A Windows 11 installation setup appears on a desktop monitor beside upgrade media and a security shield.
Microsoft released KB5128941 on September 22, 2026. It is a Setup Dynamic Update for Windows 11, version 26H1 that fixes security vulnerabilities in Windows Setup binaries and in other files Setup uses during feature updates. It replaces the September 8 package, KB5126041, and applies only to devices already running 26H1. It needs no restart. Most people running 26H1 on the new hardware that shipped with it won't notice the update. The people who should pay attention are administrators who keep 26H1 installation media or offline upgrade images, because a Setup package built into a deployment share goes stale when Microsoft ships a newer one. It is also the second security-labelled Setup package for 26H1 in two weeks.

KB5128941 Updates the Windows 11 26H1 Setup Engine​

Microsoft describes the update in one sentence: it addresses security vulnerabilities in Windows Setup binaries or any files Setup uses for feature updates in Windows 11, version 26H1. The KB page lists three facts that matter for deployment. You must have Windows 11, version 26H1 installed to apply it. No restart is needed after applying it. It replaces KB5126041. The patch management vendor NinjaOne's KB catalog confirms the September 22 date and says the update covers setup files for 26H1 across all editions.

The no-restart note covers installing KB5128941 itself. A feature upgrade that later runs with these refreshed Setup files is a separate operation with its own reboots.

Microsoft offers the included-files list as a CSV that opens in Notepad or Excel. The English (United States) package may also contain files for other languages. The KB doesn't name the vulnerable Setup components, give CVE identifiers or severity ratings, or say whether anything was exploited. Nothing on record suggests an emergency or zero-day response. It reads as routine security servicing for the Setup engine.

On delivery, NinjaOne lists KB5128941 as available through Windows Update, Microsoft Update Catalog, and Windows Server Update Services (WSUS). That matches the predecessor. Microsoft's KB5126041 page lists the same three channels. It says the Windows Update package downloads and installs automatically. It also says WSUS syncs it when Products is set to "Windows 11" and Classification to "Update."

How Setup Dynamic Update Fits Into a Windows Feature Update​

Dynamic Update is part of Windows' feature-update process. Microsoft's deployment documentation says that whenever a feature update starts, whether from media or from a Windows Update-connected environment, Dynamic Update is one of the first steps. Windows Setup contacts a Microsoft endpoint, downloads Dynamic Update packages and applies them to the installation media before the upgrade continues.

Microsoft's documentation lists five kinds of Dynamic Update content, and they are separate packages:

  • Updates to Setup.exe binaries or other files that Setup uses for feature updates. KB5128941 belongs to this category.
  • Updates to the "safe operating system" (SafeOS) used for the Windows Recovery Environment (WinRE).
  • Servicing stack updates needed to complete the feature update.
  • The latest cumulative (quality) update.
  • Driver updates that manufacturers published specifically for Dynamic Update.

The difference matters when you read Microsoft's release notes. When Microsoft released KB5126041 on September 8, it also released a separate Safe OS Dynamic Update for 26H1, KB5124011. Neowin and Windows Report both reported that it updates WinRE to version 10.0.28000.2949. KB5128941 is described only as a Setup package. It shouldn't be read as a WinRE fix, a cumulative update or a driver release.

Dynamic Update also keeps language packs and Features on Demand. According to Microsoft, Setup downloads those components again during the upgrade, and a separate quality update isn't needed. When Setup can download current content, the upgrade finishes closer to fully patched.

The Windows 11 26H1 Setup Chain: From "Improvements" to Security Fixes​

Microsoft's record of 26H1 Setup packages shows the recent pattern. The KB5124001 page, dated August 27, 2026, says only that the update makes improvements to Windows setup binaries or any files that setup uses for feature updates. The May 26 package, KB5096160, uses the same wording. With KB5126041 on September 8, the description changed to addressing security vulnerabilities, and KB5128941 keeps that wording.

KBDateMicrosoft's descriptionReplaces
KB5124001August 27, 2026Improvements to Setup binariesNot established here
KB5126041September 8, 2026Addresses security vulnerabilities in Setup binariesKB5124001
KB5128941September 22, 2026Addresses security vulnerabilities in Setup binariesKB5126041

The two security packages arrived with other September servicing. Neowin reported that KB5126041 shipped alongside the September Patch Tuesday updates, together with Safe OS packages and matching Setup packages for other Windows 11 versions. Windows Report says the batch covered versions 23H2, 24H2, 25H2, and 26H1. KB5128941 shares its September 22 date with the 2026-09 "D" release for 26H1. Microsoft's release-health table lists that as KB5124006, OS build 28000.3086.

Microsoft hasn't given KB5128941 an OS build number, and the cumulative update's build number shouldn't be attached to this Setup package. The shared date matters for image maintenance, because Microsoft advises pairing Dynamic Update packages with the cumulative update from the same month. That is covered below.

Why Windows 11 26H1's Limited Reach Narrows the Audience for KB5128941​

Windows 11 26H1 doesn't follow the usual Windows 11 release pattern. Microsoft's update history says it is available only on new devices with select new silicon as they come to market starting early 2026. Devices on earlier Windows 11 versions will not be offered an update to version 26H1 through Windows Update and cannot be installed as an in-place update on existing devices. The release-health page adds that IoT Enterprise edition isn't supported on 26H1. It lists 26H1 as general availability from February 10, 2026, on OS build family 28000.

So KB5128941 matters to fewer people than a Setup package for 24H2 or 25H2. Machines on 24H2 or 25H2 won't upgrade to 26H1, and this package doesn't touch their setup path. Those versions got their own security-labelled Setup package on September 8, KB5126056. The audience for KB5128941 is organizations and enthusiasts who own 26H1 hardware and use Setup on it: people who build or refresh 26H1 installation media, maintain offline 26H1 images, or run Setup-based operations on those devices. Microsoft doesn't list the specific scenarios in which 26H1's Setup is used. Setup-based in-place repairs of a 26H1 installation are our inference about where refreshed Setup files would apply.

For 26H1 machines connected to Windows Update, the process is mostly automatic. Windows Report notes that Windows Update downloads and installs them automatically. And whenever Setup has internet access at the start of a feature update, it fetches current Dynamic Update content itself. NinjaOne adds that community discussion is limited so far. It describes the release as a straightforward security maintenance release with no reported complications in available sources.


Refreshing 26H1 Installation Media With KB5128941​

Offline and media-based deployment is where KB5128941 creates work. Microsoft's documentation says devices need internet access to get Dynamic Updates, and that some environments can't allow it. In those environments you can still run a media-based feature update, but you first download the Dynamic Update packages and apply them to the image before starting Setup. An image refreshed with KB5126041 two weeks ago now carries a superseded Setup package.

Microsoft's media-refresh guidance puts the Setup Dynamic Update near the end of a long ordered sequence. The Setup DU is added to the new media itself, not to install.wim, boot.wim or winre.wim. It is task 26 of 28. Task 27 copies Setup.exe and setuphost.exe from WinPE onto the media, and task 28 adds the boot manager from WinPE. Earlier tasks service WinRE, the operating system image and WinPE with the combined servicing stack and cumulative update, languages, Features on Demand, the Safe OS Dynamic Update and cleanup. Microsoft says to resolve every failed task before moving on and not to distribute images tied to a failed task.

Microsoft also gives guidance on pairing packages. Dynamic Update packages should come from the same month as the latest cumulative update. If a Setup or Safe OS package isn't available for that month, use the most recent published version of each. For 26H1 this month, KB5128941 is the newest Setup package. The September 8 Safe OS package, KB5124011, is the latest one on this record.

Finding and staging the package​

These steps follow Microsoft's general Dynamic Update documentation. Microsoft's KB5128941 page doesn't give package-specific staging instructions, so check applicability in the Catalog entry before you deploy.

  1. Search the Microsoft Update Catalog for the September 2026 Setup Dynamic Update for Windows 11, version 26H1. Microsoft warns that one search may not return every Dynamic Update package for a release, so try different keywords and check that you have the right file.
  2. For Windows 11 22H2 and later, Microsoft says the package title alone identifies each Dynamic Update type, in the form "YYYY-MM Setup Dynamic Update for Windows 11 Version…". The documentation lists that naming pattern for 22H2 through 24H2 and doesn't list 26H1 separately, so confirm the exact title in the Catalog.
  3. Stage the package with your other refresh inputs. Microsoft's sample PowerShell script keeps the Setup DU as a .cab file in a separate folder from the cumulative update. It copies the original media to a new working folder so a failed run can restart from a known state.
  4. Apply the Setup DU at the media stage (task 26), then copy Setup.exe and setuphost.exe from WinPE (task 27), following Microsoft's documented order.
  5. Retire any media or deployment share that still contains KB5126041 or an older 26H1 Setup package.

Where Setup's command-line switches fit in​

Administrators who run Setup from scripts should know the /DynamicUpdate switch. Its values are Enable, Disable, NoDrivers, NoLCU and NoDriversNoLCU, and they control whether Setup searches for, downloads and installs Dynamic Update content, and which categories it skips. If you run setup /auto upgrade /dynamicupdate disable, Setup won't download a fresher package, so the Setup files on your media are the ones that run. In that case, refreshing the media is the only way KB5128941's fixes get into the process. KB5128941 doesn't change these switches, and none of them is required to install it.

What this means for you​

Whether you need to act depends on how your 26H1 devices get Setup files. Connected 26H1 machines that take Windows Update or WSUS content need nothing beyond normal approval. Teams that keep offline 26H1 media should rebuild it this cycle.

  • KB5128941 applies only to Windows 11, version 26H1. It does nothing for 24H2, 25H2 or 23H2 machines, which can't upgrade in place to 26H1 anyway.
  • If WSUS syncs the "Windows 11" product with the "Update" classification, KB5128941 should arrive the same way KB5126041 did. Approve it and let it supersede the September 8 package.
  • Replace KB5126041 in any 26H1 installation media or offline image with KB5128941. Apply it at the media stage in Microsoft's documented sequence, and pair it with the matching month's cumulative and Safe OS packages.
  • Scripts that run Setup with /DynamicUpdate Disable rely completely on the Setup files already on the media, so those environments need the refreshed package most.
  • Installing KB5128941 requires no restart. Plan reboots for the feature upgrade or repair operation that later uses the refreshed Setup files, not for the package.
  • Microsoft's KB page also links its separate guidance on Secure Boot certificates, which it says started expiring in June 2026. That is a separate project. KB5128941 isn't described as updating those certificates.

A Setup Dynamic Update is a low-risk package, but a stale one sitting in a deployment share can quietly undo the point of patching. Microsoft labelled two consecutive 26H1 Setup packages as security fixes without naming the vulnerabilities, so the safe course is to treat each new one as mandatory for your media. The next point to watch is Microsoft's October 2026 servicing cycle. Because the KB5124001, KB5126041 and KB5128941 releases each replaced the one before, expect the next 26H1 Setup package to replace KB5128941 and to require another media refresh.