Microsoft’s support article also says KB5129195 adds protection for CVE-2026-62721, an elevation-of-privilege vulnerability in the Windows User-Mode Power Service. That makes this more than a conventional reliability hotfix: organizations that deferred the September cumulative update because of the Remote Desktop regression now have a replacement that retains the month’s prior fixes while adding a new security correction.
The patch arrives through Windows Update and Windows Update for Business under configured policies, and synchronizes to WSUS as a Security Updates classification. That delivery treatment is important. This is not merely an optional preview build for test machines; environments approving September security updates can receive it through their ordinary servicing process.
KB5129195 repairs the Windows 11 side of the RDS regression
The headline fix addresses the Remote Desktop Services failures that followed September’s Patch Tuesday updates. Microsoft’s Windows release-health documentation describes the symptom as RDP connections failing after several minutes, sign-in failures, hosts hanging during Remote Desktop configuration, and related management components becoming unresponsive. Microsoft Management Console, RDS Licensing Diagnoser, File Explorer, and even the Windows Update settings page could stall.
Independent reporting from BleepingComputer established that the wider incident was operationally serious on Windows Server estates as well: administrators described servers that accepted connections initially, then stopped accepting new RDP sessions after logouts or after several hours of use. Some reported that ordinary restarts were not enough and that they needed a hard reset; others said removing the September cumulative update restored functionality at the cost of removing the month’s security fixes.
KB5129195 is the Windows 11 24H2 and 25H2 remedy. It should not be read as a universal cure for every system caught in the September RDS incident. Microsoft’s own release-health dashboard lists affected client and server platforms far beyond these two Windows 11 releases. Administrators responsible for Windows Server RDS session hosts need to identify the separate out-of-band update assigned to their server version rather than assuming a Windows 11 package addresses a server-side deployment.
There is also a documentation error worth catching before it becomes a ticketing or change-management problem. The KB5129195 support page says the RDS issue followed KB5122880, but Microsoft’s release-health entry for Windows 11 24H2 identifies the originating September 8 update as KB5124008, build 26100.9445. KB5122880 is the corresponding Windows 11 23H2 update. The fix itself is correctly targeted at 24H2 and 25H2, but the wrong originating KB in the support article can send admins looking in the wrong compliance report or uninstall history.
For incident records, use the build and product line rather than the stray reference: Windows 11 24H2 and 25H2 systems affected by the September regression came from the KB5124008 servicing branch and should end up on build 26100.9457 or 26200.9457 after KB5129195.
Hyper-V and WSL users get the Plan9 share repair
KB5129195 also resolves a failure in host-folder integration for applications using Host Compute Service-managed virtual machines and Plan9 file sharing. Affected Linux guests could boot normally, but folders exposed from the Windows host did not appear inside the guest or could not be opened.
The distinction between HCS-managed environments and ordinary Hyper-V VMs is useful. Microsoft’s release-health documentation says standard Hyper-V virtual machines that do not rely on Plan9 host shares are not affected. The regression instead hits tools and sandbox-style workflows that rely on this integration layer, including Windows Subsystem for Linux and Claude Cowork, according to Microsoft.
For developers, this symptom can look like an application or distribution-specific mount problem: the VM launches, Linux itself is responsive, yet expected project folders are absent. Recreating the virtual machine, changing Linux permissions, or remounting a host path will not correct an OS-level regression in the host sharing path. KB5129195 is therefore the preferred remediation for affected Windows 11 24H2 and 25H2 clients, rather than an improvised workaround inside the guest.
The update’s timing also matters for managed developer workstations. A machine may have been kept on the September security update because it fixed an unrelated issue, while its WSL workflow silently broke afterward. Administrators should include a basic host-to-guest folder access check in their post-deployment validation, especially where developer images use managed Windows Update rings.
The audio correction is partial, not a general USB-audio fix
Microsoft says KB5129195 fixes one narrow audio failure: USB Audio Class 1.0 devices that worked in normal stereo could fail when users selected multichannel modes, including eight-channel or 3D audio. Users whose hardware failed only when switching from two-channel output to surround or spatial configurations should retest after the update.
But the update does not resolve every audio defect caused by the September release. Microsoft continues to list a known issue in which USB Audio Class 1.0 devices may show Device Manager Code 10, produce no sound, leave volume controls stuck at zero, or make sound settings unavailable. The company says it is still working on a resolution.
That separation is easy to miss because the affected hardware class is the same. A successful update should be expected to restore the multichannel-mode scenario cited in the release notes; it is not evidence that an adapter or DAC with Code 10 will begin working again. Support teams should collect the Device Manager status and the selected channel mode before concluding that KB5129195 failed to install or failed to address a documented fix.
As a temporary operational measure, Microsoft’s release-health entry says some users have restored sound in the multichannel-only scenario by moving back to two-channel output. That is a workaround for the configuration-specific failure, not a fix for the unresolved no-output and Code 10 cases.
Deployment details matter for offline servicing
For normally managed devices, the clean path is to allow Windows Update, Windows Update for Business, or WSUS to deploy KB5129195. Because it is cumulative, it includes the preceding servicing content as well as the new corrections. Microsoft also notes that the package contains Copilot+ PC AI component updates, although those components do not install on ordinary Windows client PCs or on Windows Server.
Manual deployment deserves more care. Microsoft requires a checkpoint cumulative update, KB5043080, before the target KB5129195 package when that checkpoint is not already installed. This applies to both architectures:
- Arm64 installations use
windows11.0-kb5043080-arm64.msubeforewindows11.0-kb5129195-arm64.msu. - x64 installations use
windows11.0-kb5043080-x64.msubeforewindows11.0-kb5129195-x64.msu.
Administrators using the Microsoft Update Catalog should keep the required packages together in an otherwise empty folder. Installing the MSUs individually requires the checkpoint package first. DISM can instead process the target package and scan its package path for the needed checkpoint update, which is safer for repeatable offline-media servicing and reduces the chance that an operator reverses the order.
Images that also receive Dynamic Update packages need another check: Microsoft advises using packages from the same release month as KB5129195. If the matching Safe OS Dynamic Update or Setup Dynamic Update is unavailable, Microsoft says to use the most recently released version. That guidance is especially relevant for organizations maintaining custom Windows 11 media, where mismatched servicing components can turn a straightforward quality update into setup-time troubleshooting.
What to validate after installation
The practical priority is higher for organizations that installed the September 8 cumulative update and enabled RDS on Windows 11 endpoints, run WSL or another HCS-managed Linux VM workflow, or use USB Audio Class 1.0 hardware in multichannel configurations. Test the exact path that failed rather than relying solely on a successful reboot.
A focused post-install check should include an RDP sign-in and disconnect/reconnect cycle, access to a host-shared directory from the affected Linux guest, and playback in the previously failing multichannel mode. For managed fleets, confirm the resulting build number: 26100.9457 for Windows 11 24H2 and 26200.9457 for Windows 11 25H2.
KB5129195 closes the immediate Windows 11 gap created by September’s regression, but it leaves the broader USB Audio Class 1.0 Code 10 and no-output issue unresolved. Teams that depend on those devices should install the OOB update for its security and fixed-feature benefits, then keep their workaround and monitoring in place until Microsoft publishes the separate audio resolution.
Update: Additional Windows releases receive separate out-of-band fixes (September 16, 2026)
TechRepublic reports that Microsoft has extended the September Remote Desktop, Plan9 sharing, and USB multichannel-audio remediation beyond the Windows 11 24H2 and 25H2 package covered above. Windows 11 26H1 is also included in the security-update rollout, while affected Windows Server versions and supported Windows 10 editions have their own corresponding releases.
For Windows 11 24H2 and 25H2 systems using hotpatching, the reported package is KB5129241. Eligible devices must already have the September security update installed before receiving that hotpatch-based fix. That requirement matters for administrators using hotpatch rings: verify the baseline update before treating a missing OOB deployment as a servicing failure.
TechRepublic also reports that Windows 11 23H2 receives KB5129242 as an optional, non-security update rather than through the normal automatic security-update path. Organizations with affected 23H2 endpoints should therefore check Windows Update policy and user action requirements instead of assuming the remediation will arrive automatically.
The report further says the 26H1 release includes CVE-2026-62721 protection plus a separate fix for CVE-2026-85921.
Update: Microsoft labels broader USB Audio issue “mitigated,” not resolved (September 16, 2026)
Redmondmag reports that Microsoft now classifies the remaining USB Audio Class 1.0 failure as mitigated rather than resolved. KB5129195 still addresses only the eight-channel and 3D-audio scenario; devices that fail to start, show Code 10, or produce no output remain outside the delivered fix.
For organizations facing those unresolved symptoms, Microsoft reportedly directs customers to Microsoft Support for Business for immediate assistance. The company has not published a general public workaround for the Code 10 and no-audio cases, so switching to stereo should not be presented as a fleet-wide remedy.
The report also underscores the wider affected-platform scope: the underlying issue spans Windows 11 releases from 23H2 through 26H1, supported Windows 10 versions including LTSC editions, and multiple Windows Server generations. Administrators should therefore continue to separate the completed multichannel correction from the still-open device-start and audio-output investigation when communicating status to users.
Update: Reports flag additional issues not addressed by KB5129195 (September 17, 2026)
According to Ascendants, KB5129195 does not address separate post-September reports involving AMD Radeon systems, including display failures, driver timeouts, freezes, crashes, and black screens. Microsoft has not listed Radeon-specific corrections in the KB5129195 release notes, so administrators should not treat the out-of-band update as a remedy for graphics instability.
The outlet also reports File Explorer launch failures or crashes after sign-in in some enterprise profile-management environments using Citrix UPM, FSLogix, Horizon, or ProfileUnity ProfileDisks. These cases are likewise outside the documented KB5129195 fixes. IT teams using those products should validate Explorer and taskbar availability after deployment, alongside the RDP, Plan9-share, and multichannel-audio checks already recommended.
The remaining USB Audio Class 1.0 Code 10, no-output, and stuck-volume symptoms also remain uncorrected.
Update: Report identifies KB5129194 as an additional RDS remediation package (September 18, 2026)
Computerworld reports that Microsoft has also issued KB5129194 to resolve the Remote Desktop Services instability triggered by September’s Patch Tuesday updates. The reported symptoms match the broader incident already documented: failed RDP connections and servers hanging at “Please wait for the Remote Desktop Configuration.”
The report does not change the Windows 11 24H2 and 25H2 guidance for KB5129195. Instead, it reinforces that the RDS regression is being serviced through version-specific out-of-band packages. Administrators should confirm the operating system and servicing branch before approving KB5129194, rather than substituting it for the Windows 11 client update.
Computerworld’s report also covers an Excel 2016 paste-operation problem addressed partly by Office update KB5002665. That is a separate Office regression and is not fixed by KB5129195.
Update: Microsoft flags File History backup failures after September updates (September 21, 2026)
According to BleepingComputer, Microsoft has identified a new known issue affecting the built-in File History backup feature after the September 2026 security updates. Some users may be unable to create or refresh File History backups, with Event Viewer crashes referencing FileHistory.exe and KERNELBASE.dll.
Affected systems can also show a misleading “Reconnect your drive” warning despite a working external or network backup target. Other reported signs include a Last Backup timestamp that does not advance and previously saved files appearing without available historical versions.
The issue spans Windows 11 23H2 and later, including the 24H2 and 25H2 branches covered by KB5129195, as well as supported Windows 10 releases and Windows 10 Enterprise LTSC editions. This is a separate regression from the RDS, Plan9 sharing, and USB multichannel-audio problems addressed by the out-of-band updates; administrators should not assume KB5129195 restores File History functionality.
Teams still using File History for local or NAS-based recovery should verify that a new backup completes and that prior versions can be restored. Until Microsoft publishes a fix or workaround, organizations should ensure important data also has a separate, validated backup path.
References
- September 14, 2026—KB5129195 (OS Builds 26200.9457 and 26100.9457) Out-of-band | Microsoft Support Microsoft Support · 2026-09-14T00:00:00+00:00
