September 14, 2026—KB5129195 (OS Builds 26200.9457 and 26100.9457) Out-of-band

Applies To
Windows 11 version 25H2, all editions Windows 11 version 24H2, all editions

This out-of-band (OOB) update for Windows 11, version 25H2 and Windows 11, version 24H2 (KB5129195) is cumulative. It includes updates from previous releases, along with additional security and non-security improvements. Visit the Windows release health dashboard for the latest status on this release.

Improvements

This OOB update includes the following improvement:

  • [Security] This update includes protections documented in CVE-2026-62721, which refers to a Windows User-Mode Power Service (UMPS) Elevation of Privilege vulnerability.

  • [Remote Desktop Services (known issue)] Fixed: This update addresses an issue affecting Remote Desktop Services (RDS) after installing the September 2026 Windows security update (KB5122880). In affected environments, RDS might become unstable, causing RDP connection and sign-in failures or servers to become unresponsive during Remote Desktop configuration. Related tools, including Microsoft Management Console (MMC), RDS Licensing Diagnoser, File Explorer, and the Windows Update page, might also stop responding.

  • [Hyper-V (known issue)] Fixed: Some applications that use HCS-managed virtual machines experienced issues when sharing host folder with Linux VMs using Plan9. Folders shared from the Windows host using Plan9 did not appear or could not be accessed in the guest environment.

  • [8-channel or 3D audio modes] Fixed: Some USB Audio Class 1.0 devices functioning as expected in standard stereo configurations failed when using multichannel audio features, including 8-channel or 3D audio modes. (Note: There are other audio symptoms not resolved in this OOB update. See the “Known issues in this update” section for more information.)

Component updates

Windows 11 servicing stack update (KB5124007) - 22621.9441

This update makes quality improvements to the servicing stack, which is the component that installs Windows updates. Servicing stack updates (SSU) ensure that you have a robust and reliable servicing stack so that your devices can receive and install Microsoft updates. To learn more about SSUs, see Simplifying on-premises deployment of servicing stack updates.

Known issues in this update

Domain-joined devices might lose their secure trust relationship with the domain

Symptoms

After installing the September 8, 2026, Windows security update (KB5124008), or later updates, some Credential Guard protected machine accounts might lose their secure channel with an on-premises Active Directory (AD) domain. Users might then be unable to sign in interactively with valid domain credentials and might receive a message stating that the trust relationship between the device and the domain failed. Offline sign-in using previously cached credentials might continue to work. AD replication and AD services on the domain controllers are not affected.

This issue occurs because KB5124008 and later updates enable the Machine Identity Isolation feature. While the update does not directly enable Machine Identity Isolation enforcement, it does cause Windows to begin honoring any existing or policy-provisioned settings that enabled Machine Identity Isolation enforcement. However, this feature is only supported for environments connected to domain controllers running at a Windows Server 2025 Domain Functional Level (DFL) and above. The feature should be disabled elsewhere. Any devices previously configured to use Machine Identity Isolation that are not connected to Windows Server 2025 domain controllers will experience this issue and will need to disable the feature.

Workaround

Important: This section contains information about modifying the registry. Before you modify the registry, back it up and make sure that you know how to restore it if a problem occurs. For more information, see How to back up and restore the registry in Windows.

To work around this issue, disable Machine Identity Isolation using the same management method that was used to enable it. Choose the applicable option below:

  1. If Machine Identity Isolation was enabled by Intune policy, disable Machine Identity Isolation with Intune.

  2. If Machine Identity Isolation was enabled by Group Policy, disable Machine Identity Isolation with Group Policy.

  3. If Machine Identity Isolation was enabled directly in the registry, use these steps to disable it:

    • On the Windows 11, version 24H2 or 25H2 device, locate the following registry paths:

      HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MachineIdentityIsolation
      
      HKLM\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard\MachineIdentityIsolation
      
    • For either of these registry keys, if the value of MachineIdentityIsolation is set to 2, change it to:

      MachineIdentityIsolation = 0
      

After you disable Machine Identity Isolation, restart the device.

Then reset the secure channel using the following command:

Test-ComputerSecureChannel -Repair -Credential (Get-Credential)

Resolution

Microsoft plans to resolve this issue in a future Windows update by temporarily preventing Machine Identity Isolation enforcement while improvements are made to the feature.

USB Audio Class 1.0 devices with error Code 10 or no output

Symptoms

After installing the September 8, 2026, Windows security update, some USB Audio Class 1.0 devices might fail to start or produce audio. Affected devices might experience one or more of the following symptoms:

  • The device displays an error in Device Manager: "This device cannot start (Code 10).”
  • No audio output.
  • Volume controls are unresponsive or remain at zero.
  • Sound settings are unresponsive or unavailable.

This issue is limited to USB Audio Class 1.0 devices.

Resolution

Microsoft is working on a resolution and will update this documentation when more information is available.

How to get this update

Before you install this update

Microsoft now combines the latest servicing stack update (SSU) for your operating system with the latest cumulative update (LCU). For general information about SSUs, see Servicing stack updates and Servicing Stack Updates (SSU): Frequently Asked Questions.

Install this update

To install this update, use one of the following Windows and Microsoft release channels.


Available Next Step
Available This update downloads and installs automatically from Windows Update and Microsoft Update.

File Information

For a list of the files provided in this update, download the file information for cumulative update KB5129195.

For a list of the files provided in the servicing stack update, download the file information for SSU KB5124007 - versions 22621.9441.