.

File information

For a list of the files provided in this update, download the file information for cumulative update KB5124012​​​​​​​​​.

For a list of the files provided in the servicing stack update, download the file information for the SSU (KB5125104) - version 28000.2950.

Windows monthly updates explained

Description of the standard terminology used for Microsoft software updates

Windows release health

Change log
Change date Change description
September 19, 2026 Added a known issue, "File History might stop working after installing September 2026 Windows update".
September 14, 2026 Added the resolution for the known issue "Remote Desktop Services might stop responding after September 2026 security update".
September 12, 2026 Added a known issue, "Remote Desktop Services might stop responding after September 2026 security update".
September 12, 2026 Added a known issue, "USB audio devices might fail to start or produce no sound".
September 11, 2026 Added a known issue, "Host folder shares might be unavailable in Hyper-V-based Linux VMs".